Infobip
Croatia · www.infobip.com · 29 vendors
Resilience scores
- Digital Sovereignty: 14
- Digital Resilience: 9
- Financial Resilience: 7
Technology vendors
- Anthropic, PBC — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Netlify, Inc. — Technology — United States
- and 29 more
Services catalogue
3 services in catalogue across 3 categories; runs on 29 sub-vendors.
- Infobip
- Personal Data Processing
- SMS/MMS Delivery Provider
Insights
Last updated 2026-08-14 · revision 1
29 direct vendors, 321 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 1
- Croatia: 1
- Denmark: 2
Subvendors by controlling owner country (sample)
- Denmark: 5
- Portugal: 2
- Unknown: 2
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Infobip exhibits very high migration readiness, largely driven by its cutting-edge and cloud-native internal tech stack. The extensive adoption of public cloud platforms (AWS, Azure), containerization technologies (Kubernetes, Docker), and infrastructure-as-code tools (Terraform, Chef, Ansible) signifies a highly modular, scalable, and portable infrastructure. The company's commitment to a microservices architecture, coupled with proficiency in a wide array of modern programming languages (Java, Kotlin, Go, Python, JavaScript) and robust CI/CD pipelines, ensures high agility and minimal technical debt, which are critical for seamless migration projects. While the lack of data on financial stability, specific regulatory environments, and data residency requirements introduces some unknowns, the inherent flexibility and modernity of the technology stack strongly position Infobip for efficient and successful migrations. The 'Vendor Lock-in Risk' is unknown, and the contradictory 'Total Vendors: 0' makes it difficult to assess vendor concentration, but the overall technological foundation suggests a high degree of independence and adaptability for future migrations.
Compliance
12 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 is the international assurance standard used for non-financial assurance engagements, including SOC 2 reports issued under IAASB standards (as opposed to AICPA AT-C 205). Infobip's SOC 2 Type 2 certification may be issued under ISAE 3000 (if conducted by a non-US auditor) or AICPA AT-C 205 (if by a US CPA firm). Given Infobip's European headquarters and the AICPA logo displayed on its certificates page, the SOC 2 report may be dual-standard (AICPA + ISAE 3000). Risk is Low because: (a) ISAE 3000 is a framework standard rather than a regulatory requirement with enforcement penalties; (b) Infobip's SOC 2 Type 2 certification already addresses the substantive assurance requirements; (c) no regulatory body mandates ISAE 3000 specifically for Infobip's sector. Status is 'Assessment Required' because the specific standard under which Infobip's SOC 2 report was issued (AICPA AT-C 205 vs. ISAE 3000) is not publicly disclosed.
Evidence: https://www.infobip.com/certificates
SOC 2 (source) — Compliant
Infobip has publicly confirmed SOC 2 Type 2 certification on its official certificates page. SOC 2 Type 2 is the most rigorous form of SOC 2 attestation, requiring an independent auditor to assess the design AND operating effectiveness of security controls over a defined period (typically 6-12 months). As a cloud-based CPaaS provider processing billions of interactions for 10,000+ enterprise clients, SOC 2 Type 2 is both highly relevant and actively maintained. Risk is Low because: (a) the certification is confirmed and publicly disclosed; (b) SOC 2 Type 2 demonstrates ongoing operational effectiveness of security controls (Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy); (c) the certification is complemented by ISO 27001, ISO 27017, ISO 27018, and CSA STAR Level 1; (d) enterprise clients routinely require SOC 2 Type 2 as a procurement prerequisite, creating strong commercial incentive for maintenance.
Evidence: https://www.infobip.com/certificates, https://cloudsecurityalliance.org/star/registry/infobip-ltd
GDPR (source) — Compliant
Infobip is headquartered in Croatia (EU member state) and operates as a large-scale CPaaS provider processing vast volumes of personal data on behalf of 10,000+ enterprise customers globally, including EU/EEA residents' data. GDPR is unambiguously applicable. Risk is rated Medium rather than High because Infobip demonstrates a mature, documented privacy program: published Privacy Notice, Cookie Policy, Data Transfer Agreement (EU SCCs + UK SCC Addendum), Sub-processors list, Data Retention Notice, EU region-locked data center (Schrems II compliant), AI Privacy Whitepaper, and a formal Privacy Rights Request Form. The company processes data both as a Controller (own marketing/HR) and as a Processor (on behalf of enterprise clients), which increases complexity and residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover, and enforcement by Croatian DPA (AZOP) and other EU supervisory authorities is active. The scale of data processing (billions of interactions) elevates inherent risk, but the documented compliance posture mitigates it to Medium.
