IPify

United States · www.ipify.org · 7 vendors

Ipify (ipify.org) offers a free and open-source API that provides users with their public IPv4 and IPv6 addresses. It also offers an IP Geolocation API to retrieve detailed location information, which is utilized for various applications including content personalization, targeted advertising, and cybersecurity.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 7 sub-vendors.

Insights

Last updated 2026-08-15 · revision 2

7 direct vendors, 152 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

IPify exhibits a high degree of migration readiness due to its highly modern and cloud-native internal tech stack. The use of Go, Heroku, and Amazon Web Services (AWS), including CloudFront and S3, indicates a flexible, scalable, and potentially microservices-oriented architecture that significantly eases migration efforts. The reliance on REST APIs and open-source components like httprouter and GitHub further enhances portability and reduces dependency on proprietary systems. The geographic diversity of vendor headquarters (Denmark, United States, Sweden) could also simplify vendor management during a migration, especially if regional service shifts are required. However, the 'Vendor Lock-in Risk' is unknown; while the tech stack is modern, reliance on specific AWS services and Heroku could introduce some level of platform-specific lock-in, requiring effort to migrate to alternative providers. Critical data regarding specific regulatory environments and data residency requirements is missing, which could introduce significant complexity and cost to a migration project. Similarly, the absence of financial stability data (revenue concentration, growth history) makes it difficult to assess the company's capacity to fund a potentially large-scale migration. The 'Total Services: 8' suggests a number of integrations, the complexity of which is unknown and could impact migration timelines.

Compliance

6 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is the internationally recognized standard for information security management systems (ISMS). As a commercial API service provider processing customer account data, API keys, payment information, and IP geolocation data, ISO 27001 certification would be expected by enterprise customers and is a recognized best practice. Risk is MEDIUM because: (1) lack of certification signals potential gaps in formal information security governance, (2) the service handles sensitive data (payment info, API keys, user accounts) without publicly evidenced security controls, (3) enterprise customers increasingly require ISO 27001 as a vendor qualification criterion, and (4) a security incident without demonstrated ISMS could result in significant reputational and legal consequences.

Evidence: https://www.ipify.org, https://geo.ipify.org/privacy-policy, https://geo.ipify.org/payment-security-and-policy

GDPR (source) — Partially Compliant

IPify explicitly acknowledges GDPR in its privacy policy and processes IP addresses of EU/EEA residents through its globally accessible public API and IP Geolocation service (geo.ipify.org). Under GDPR, IP addresses are classified as personal data. The privacy policy acknowledges this: 'According to EU General Data Protection Regulation (GDPR) IP addresses and Dynamic IP addresses are considered Personal Data.' However, the policy lacks several GDPR-required elements: no Data Protection Officer (DPO) is identified, no lawful basis for processing is explicitly stated, no data subject rights mechanism (access, erasure, portability) is described, no data retention periods are specified, no mention of Standard Contractual Clauses (SCCs) or other transfer mechanisms for international data transfers, and no cookie consent mechanism is described despite acknowledging cookie use. The risk is HIGH because: (1) the service is globally used and processes EU resident IP data at scale, (2) enforcement by EU DPAs has intensified, (3) fines can reach €20M or 4% of global annual turnover, and (4) the identified compliance gaps are material.

Evidence: https://geo.ipify.org/privacy-policy, https://www.ipify.org, https://geo.ipify.org/terms-of-service

COPPA — Compliant

IPify explicitly states COPPA compliance in its privacy policy and prohibits use by anyone under 13 years of age. The service does not target children and has implemented age restrictions. Risk is LOW given the explicit compliance statement and the nature of the service (developer/technical API tool not directed at children).

Evidence: https://geo.ipify.org/privacy-policy

Financials

Three-year financials

Financial Resilience Score: 6/10

IPify is a hybrid entity: a free, open-source public IP API project self-funded by its creator Randall Degges since 2014, coupled with a small commercial IP Geolocation API business (GEO IPIFY). No financial statements are published, as the entity is privately held, not SEC-registered, and has no investor relations disclosures. Qualitatively, the operation appears to have an extremely low cost structure, with the free core service running as a stateless Go binary on Heroku serving 30+ billion requests/month. From a resilience standpoint, IPify benefits from no debt, no investor pressure, and a creator-funded model with a strong brand moat as one of the most widely embedded public-IP endpoints on the internet. However, meaningful risks exist including key-person dependency, single-vendor infrastructure concentration on Heroku/Salesforce, competitive pressure on the paid geolocation product from established players like MaxMind and IPinfo, and a capped monetization ceiling due to the free-by-design core product. The lack of any disclosed revenue, headcount, or entity structure makes independent verification of commercial scale impossible.

Key strengths: Extremely low cost structure — stateless Go binary on Heroku, No debt, no investors, no burn pressure — creator-funded, Strong brand moat with 30+ billion requests/month, Complementary paid Geolocation API monetizes free traffic funnel, Open-source resilience (MIT/Unlicense)

Risk factors: Key-person risk — effectively supported by one individual, No disclosed revenue base — impossible to assess liquidity/runway, Single infrastructure provider concentration (Heroku/Salesforce), Competitive pressure from MaxMind, IPinfo, ipapi, ipgeolocation.io, IP2Location, Monetisation ceiling — core product is free by design, Governance/entity opacity — legal entity behind 'GEO IPIFY' not clearly disclosed

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report