Lempea Edge Oy

Finland · owned by Independent (Finland) · iamrain.ai · 4 vendors

IAM RAIN, operated by Lempea Edge Oy, develops and runs a sovereign Defence AI Operating System (OS) that connects sensors to command-and-control (C2) systems across NATO's Eastern Flank. The platform provides a data fabric, agentic AI layer, and digital nervous system enabling rapid integration of sensor data into military command environments. The company built and operated NATO's first Innovation Range event in Finland and serves as a permanent platform partner for the DEFINE Accelerator and Borderland Europe programmes.

Resilience scores

Disruption prediction

Lempea Edge Oy has an estimated 17% probability of disruption in the next 6 months.

2 of Lempea Edge Oy's 4 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-08-25 · revision 4

4 direct vendors, 80 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Lempea Edge Oy exhibits extremely high migration readiness. Its internal tech stack is entirely modern, cloud-native, and Kubernetes-native, leveraging containerization and microservices architecture (e.g., Data Fabric, Agentic AI Layer). The use of AWS, streaming data pipelines, and advanced AI orchestration with LangGraph positions the company for seamless transitions across cloud or on-premise environments. The "Sovereign / Air-Gapped Compute" capability further underscores an architecture designed for flexible deployment. A critical factor contributing to high readiness is the reported "Total Vendors: 0" under vendor relationships, which, if interpreted as a complete absence of external vendor dependencies, signifies an absence of vendor lock-in, eliminating a major impediment to migration such as complex contract negotiations or proprietary technology dependencies. The company also utilizes open-source components (Context Foundry) and industry-standard protocols (SAPIENT, CoT), further reducing proprietary lock-in. While NIS2 is currently not applicable, the highly sensitive nature of its defense industry operations (NATO C2 integration) means any migration would still require rigorous security and compliance considerations, despite the robust technical foundation (confidential compute, RBAC, Keycloak). Similar to resilience, the vendor data presents a contradiction with "Total Services: 6" from "Vendor HQ Countries: United States" and "Vendor Geographic Diversity: 1 unique countries." For this assessment, the direct statement of "Total Vendors: 0" is prioritized, indicating minimal external vendor lock-in. The main challenges or unknowns are the lack of publicly verified information regarding specific data residency requirements and financial stability, which could influence the scope and funding of a migration.

Compliance

8 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

GDPR is universally applicable to Lempea Edge Oy as an EU-registered company (Helsinki, Finland) that explicitly processes personal data. The company has published a privacy notice acknowledging GDPR obligations and granting data subject rights, which demonstrates baseline awareness. However, the privacy notice is minimal and several gaps exist: no Data Protection Officer (DPO) is named or referenced, no formal legal basis for each processing activity is articulated beyond implied legitimate interest/contract, no mention of data processing agreements (DPAs) with sub-processors (Netlify, Plausible), no cookie consent mechanism is described (though they claim cookieless analytics), and no mention of cross-border transfer mechanisms for data processed outside the EEA. The defence/military context adds complexity — if the platform processes any personal data of military personnel or civilians in operational contexts, the risk exposure increases significantly. Fines under GDPR can reach €20M or 4% of global annual turnover. Given the company's small size (5 named team members), enforcement likelihood is moderate but consequences could be existential.

Evidence: https://iamrain.ai/legal/privacy/, https://iamrain.ai/company/, https://iamrain.ai/legal/security/

NIS2 (source) — Assessment Required

NIS2 risk is assessed as High for several compounding reasons. First, Lempea Edge Oy operates in the digital infrastructure and ICT service management space — both listed as Essential Entity categories under NIS2 Annex I. The company provides a sovereign Defence AI Operating System connecting sensors to NATO C2 (Command and Control) systems, which constitutes critical digital infrastructure for national defence and security. Second, Finland transposed NIS2 into national law (Cybersecurity Act, effective April 2024), and Finnish authorities (Traficom/NCSC-FI) are actively enforcing it. Third, the company's platform underpins NATO Eastern Flank operations, meaning a security incident could have severe national security consequences — exactly the scenario NIS2 was designed to address. Fourth, the company has not publicly disclosed any NIS2 registration, compliance assessment, or incident reporting procedures. The combination of critical sector applicability, national security implications, and absence of documented compliance creates a high-risk profile. Non-compliance penalties under NIS2 can reach €10M or 2% of global annual turnover for Essential Entities.