Evidence: https://www.infobip.com/privacy-documents, https://www.infobip.com/policies/privacy-notice, https://www.infobip.com/policies/data-transfer-agreement, https://www.infobip.com/policies/processors, https://www.infobip.com/policies/data-retention-notice, https://cdn-web.infobip.com/uploads/2023/12/Infobips-privacy-program-whitepaper.pdf, https://cdn-web.infobip.com/uploads/2023/05/infobip_schrems_II_EU_region_locked_data_center_whitepaper.pdf, https://www.infobip.com/news/infobip-to-deploy-region-locked-eu-data-centre, https://www.infobip.com/certificates
Financials
Three-year financials
- 2024: revenue €1.9B
- 2023: revenue €1.78B
- 2022: revenue €1.60B
Financial Resilience Score: 7/10
Infobip demonstrates strong financial resilience underpinned by its position as a global leader in the CPaaS market, with consistent recognition as a Leader in Gartner Magic Quadrant (2022-2026), IDC MarketScape, and Omdia CPaaS Universe. The company has scaled to approximately €1.9B in revenue with a diversified global footprint across 190+ countries, 75+ offices, and 40+ data centers, serving blue-chip customers including Uber, Meta, Google, Adobe, Deutsche Telekom, and Santander. Its 20-year track record of self-funded growth from 2006 to 2020 (bootstrapped to ~$1bn revenue) evidences a disciplined operating culture and strong founder-led execution. However, the company faces structural challenges typical of CPaaS players, including thin gross margins (20-30% range) due to pass-through operator termination fees, and heavy concentration in A2P SMS revenue which is being pressured by WhatsApp/RCS substitution. The 2022 net loss, driven by aggressive M&A (OpenMarket $300m, Anam, Peerless Network) and higher financing costs post-Brookfield investment, highlights integration risk. Growth has decelerated from ~40% (2021→2022) to high-single-digit percentages by 2023-2024. The company returned to profitability in 2023-2024 and continues to strengthen its position through strategic acquisitions (SocketLabs 2026) and product innovation (AgentOS, RCS leadership), supported by strong PE backing from One Equity Partners and reportedly Brookfield.
Key strengths: Global CPaaS market leader recognized by Gartner, IDC, Omdia, Juniper, Diversified global footprint across 190+ countries and 75+ offices, Blue-chip enterprise customer base (Uber, Meta, Google, Adobe, Deutsche Telekom), 20-year track record of self-funded growth to ~$1bn revenue by 2020, Strong strategic investors (One Equity Partners, reportedly Brookfield), Broad product portfolio spanning SMS, RCS, WhatsApp, Voice, Email, AI agents, Returned to profitability in 2023-2024 after 2022 loss, First CPaaS to deliver RCS across all four major US carriers (2025)
Risk factors: Thin structural margins typical of CPaaS (20-30% gross margin), Heavy revenue concentration in A2P SMS facing WhatsApp/RCS substitution, M&A-driven balance sheet with increased goodwill and debt, 2022 net loss from acquisition integration, FX and financing costs, Delayed IPO (2022 postponed) limits liquidity for backers, Geographic exposure to emerging markets (LATAM, MENA, SEA) with FX and regulatory risk, AI disintermediation risk from hyperscalers (Meta, Google, Microsoft, Amazon), Growth deceleration from ~40% to high-single-digit percentages, Limited public financial disclosure as private Croatian d.o.o.
Revenue by product/service
- SMS/A2P Messaging: 70%
- WhatsApp/OTT Messaging: 15%
- Voice, Email, RCS, Viber and other channels: 8%
- SaaS/Customer Engagement Software: 4%
- Wholesale/Firewall (Anam Protect): 3%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.