IntraNote

Denmark · owned by Independent (Denmark) · www.intranote.dk · 10 vendors

IntraNote develops, advises, and implements user-friendly software through Enterprise Content Management (ECM) solutions. These solutions gather and store a company's knowledge and data, including correspondence, information, and documentation, in one secure place. The company focuses on intranet and document handling to optimize workflows and facilitate knowledge sharing for public and private organizations.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 1

10 direct vendors, 176 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

IntraNote's migration readiness is assessed at 40, indicating a moderate level of readiness with significant challenges. **Challenges:** * **Traditional Tech Stack & Architecture:** The primary challenge stems from a tech stack heavily reliant on traditional Microsoft enterprise technologies (Microsoft IIS, SQL Server, Windows Server) and deployment models (private cloud/on-premises). This suggests a potentially monolithic architecture for flagship products like DocuNote and IntraNote WorkSpace. Migrating such systems to a modern public cloud environment (especially beyond a simple lift-and-shift to IaaS) would require substantial re-platforming, refactoring, or re-architecting, which is time-consuming and costly. * **Regulatory Compliance Complexity:** While a strength for resilience, the strong regulatory environment (GDPR, ISAE 3000, NIS2) adds complexity to migration. Ensuring continued compliance with data residency, security controls, and auditability in a new cloud provider's infrastructure requires meticulous planning and validation. * **Financial Stability (Unknown):** The absence of data on financial stability (revenue concentration, growth) makes it difficult to assess IntraNote's capacity to fund a potentially large and complex migration project. * **Platform Lock-in:** Despite assumed geographic vendor diversity, there is a high degree of platform lock-in to the Microsoft ecosystem. While this offers a clear migration path to Azure, it limits flexibility to explore other cloud providers without significant re-development. **Opportunities:** * **Microsoft Ecosystem Alignment:** The existing Microsoft .NET, C#, SQL Server, and Active Directory stack provides a clear and relatively smoother migration path to Microsoft Azure, leveraging existing skill sets and potentially reducing the learning curve for cloud adoption. * **Private Cloud Experience:** Experience with "Private Cloud Infrastructure" and "Private Cloud Solution" for WorkSpace indicates some familiarity with virtualized environments, which can be a stepping stone for public cloud migration.

Compliance

8 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Compliant

IntraNote explicitly and proactively obtains an annual ISAE 3000 assurance report from an independent third-party auditor. This is a strong compliance indicator. The ISAE 3000 report covers GDPR compliance, data protection provisions in EU law, member state national law, and the content of the Data Processing Agreement. The report is publicly available for download, demonstrating transparency. This is the primary third-party assurance mechanism used by IntraNote and is well-suited to the Danish/Scandinavian market. The risk level is low because the company has a documented, recurring, independent audit process in place.

Evidence: https://www.intranote.dk/compliance, https://www.intranote.dk/hubfs/Intranote%20ISAE-3000%202025.pdf

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for information security management systems (ISMS) and is highly relevant for a SaaS/cloud software provider like IntraNote that processes sensitive customer data (documents, contracts, personal data) for critical infrastructure clients. IntraNote has not publicly disclosed ISO 27001 certification. However, the company has implemented a structured Digital Security Program (GRC framework) and obtains annual ISAE 3000 assurance reports, which cover overlapping security controls. The absence of ISO 27001 certification represents a medium risk, particularly as NIS2-regulated customers (energy utilities) may increasingly require ISO 27001 from their ICT suppliers. The risk is partially mitigated by the ISAE 3000 audit and NIS2 registration.

Evidence: https://www.intranote.dk/compliance, https://www.intranote.dk/blog/nis2

NIS2 (source) — Compliant

IntraNote has proactively addressed NIS2 compliance in a highly documented manner. The company is formally registered with the Danish Agency for Digital Government (Digitaliseringsstyrelsen) under the NIS2 registration obligation for suppliers relevant to critical infrastructure. It maintains a structured Digital Security Program (GRC framework), an annual ISAE assurance report, and implements concrete technical controls (MFA, role-based access, logging, backup, continuous risk assessment). NIS2 became effective in Denmark on 1 July 2025. IntraNote's primary customer base includes energy and utility companies (water, heat, electricity) — sectors explicitly covered by NIS2 as Essential Entities — making IntraNote a relevant ICT supplier subject to NIS2 supply chain security requirements. The company's documented compliance posture and official registration significantly reduce residual risk.

Evidence: https://www.intranote.dk/compliance, https://www.intranote.dk/blog/nis2, https://www.intranote.dk/loesninger/brancher/forsyninger

Financials

Three-year financials

Financial Resilience Score: 6/10

IntraNote A/S is a long-established (since 2001) Danish enterprise software vendor with a stable, sticky product portfolio in document management, contract lifecycle management, digital signature, and intranet/collaboration. The company benefits from a diversified vertical exposure across Energy & Utilities, Education, Construction, Membership organisations, and Auditors, with a customer base that is predominantly Danish public-sector-adjacent institutions (utilities like Novafos, Biofos, VEKS, and over 100 educational institutions). These customers are typically low-credit-risk and have long tenure with high renewal rates on multi-year subscription/maintenance contracts, providing revenue predictability. Regulatory tailwinds from NIS2, GDPR, and increasing compliance requirements support structural demand for their document and contract management offerings. Recent M&A activity, including the January 2026 acquisition of TimeSolutions A/S (TimeView), signals growth ambition and suggests available capital or financing capacity. However, the exact financial figures (revenue, EBIT, equity) for the last three fiscal years could not be retrieved in this session and require pulling årsrapport PDFs from datacvr.virk.dk under CVR 25797620. As a small vendor, IntraNote competes against much larger players like Microsoft SharePoint/M365, cBrain (F2), Netcompany, EG, and KMD, creating scale disadvantages in R&D. The company is geographically concentrated in Denmark with a small Swedish presence, limiting addressable market. Customer concentration within verticals poses risk—churn of a single large logo could materially affect P&L. Technology transition from legacy on-prem ESDH to cloud/SaaS may cause margin compression during the transition period.

Key strengths: Long operating history since 2001 (~24 years), Sticky SaaS/on-prem product portfolio with multi-year subscription contracts, Diversified vertical exposure across utilities, education, construction, membership organisations, and auditors, Low-credit-risk Danish public-sector-adjacent customer base, Regulatory tailwinds from NIS2 and GDPR compliance requirements, Recent M&A activity (TimeSolutions acquisition Jan 2026) indicates growth capacity, Over 100 named educational institution customers

Risk factors: Small vendor competing against much larger players (Microsoft, cBrain, Netcompany, EG, KMD), Scale disadvantage on R&D investment, Geographic concentration in Denmark with limited Swedish footprint, Customer concentration risk within verticals, Technology transition risk from on-prem to cloud/SaaS causing potential margin compression, Limited ownership and financing transparency as a private A/S, Potential debt financing of TimeSolutions acquisition not yet visible, Possible residual related-party arrangements with Avidly marketing agency

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report