IoTeX

United States · iotex.io · 14 vendors

IoTeX is a decentralized, open-source blockchain platform focused on connecting real-world data and smart devices with artificial intelligence (AI) and decentralized applications. It provides modular infrastructure, including a Layer-1 blockchain, for building and powering next-generation AI models and applications that leverage verifiable, real-time data from physical networks. The platform aims to enable an ecosystem where machines, humans, businesses, and applications can interact with trust and privacy.

Resilience scores

Disruption prediction

IoTeX has an estimated 27% probability of disruption in the next 6 months.

8 of IoTeX's 14 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 14 sub-vendors.

Insights

Last updated 2026-08-14 · revision 2

14 direct vendors, 188 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

IoTeX exhibits very high migration readiness due to several key factors. Its internal tech stack is highly modern and conducive to migration, featuring explicit use of Docker for containerization and protocols like gRPC and Protocol Buffers, which are foundational for microservices architectures. The adoption of modern programming languages such as Go, Rust, Python, and JavaScript/TypeScript further supports agile development and cloud-native deployments. The decentralized nature of its core products, including a Layer-1 EVM-Compatible Blockchain and DePIN infrastructure, inherently promotes a distributed and modular architecture that aligns well with cloud environments. The most critical factor for its high migration readiness is the stated 'Total Vendors: 0'. This indicates a profound lack of vendor lock-in, significantly simplifying any potential migration by removing the complexities of managing external vendor contracts, proprietary technologies, and dependencies. This drastically reduces the cost and effort typically associated with large-scale migrations. The primary limitations to a perfect score are the unspecified regulatory environment and data residency requirements, which are crucial considerations for migration planning and could introduce unforeseen challenges. Additionally, financial stability data is missing, which could impact the ability to fund a large-scale migration project.

Compliance

9 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

IoTeX Technology explicitly acknowledges GDPR applicability in its Privacy Policy (last updated June 1, 2025), citing legal bases for processing EU/EEA and UK residents' personal data (consent, legitimate interests, legal obligations, vital interests). However, several significant gaps elevate risk: (1) The privacy policy references a Cookie Notice that is blank ('__________'), indicating an incomplete compliance framework; (2) No Data Protection Officer (DPO) appointment is disclosed, which may be required given the scale of global data processing (25M+ DePIN devices); (3) International data transfers to the US are acknowledged but no Standard Contractual Clauses (SCCs) or adequacy decisions are referenced; (4) The legal entity is registered in the British Virgin Islands, creating jurisdictional complexity for EU data subjects seeking redress; (5) No GDPR audit or certification evidence found. The global scale of IoTeX's operations (25M+ devices, 399 ecosystem projects) and the nature of IoT/DePIN data (which may include location, device behavior, and potentially personal data from physical machines) significantly elevates GDPR risk. Fines can reach €20M or 4% of global annual turnover.

Evidence: https://iotex.io/privacy, https://iotex.io/terms, https://ec.europa.eu/newsroom/article29/items/612080, https://ico.org.uk/make-a-complaint/data-protection-complaints/data-protection-complaints/

CCPA — Partially Compliant

IoTeX Technology's Privacy Policy (last updated June 1, 2025) includes a dedicated CCPA section acknowledging California residents' rights (right to know, delete, opt-out, non-discrimination). The company explicitly states it has not sold or shared personal information to third parties. However, compliance gaps exist: (1) The Cookie Notice referenced in the privacy policy is blank ('__________'), which is a material gap for CCPA compliance; (2) No 'Do Not Sell or Share My Personal Information' link was identified on the website; (3) The company's BVI registration creates uncertainty about CCPA threshold applicability (annual gross revenue >$25M, or data on 100,000+ consumers). Medium risk because the company has made good-faith CCPA disclosures but has material gaps in implementation.

Evidence: https://iotex.io/privacy, https://iotex.io/terms

SOC 2 (source) — Assessment Required

IoTeX Technology operates cloud-based blockchain infrastructure services, a mobile wallet (ioPay), W3bstream (IoT data processing), and various digital platforms serving 25M+ DePIN devices and 399 ecosystem projects. As a technology infrastructure provider processing data for enterprise and developer clients, SOC 2 compliance would be highly relevant and expected by institutional partners and enterprise customers. The absence of any publicly disclosed SOC 2 report or certification is a notable gap for a company of this scale and profile. Medium risk is assigned because: (1) the company's infrastructure role makes SOC 2 highly relevant; (2) lack of SOC 2 may limit enterprise adoption; (3) no evidence of compensating controls or alternative assurance frameworks was found. The risk is not High because IoTeX's primary products are decentralized/blockchain-based, which may reduce traditional SOC 2 applicability for some components.

Evidence: https://iotex.io, https://iotex.io/privacy

Financials

Three-year financials

Financial Resilience Score: 4/10

IoTeX is a private blockchain foundation/protocol that does not publish audited financial statements, has no SEC filings, and does not disclose revenue, EBIT, or equity. Assessment must therefore rely on token treasury value, ecosystem activity, and disclosed fundraising history rather than GAAP figures. The project has an established multi-year operating history since 2017, which is long-lived for a crypto project, and has demonstrated ecosystem traction with 25M+ connected devices, ~399 ecosystem projects, and a self-reported US$5B+ aggregate ecosystem market value as of 2025. However, financial resilience is materially constrained by dependence on IOTX token economics. Chain fees, staking rewards, and treasury value are all denominated in IOTX, which has traded from an all-time high of ~US$0.26 (Nov 2021) to roughly US$0.02–0.05 in 2023–2025—implying significant treasury drawdowns. Historical fundraising of ~US$30M (2018 token sale) and a US$50M ecosystem fund (2021) provided initial capitalization, but current cash reserves and burn rate are unverifiable. Regulatory uncertainty around DePIN tokens and staking, combined with concentration risk to a small number of large DePIN partners and broader crypto market cycles, further limits resilience visibility. The score reflects the absence of transparency more than confirmed weakness.

Key strengths: Multi-year operating history since 2017, Token treasury from 10B IOTX supply cap held by foundation, ~US$30M raised in 2018 token sale plus US$50M ecosystem fund (2021), Ecosystem traction: 25M+ DePIN devices, ~399 projects, US$5B+ aggregate ecosystem market value (2025), Low fixed cost footprint as a protocol/foundation, Positioned in active DePIN and AI narratives

Risk factors: No audited financials or SEC disclosures, Revenue model dependent on IOTX token economy, IOTX price volatility (from ~US$0.26 peak to US$0.02–0.05 range), Regulatory risk around DePIN tokens and staking, Concentration risk to large DePIN partners and crypto market cycles, No visibility into cash reserves, runway, or burn rate

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report