InReality

Denmark · owned by Independent (Denmark) · inreality.io · 6 vendors

InReality is a Danish technology company that cryptographically signs and verifies real digital content — including images, videos, audio, and text — at or near the point of capture, enabling anyone to confirm that content is authentic, unaltered, and not a deepfake. Rather than detecting fakes, InReality's patented technology proactively signs genuine content so its authenticity can be independently verified downstream. The company targets industries that cannot afford to be wrong, with initial solutions focused on insurance fraud prevention and trusted news publishing.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 2

6 direct vendors, 142 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

InReality's migration readiness is assessed as medium-low, scoring 45. The primary challenges stem from critical data gaps. The regulatory environment, specifically NIS2 compliance, and data residency requirements are unknown, which are fundamental considerations that can significantly impact migration strategy, architecture, and cost. The absence of financial data (revenue concentration, growth history) also makes it impossible to gauge their capacity to fund a potentially complex migration project. Regarding their tech stack, while it incorporates modern cybersecurity standards (C2PA, CAWG) and SDK-based integrations, there is no explicit mention of cloud-native architecture, containerization, or microservices. This suggests that a migration might require substantial refactoring efforts rather than a straightforward lift-and-shift, increasing complexity and cost. The vendor relationships, while showing some geographic diversity for 7 services, have an unknown vendor lock-in risk, which could complicate disentanglement from existing service providers. The contradictory 'Total Vendors: 0' data point adds ambiguity, but assuming they rely on external services, the unknown lock-in is a concern. Opportunities for migration could arise from the modularity suggested by SDK-based integrations and adherence to open standards, but these are overshadowed by the significant unknowns.

Compliance

10 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SOC 2 is not a legal requirement but is a critical commercial and trust framework for cloud/SaaS providers. Risk is Medium because: (1) InReality operates a cloud-based cryptographic signing and verification platform — exactly the type of service for which enterprise clients (insurance companies, news organisations) routinely require SOC 2 Type II reports before procurement; (2) InReality's insurance sector clients are themselves heavily regulated and will likely demand evidence of security controls; (3) Without SOC 2 certification, InReality may face significant commercial barriers when selling to enterprise clients, particularly in regulated industries; (4) As an early-stage startup, the absence of SOC 2 is understandable but represents a growing commercial risk as they scale; (5) The risk is Medium rather than High because SOC 2 is not legally mandated and non-compliance does not carry regulatory fines — the risk is primarily commercial/reputational.

Evidence: https://inreality.io/product, https://inreality.io/solutions/insurance, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy

DORA (source) — Assessment Required

DORA applies directly to financial sector entities and indirectly to their ICT third-party providers. Risk is Medium because: (1) InReality's insurance sector clients are financial entities subject to DORA (applicable from January 17, 2025); (2) As an ICT third-party service provider to insurance companies, InReality will be subject to DORA's third-party risk management requirements through contractual obligations; (3) If InReality's services are classified as 'critical' by insurance clients, they may be subject to oversight by financial supervisory authorities; (4) InReality is not itself a financial entity, so direct DORA obligations are limited; (5) Risk is Medium because the indirect obligations through client contracts are real and growing, particularly as DORA enforcement ramps up in 2025.

Evidence: https://inreality.io/solutions/insurance, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554, https://www.eba.europa.eu/regulation-and-policy/digital-operational-resilience-act-dora

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for information security management and is highly relevant to InReality's business model. Risk is Medium because: (1) InReality's core value proposition is cryptographic security and content authenticity — their clients' trust in the product depends entirely on the security of InReality's own systems; (2) A security breach of InReality's signing infrastructure would be catastrophic for their business model and client trust; (3) Insurance and news sector clients will increasingly require ISO 27001 certification as a procurement prerequisite; (4) Without certification, InReality faces commercial risk in enterprise sales; (5) Risk is Medium rather than High because ISO 27001 is not legally mandated and the company is early-stage. However, given that security IS their product, the reputational risk of a security incident without a certified ISMS is particularly acute.

Evidence: https://inreality.io/product, https://inreality.io/resources/blog/inreality-selected-for-deloitte-innovation-accelerator, https://www.iso.org/standard/27001, https://www.ds.dk/en

Financials

Three-year financials

Financial Resilience Score: 4/10

InReality is an early-stage Danish deep-tech company operating in the content authenticity and cybersecurity space. The company benefits from a strong non-dilutive funding stack including grants from Innovationsfonden and DIREC Denmark, which reduces equity burn and validates the technology thesis. Backing from Antler, participation in Deloitte's Innovation Accelerator, membership in C2PA, and inclusion in the IBC Accelerator provide strong external validation and lower reputational and go-to-market risk. The patented core technology supports defensibility, and the capital-light SaaS/API delivery model implies limited capex requirements. However, the company is very likely pre-revenue or in very early revenue stages, with cash runway dependent on continued grant funding and follow-on venture rounds. As a Danish ApS at this stage, it typically operates with negative EBIT and negative retained earnings. Category risk is significant given that C2PA is being pushed by much larger participants like Adobe, Microsoft, and the BBC. Customer concentration is likely high with only a small number of pilot customers in insurance and broadcasting. Additionally, if losses continue, equity could fall below the DKK 40,000 minimum share capital threshold for an ApS, requiring recapitalization. Overall, resilience is moderate-to-low given early-stage status, but supported by diversified non-dilutive funding sources.

Key strengths: Non-dilutive grant funding from Innovationsfonden and DIREC Denmark, Antler backing and Deloitte Innovation Accelerator membership, C2PA contributing member status for international content-provenance standard, Patented core technology providing defensibility, Capital-light SaaS/API delivery model, Topical problem space with growing demand for deepfake/authenticity solutions, IBC Accelerator participation for live-video signing

Risk factors: Pre-revenue or very early revenue stage, Cash runway dependent on continued grants and follow-on venture rounds, Competition from much larger C2PA participants (Adobe, Microsoft, BBC), High customer concentration among small number of pilot customers, Regulatory dependency on EU AI Act enforcement, Small equity base at risk of falling below DKK 40,000 ApS minimum, Likely negative EBIT and accumulated losses typical of seed-stage companies

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report