IFTTT
United States · ifttt.com · 21 vendors
IFTTT is a connectivity and automation platform that allows users to create automated workflows, called Applets, between various apps, devices, and services. It operates on the principle of "If This, Then That" to trigger actions across different digital platforms and smart home devices.
Resilience scores
- Digital Sovereignty: 67
- Digital Resilience: 6
- Financial Resilience: 5
Disruption prediction
IFTTT has an estimated 11% probability of disruption in the next 6 months.
14 of IFTTT's 21 vendors monitored for disruptions.
Technology vendors
- HubSpot, Inc. — Technology — United States
- Statuspage (an Atlassian company) — Australia
- Stripe, Inc. — Financial Services — United States
- and 18 more
Services catalogue
2 services in catalogue across 2 categories; runs on 21 sub-vendors.
- Automation Platform
- IFTTT
Insights
Last updated 2026-08-11 · revision 2
21 direct vendors, 261 subvendors
Direct vendors by controlling owner country (sample)
- Japan: 1
- Germany: 1
- Australia: 3
Subvendors by controlling owner country (sample)
- Luxembourg: 1
- Unknown: 2
- Netherlands: 5
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
IFTTT demonstrates high migration readiness, primarily due to its existing adoption of Amazon Web Services (AWS), which signifies a cloud-aware operational model. The internal tech stack, including modern components like Ruby on Rails, React, MySQL, Redis, and Kafka, is generally compatible with cloud-native architectures and microservices, facilitating potential re-platforming efforts. The extensive use of REST APIs and Webhooks, alongside a 'No-Code / Low-Code Workflow Builder,' suggests a modular and well-integrated system that could be easier to decouple and migrate. The company's focus on AI/LLM integration and the Model Context Protocol (MCP) further indicates an agile development culture capable of adapting to new cloud services. However, several critical data gaps introduce potential challenges. The absence of information on the 'Regulatory Environment' and 'Data Residency Requirements' means potential compliance hurdles or geographical constraints for data movement are unknown. There is no data on financial stability, which is crucial for assessing the company's capacity to fund a significant migration. While vendor geographic diversity is a resilience strength, it could add complexity to managing contracts and relationships during a large-scale migration. The 'Vendor Lock-in Risk' is explicitly 'Unknown,' which is a significant concern, as high lock-in could make migrating away from certain services costly and time-consuming. Explicit mention of containerization or a fully microservices-based architecture is also absent, which, if not in place, could require additional effort for optimal cloud elasticity.
Compliance
6 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 (Information Security Management System) is highly relevant for IFTTT given its role as a cloud automation platform handling OAuth credentials, API keys, personal data, and acting as a trusted intermediary between sensitive services. The risk is Medium because: (1) No ISO 27001 certification has been publicly identified; (2) IFTTT's business model — acting as a broker between 1,000+ services including financial apps, smart home security, and communication platforms — creates significant information security risk exposure; (3) Enterprise customers and regulated-industry partners would typically require ISO 27001 or equivalent; (4) The absence of certification does not mean non-compliance with the standard's principles, but it does mean there is no independent verification. The risk is not High because IFTTT is a consumer-focused platform and ISO 27001 is not legally mandated for its sector.
Evidence: https://ifttt.com/privacy
GDPR (source) — Partially Compliant
IFTTT has made meaningful GDPR compliance efforts — including a dedicated GDPR trust page, a designated EU representative (DP-Dock GmbH in Hamburg, Germany), a designated UK representative (DP Data Protection Services UK Ltd.), a dedicated GDPR contact email (IFTTT@gdpr-rep.com), and documented data subject rights (access, rectification, erasure, portability, objection, restriction). However, the privacy policy explicitly states the service 'does not support Do Not Track requests,' and data is hosted exclusively on US servers with transfers authorized by user consent rather than Standard Contractual Clauses (SCCs) or other adequacy mechanisms being explicitly cited. The policy also acknowledges sharing data with ad networks and third-party analytics providers, which raises questions about lawful basis documentation. The risk is Medium rather than High because IFTTT has clearly invested in GDPR infrastructure, but gaps in transfer mechanism transparency and Do Not Track non-support create residual risk. IFTTT serves users in 190+ countries including EU/EEA residents, making GDPR unambiguously applicable.
Evidence: https://ifttt.com/privacy, https://www.dp-dock.com
CPRA — Partially Compliant
IFTTT is incorporated and headquartered in San Francisco, California, making CCPA/CPRA directly applicable. IFTTT's privacy policy includes a 'Your California Privacy Rights' section, which is a positive indicator. However, the section is notably brief and states only that IFTTT does not share personal information with third parties for direct marketing purposes — it does not address the full scope of CCPA/CPRA rights including the right to know, right to delete, right to opt-out of sale/sharing, right to correct, or right to limit use of sensitive personal information. The risk is Medium because: (1) IFTTT is a California company subject to CCPA/CPRA; (2) The California Privacy Rights Act (effective January 2023) expanded CCPA significantly; (3) IFTTT's privacy policy does not appear to have been fully updated to reflect CPRA requirements; (4) IFTTT shares data with ad networks and analytics providers, which may constitute 'sharing' under CPRA's expanded definition.
Evidence: https://ifttt.com/privacy
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 5/10
IFTTT Inc. is a privately held US company that does not file with the SEC and does not publish audited financial statements, making direct assessment of financial resilience difficult. The company has raised approximately US$63M in venture funding across seed, Series A (2012, ~$7M from Andreessen Horowitz), Series B (2014, ~$30M from Norwest), and Series C (2018, ~$24M from IBM Ventures and Salesforce Ventures). No fresh capital raise has been publicly disclosed since 2018, which could indicate either self-sustaining cash flow or constrained investment capacity. Strengths include a large established user base (10M+ app downloads across 190+ countries), a diversified catalog of 1,000+ integrated services creating network effects, dual revenue streams from consumer subscriptions (IFTTT Pro/Pro+) and B2B partner integrations, and timely positioning in the AI-agent ecosystem via the new IFTTT MCP product. The capital-efficient SaaS model provides low marginal costs. However, IFTTT faces significant competitive pressure from better-funded automation platforms like Zapier, Make, Microsoft Power Automate, n8n, Workato, and Pipedream. The business is highly dependent on third-party API access (as demonstrated by Twitter/X API pricing changes in 2023 disrupting integrations), and consumer freemium monetization has historically been challenging. Given the lack of disclosure and competitive pressures, a mid-range resilience score is warranted.
Key strengths: 10M+ mobile downloads and users in 190+ countries, 1,000+ integrated services creating network effects, Dual revenue streams: consumer subscriptions and B2B partner integrations, Approximately US$63M total venture funding raised to date, Timely AI-agent positioning via IFTTT MCP product, Capital-efficient SaaS business model
Risk factors: Intense competition from Zapier, Make, Microsoft Power Automate, n8n, Workato, and Pipedream, Heavy dependency on third-party APIs (e.g., Twitter/X API pricing changes in 2023), Difficulty monetizing freemium consumer users, No publicly disclosed capital raise since 2018, Opacity as a private company limits creditor/counterparty visibility, Platform risk from API access changes by Google, Meta, X, Amazon, etc.
Workforce by country
- United States: 75
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.