Evidence: https://iamrain.ai/, https://iamrain.ai/legal/security/, https://iamrain.ai/company/, https://iamrain.ai/defence-ai-os/

EU AI Act (source) — Assessment Required

The EU AI Act is directly and critically relevant to Lempea Edge Oy. The company's core product is an 'Agentic AI Layer' with 'LangGraph orchestration, RAG grounding, and agents that act on data' deployed in defence and military contexts. AI systems used in defence, military, and critical infrastructure are subject to the EU AI Act's risk classification framework. Specifically: (1) AI systems used in critical infrastructure (including defence-adjacent digital infrastructure) may be classified as High-Risk under Annex III; (2) Agentic AI systems that make autonomous decisions in operational military contexts raise significant questions under the Act's requirements for human oversight, transparency, and conformity assessment; (3) The Act's prohibited practices and high-risk system requirements include conformity assessments, technical documentation, logging, and human oversight mechanisms. The risk is High because: the company's AI systems operate in high-stakes military environments; the Act's enforcement timeline is active (prohibited practices from February 2025, high-risk system requirements from August 2026); and non-compliance could result in fines up to €30M or 6% of global annual turnover.

Evidence: https://iamrain.ai/, https://iamrain.ai/defence-ai-os/, https://iamrain.ai/company/

Financials

Three-year financials

Financial Resilience Score: 4/10

Lempea Edge Oy (IAM RAIN) is a seed-stage Finnish defence-AI company with a very limited financial track record. 2025 marks its first meaningful commercial year with only €150,000 in revenue derived from a first paid platform licence and a Finnish Defence Forces pilot. The company is currently raising a €2.0m seed round, indicating it is pre-profit and dependent on external funding to bridge to scale. EBIT, equity, and balance-sheet figures are not publicly disclosed, limiting external verification of financial health. Despite the small financial base, the company has meaningful strategic positioning: it operates as horizontal middleware between defence sensors and NATO command-and-control systems, has anchor traction with the Finnish Defence Forces, and has strong NATO ecosystem visibility (operated NATO's first Innovation Range event in Finland in December 2025). Credible technology and industry partners (AWS, FMI, Digia, Nokia, Telia, Patria) further strengthen its positioning. However, resilience is constrained by seed-stage cash-runway risk, extreme customer concentration (essentially single-customer FDF in 2025), a very small team (~5-7 people), long defence procurement sales cycles, and dependence on converting pilot/exercise work into NATO framework contracts — a risk the company itself openly flags. Given these factors, the score reflects meaningful strategic upside offset by significant early-stage financial fragility.

Key strengths: Architectural moat as horizontal middleware between defence sensors and NATO C2/CRC/CAOC systems, Anchor customer: paid pilot with Finnish Defence Forces in 2025, NATO ecosystem visibility (operated NATO's first Innovation Range event in Finland, Dec 2025), Credible technology and industry partners (AWS, FMI, Digia, Nokia, Telia, Patria), Tailwind from expanding European/NATO defence-tech spending on Eastern Flank, Active €2.0m seed fundraising round

Risk factors: Very small revenue base (€150K in 2025) with heavy dependence on external funding, Conversion risk: turning exercise operator status into signed NATO framework contracts, Extreme customer concentration (single-market Finland/NATO, few contracts), Small team (~5-7 people) creating key-person and execution risk on founder/CEO, Long, procedural defence procurement sales cycles, No audited public financials — external stakeholders cannot verify margins, burn, or equity, Pre-profit / loss-making status typical of seed stage

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report