Incsub
United States · incsub.com · 33 vendors
Resilience scores
- Digital Sovereignty: 67
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Netlify, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 31 more
Services catalogue
1 service in catalogue across 1 category; runs on 33 sub-vendors.
- Smush
Insights
Last updated 2026-08-13 · revision 1
33 direct vendors, 359 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 2
- Slovenia: 1
- Denmark: 2
Subvendors by controlling owner country (sample)
- Ireland: 2
- Cyprus: 1
- Denmark: 6
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Incsub's migration readiness is assessed at 55, indicating a medium level of readiness. A significant advantage for potential migration is the company's existing robust compliance framework, including SOC 2 Type II, GDPR, FERPA, and WCAG. These established standards and processes would streamline the regulatory aspects of migrating to a new cloud environment. Additionally, the company's engagement with 25 services from vendors across 5 unique countries suggests a diversified vendor landscape, which generally reduces the risk of heavy vendor lock-in and offers more flexibility during a migration, aligning with the principle that many vendors indicate lower lock-in. The primary challenge to migration readiness lies in the core internal tech stack, which is built around WordPress, WordPress Multisite, PHP, and MySQL. While widely used, this architecture is not inherently cloud-native, containerized, or microservices-based, which are characteristics of high migration readiness. Migrating a large, potentially customized WordPress Multisite environment can be complex and may require significant re-architecting or refactoring to fully leverage cloud-native benefits. The mention of "Managed WordPress Hosting" also suggests potential dependencies on specific hosting environments. Critical information regarding data residency requirements is not specified, which is a crucial factor in cloud migration planning. Furthermore, the company's financial stability (revenue concentration, growth history) is unknown, impacting the ability to fund a potentially large-scale migration project. The explicit vendor lock-in risk is also stated as "Unknown," which introduces an element of uncertainty despite the observed vendor diversity.
Compliance
8 in-scope frameworks identified; showing 3.
CPRA — Partially Compliant
Incsub's privacy policy explicitly addresses California residents' rights under CCPA/CPRA, including the right to access, know, delete, opt-out of sale, portability, and non-discrimination. The company states it does not sell personal information. However, full CCPA/CPRA compliance requires formal data mapping, opt-out mechanisms for sharing (not just sale), and annual privacy policy updates. The company serves a global customer base including California residents. Risk is Medium because the company has acknowledged CCPA obligations and implemented key rights, but full operational compliance cannot be verified from public sources alone.
Evidence: https://incsub.com/privacy-policy/
GDPR (source) — Partially Compliant
Incsub (Incsub, LLC) is a US-based company that explicitly processes personal data of EU/EEA residents across its WPMU DEV, CampusPress, and Edublogs platforms. The company has taken meaningful steps toward compliance — including EU-U.S. Data Privacy Framework (DPF) certification, a published DPA process, a dedicated DPO email (dpo@incsub.com), data subject rights procedures, and a 48-hour breach notification policy. However, the company relies on the DPF as its primary cross-border transfer mechanism rather than Standard Contractual Clauses (SCCs) as a primary fallback, and the DPF remains subject to legal challenge. The privacy policy acknowledges GDPR rights (access, portability, erasure, restriction, objection, automated decision-making opt-out) for EU/EEA residents, but full compliance verification (e.g., Records of Processing Activities, DPIA documentation, formal DPO appointment status) cannot be confirmed from public sources alone. Risk is Medium rather than High because the company has demonstrably invested in compliance infrastructure and is not in a high-enforcement sector.
Evidence: https://incsub.com/privacy-policy/, https://www.dataprivacyframework.gov/, https://security.incsub.com/
COPPA — Partially Compliant
Incsub's Edublogs platform explicitly serves children under 13 in educational settings. COPPA applies to operators of websites or online services directed to children under 13, or that have actual knowledge they are collecting personal information from children under 13. Edublogs requires parental consent or teacher/school sponsorship for accounts of children under 13. The company states it does not collect sensitive data from children. However, full COPPA compliance requires verifiable parental consent mechanisms, specific data minimization practices, and FTC compliance. Risk is Medium because the company has implemented protective measures but full COPPA compliance verification requires deeper assessment.
Evidence: https://incsub.com/privacy-policy/, https://edublogs.org/
Financials
Three-year financials
- null:
Financial Resilience Score: 6/10
Incsub demonstrates qualitative hallmarks of a durable, bootstrapped SaaS business with nearly two decades of operating history since its founding in 2007. The company operates a diversified portfolio across three WordPress-focused brands (WPMU DEV, CampusPress, Edublogs) targeting distinct customer segments, which reduces single-product risk. Its recurring subscription model, blue-chip higher-education customer base (Yale, Cornell, UCL, LSE, University of Melbourne), and fully remote workforce structure suggest predictable revenue and low fixed overhead. The founder-led, internally-promoted culture is consistent with a lean, cash-flow-funded operation rather than a VC-dependent growth model. However, the resilience score is constrained by significant risks and the complete absence of public financial disclosure. As a US-domiciled LLC with no public securities, Incsub is not required to publish financials, and no revenue, EBIT, or equity figures are available. The business faces platform-dependence risk on the WordPress ecosystem, intense competition from well-funded rivals (Automattic, Elementor, WP Engine, Kinsta), education-budget cyclicality for CampusPress/Edublogs, and key-person risk given the small ~160-person workforce. The lack of visible external capital is operationally healthy but limits the war chest for downturns or acquisitions relative to VC/PE-backed peers.
Key strengths: Long operating history since 2007 (nearly two decades), Diversified portfolio across three brands (WPMU DEV, CampusPress, Edublogs), Blue-chip education customer base including Yale, Cornell, UCL, LSE, Recurring SaaS subscription revenue model with high gross margins, Fully remote workforce minimizing fixed real-estate costs, Bootstrapped, founder-led culture with internal-only management promotion
Risk factors: Platform dependence on WordPress ecosystem, Intense competition from well-funded rivals (Automattic, Elementor, WP Engine, Kinsta), Concentration in education sector exposes to K-12 and higher-ed budget cycles, No public financial disclosure limits external stakeholder visibility, Small workforce (~160) creates key-person risk in specialized engineering roles, No visible external capital limits war chest for downturns or acquisitions
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.