InnoCraft

New Zealand · innocraft.com · 27 vendors

InnoCraft Ltd is the creator and maker of Matomo, an open-source web analytics platform. The company provides Matomo Analytics support plans, a cloud-hosted managed service, and premium features to help businesses with their digital analytics needs.

Resilience scores

Disruption prediction

InnoCraft has an estimated 10% probability of disruption in the next 6 months.

13 of InnoCraft's 27 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 27 sub-vendors.

Insights

Last updated 2026-07-30 · revision 3

27 direct vendors, 266 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 10/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

InnoCraft exhibits exceptionally high migration readiness, primarily due to its advanced and cloud-native technology stack and the implied minimal vendor lock-in. The company's internal tech stack, featuring AWS, Kubernetes, Docker, Infrastructure as Code (IaC), and CI/CD pipelines, signifies a highly modern, agile, and containerized environment. This architecture is inherently designed for portability and efficient migration to different cloud environments or platforms. The existence of "Matomo Cloud" as a fully managed SaaS offering further demonstrates their operational expertise in cloud environments. The regulatory environment, with GDPR compliance and ISO 27001:2022 certification, indicates a mature approach to data governance and security. While this can add rigor to migration planning, it also means InnoCraft has established processes to handle complex compliance requirements, which is a significant asset during any migration. Regarding vendor relationships, the data states "Total Vendors: 0," which, if taken literally, suggests an absence of formal vendor lock-in, providing maximum flexibility for migration. Even if interpreted as using various service providers without formal vendor contracts, the "Total Services: 37" from "10 unique countries" points to a highly diversified service consumption landscape. This diversity reduces dependency on any single provider or technology, thereby lowering the complexity and risk associated with migrating away from specific vendor solutions. The primary limitations in this assessment are the lack of specific financial data, which makes it difficult to gauge the company's capacity to fund a significant migration effort, and the "Not specified" status for data residency requirements. While their Matomo Cloud is hosted in Europe, potential new or stricter data residency mandates could introduce complexities if not proactively addressed. However, these are minor considerations compared to the overwhelming strengths in their technical architecture and vendor independence, positioning InnoCraft for highly efficient and flexible migrations.

Compliance

8 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 is relevant for organizations that provide assurance reports on non-financial information, including privacy and security controls. For a SaaS provider like InnoCraft, ISAE 3000 could be relevant as the basis for a privacy or security assurance report (e.g., an ISAE 3000 Type II report on data processing controls, which is common in European markets as an alternative or complement to SOC 2). Risk is Low because: (1) ISAE 3000 is not a mandatory regulatory requirement for InnoCraft's sector; (2) SOC 2 (AICPA framework) is more commonly requested by InnoCraft's likely customer base; (3) no evidence of ISAE 3000 engagement has been found; (4) the company's primary assurance vehicle appears to be its Vanta Trust Center and published DPA.

Evidence: https://trust.matomo.org/, https://matomo.org/matomo-cloud-dpa/

NIS2 (source) — Assessment Required

NIS2 applies to entities operating within the EU that meet sector and size thresholds. InnoCraft is headquartered in New Zealand, not the EU. However, it has remote employees in Germany, Austria, and France, and its Matomo Cloud infrastructure is hosted in Europe. NIS2 could potentially apply if InnoCraft is considered to offer services within the EU as a 'digital provider' (specifically as a managed service provider or digital service provider under Annex II). The company's size (exact employee count and revenue not publicly disclosed) and whether it meets the 50+ employee or €10M+ turnover threshold is uncertain. Risk is assessed as Low because: (a) InnoCraft is not HQ'd in the EU; (b) it is a relatively small/medium analytics SaaS company, not a critical infrastructure operator; (c) its primary sector (web analytics software) is not among the Essential Entity sectors; (d) as a digital provider it may fall under Important Entities but only if it meets size thresholds and is deemed to 'provide services in the EU.' A formal legal assessment is required to determine if NIS2 obligations apply given the EU-hosted infrastructure and EU-based employees.

Evidence: https://matomo.org/faq/new-to-piwik/who-is-innocraft/, https://trust.matomo.org/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

SOC 2 (source) — Assessment Required

InnoCraft operates Matomo Cloud, a SaaS analytics platform that processes customer data in cloud infrastructure hosted in Europe. SOC 2 is highly relevant for cloud service providers, particularly those serving enterprise customers who require third-party assurance over security, availability, processing integrity, confidentiality, and privacy controls. The existence of a Vanta-powered Trust Center (trust.matomo.org) strongly suggests InnoCraft is actively pursuing or maintaining SOC 2 compliance, as Vanta is a leading SOC 2 automation platform. However, no publicly available SOC 2 Type I or Type II report has been confirmed. Risk is Medium because: (1) enterprise customers increasingly require SOC 2 reports as a vendor due diligence requirement; (2) absence of a confirmed SOC 2 report could be a commercial barrier and indicates a compliance gap; (3) the Vanta Trust Center suggests the company is aware of this requirement and working toward it.

Evidence: https://trust.matomo.org/, https://matomo.org/matomo-cloud-dpa/, https://matomo.org/security/

Financials

Three-year financials

Financial Resilience Score: 6/10

InnoCraft Ltd is a privately held, founder-led New Zealand SaaS company that operates as the commercial arm behind Matomo Analytics. The business model benefits from recurring SaaS subscription revenue via Matomo Cloud, annual on-premise support contracts, and premium plugin sales, providing predictable cash flows. The company has a large installed base (1.4 million+ websites in 190+ countries) and benefits from strong structural tailwinds from EU privacy regulation (GDPR, Schrems II), with several EU member states declaring Google Analytics unlawful — positioning Matomo as a compliant alternative. Its NZ domicile also confers GDPR adequacy status under Article 45. Qualitative signals suggest a disciplined, bootstrapped operation with no evidence of large VC rounds or debt, and the achievement of ISO 27001:2022 certification in 2025 supports upmarket enterprise sales into banking and fintech verticals. However, quantitative financial data (revenue, EBIT, equity) is not in the public domain because InnoCraft sits below New Zealand's mandatory financial-reporting thresholds (NZ$66m assets / NZ$33m revenue) and does not voluntarily publish accounts. Risks include intense competition from free Google Analytics and privacy-first rivals (Plausible, Fathom, Piwik PRO), cannibalisation from Matomo's own open-source version, small scale relative to well-funded competitors, FX exposure (revenue in EUR/USD, costs partly in NZD), and key-person risk concentrated in the two co-founders. The lack of financial transparency also limits external stakeholders' visibility into runway and solvency, warranting a middle-of-the-range resilience score.

Key strengths: Recurring SaaS subscription revenue via Matomo Cloud, Large installed base of 1.4 million+ websites across 190+ countries, Structural tailwinds from EU privacy regulation (GDPR, Schrems II), NZ domicile provides GDPR adequacy status under Article 45, ISO 27001:2022 certification (2025) supports enterprise sales, Diversified go-to-market: cloud, on-premise support, marketplace plugins, enterprise services, Bootstrapped/independent with no evidence of large VC rounds or debt

Risk factors: Competitive pressure from dominant Google Analytics (free) and privacy-first rivals (Plausible, Fathom, Piwik PRO), Open-source cannibalisation — free self-hosted product limits willingness-to-pay, Small scale with limited financial cushion versus well-funded competitors, FX exposure (revenue in EUR/USD, costs partly in NZD), Key-person risk concentrated in co-founders Matthieu Aubry and Thomas Steur, Regulatory dependence — changes to EU adequacy status for NZ could impact positioning, Limited financial transparency as a private entity with no obligation to publish accounts

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report