Invity.io
Czech Republic · invity.io · 12 vendors
Resilience scores
- Digital Sovereignty: 33
- Digital Resilience: 6
- Financial Resilience: 6
Technology vendors
- Anthropic, PBC — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Meta Platforms, Inc. — Technology — United States
- and 9 more
Services catalogue
1 service in catalogue across 1 category; runs on 12 sub-vendors.
- Invity.io
Insights
Last updated 2026-08-08 · revision 2
12 direct vendors, 206 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 1
- France: 1
- Czech Republic: 1
Subvendors by controlling owner country (sample)
- Belgium: 3
- Russia: 1
- Taiwan: 1
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Invity.io exhibits medium migration readiness. Key challenges include the highly regulated environment (MiCA, DORA), which will add significant complexity and cost to any migration effort, requiring meticulous planning to ensure continuous compliance. There is a high degree of vendor lock-in for core business functions due to reliance on critical third-party services such as BitGo for custody, SumSub for KYC/KYB, and Bank iD for local identity verification; migrating these would be complex and potentially costly. The absence of explicit information regarding cloud-native architecture, containerization, or microservices in the internal tech stack suggests that the backend infrastructure might not be fully optimized for easy cloud migration, potentially requiring significant re-architecting. Furthermore, the lack of data on financial stability makes it difficult to assess the company's capacity to fund a potentially expensive and resource-intensive migration. On the positive side, the absence of specified data residency requirements offers flexibility in choosing cloud regions or providers. The use of a modern static site generator like Astro for the main website indicates a component that would be relatively straightforward to migrate.
Compliance
9 in-scope frameworks identified; showing 3.
DORA (source) — Assessment Required
DORA (Regulation EU 2022/2554) applies to financial entities in the EU, including crypto-asset service providers authorised under MiCA, effective from 17 January 2025. Invity Finance s.r.o. explicitly references DORA compliance on its homepage, stating it 'adheres to the strict DORA regulation for cyber resilience.' This is a strong positive indicator. However, the status is 'Assessment Required' because: (1) DORA compliance is a complex, ongoing operational programme (ICT risk management, incident reporting, digital operational resilience testing, third-party ICT risk management) and self-declaration alone does not constitute verified compliance; (2) no independent DORA audit, assessment report, or regulatory confirmation of DORA compliance has been publicly disclosed; (3) DORA's third-party ICT risk management requirements are particularly relevant given Invity's reliance on BitGo (US-based custodian) and other technology providers. Risk is Medium because the company has publicly committed to DORA compliance and is under ČNB supervision (which enforces DORA), but the complexity of DORA requirements and the early stage of supervisory enforcement create uncertainty.
Evidence: https://invity.io, https://www.invity.io/about-us, https://www.invity.io/legal
EU Whistleblowing Directive — Compliant
The EU Whistleblowing Directive (2019/1937), transposed into Czech law, requires organisations with 50+ employees (or operating in financial services) to establish internal whistleblowing channels. Invity Finance s.r.o. has published a Whistleblowing Policy on its legal page, demonstrating compliance with this requirement. As a MiCA-licensed financial services entity, whistleblowing channel requirements apply regardless of employee count. Risk is Low because the company has publicly published its Whistleblowing Policy.
Evidence: https://www.invity.io/legal, https://www.invity.io/legal/whistleblowing-policy-en.pdf
MiCA — Compliant
Invity Finance s.r.o. has obtained a full MiCA licence from the Czech National Bank (ČNB), making it one of the first six entities in the Czech Republic to receive this authorisation. MiCA (Regulation EU 2023/1114) is the primary sector-specific regulation for crypto-asset service providers (CASPs) in the EU, covering authorisation, conduct of business, custody rules, conflicts of interest, order execution, and sustainability disclosures. The company explicitly states MiCA compliance on its website, in its FAQ, and in its legal footer. The risk level is Low because the company has achieved formal regulatory authorisation — the highest form of compliance evidence — and is actively supervised by the ČNB. The company publishes all MiCA-required documents (custody rules, execution policy, conflicts of interest policy, sustainability of crypto-assets, supported crypto-assets list, complaints procedure). Ongoing compliance risk exists as MiCA is a new regulation (fully applicable from December 2024) and supervisory expectations continue to evolve, but the formal licence significantly mitigates this risk.
Evidence: https://www.invity.io/about-us, https://www.invity.io/legal, https://invity.io, https://www.euro.cz/aktuality/cnb-udelila-prvnich-sest-krypto-licenci-celkem-si-o-ni-zazadalo-na-tri-sta-subjektu/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Invity Finance s.r.o. is a newly created 2025 entity that has been materially strengthened by a CZK 120M capital injection, split evenly between new investors (Michal & Pavla Nýdrle and Radek Janeček) and the original SatoshiLabs founders. This fresh equity provides significant runway for a small-scale operator entering its first full year as an independent, regulated financial-services entity. The MiCA licence granted by the Czech National Bank in 2026 — among the first six issued in Czechia out of ~300 applications — represents a meaningful regulatory moat and enables EEA-wide passporting. The backing of SatoshiLabs (Trezor) provides brand credibility, technical talent, and cross-sell opportunities with the hardware wallet ecosystem. Cumulative platform volume exceeds USD 2 billion since 2019 with over 30,000 users, demonstrating product-market fit. Segregated custody with BitGo and DORA-compliant cyber resilience reduce operational risk, and the Bitcoin-only focus (no altcoins, no leverage) limits regulatory and reputational tail risk. However, resilience is constrained by high revenue sensitivity to the Bitcoin price cycle, small scale versus EU competitors like Bitpanda, Kraken, and Coinbase, and structurally high MiCA/DORA compliance costs. The novel Turbo Buy product introduces market-price exposure that must be hedged carefully. Limited historical financial transparency as a standalone entity and concentration on a single asset (BTC) plus a single custody counterparty (BitGo) further temper the score.
Key strengths: CZK 120M capital injection in October 2025 strengthens balance sheet, MiCA licence from Czech National Bank (among first 6 in Czechia), Backing from SatoshiLabs/Trezor brand and technical expertise, Cumulative platform volume >USD 2 billion since 2019, >30,000 users with 4.8 App Store rating, Segregated custody with BitGo and DORA-compliant resilience, Bitcoin-only focus reduces regulatory tail risk, Product diversification: Auto Buy, Turbo Buy, Auto Send, Loans, Business accounts
Risk factors: High revenue sensitivity to Bitcoin price cycle, Small scale (~30k users) vs larger EU competitors (Bitpanda, Kraken, Coinbase), High MiCA + DORA compliance costs pressure margins, Turbo Buy product introduces market-price and operational-loss exposure, Limited historical financial transparency as standalone entity, Single-asset (BTC) concentration risk, Custody counterparty risk concentrated on BitGo, No standalone audited profitability track record
Revenue by geography
- Nordics: 0%
- DACH region: 0%
- Czech Republic: 0%
- Southern Europe: 0%
Revenue by product/service
- Loans: 0%
- Business accounts: 0%
- Referral/affiliate: 0%
- Bitcoin buy/sell transaction fees: 0%
- Turbo Buy (extra buying power fees): 0%
Workforce by country
- Czech Republic: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.