JCloud AS

Norway · jcloud.no · 32 vendors

JCloud AS is a Norwegian company that develops and sells cloud services and related offerings. The company also provides general consulting in internet, software development, accounting, and finance.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 32 sub-vendors.

Insights

Last updated 2026-03-04 · revision 5

32 direct vendors, 313 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

JCloud AS exhibits high migration readiness. A primary strength is its highly modern and cloud-native tech stack, encompassing PaaS, IaaS, SaaS, CDN, and AI/GPT services built on Open Source LLMs, REST, and WebSocket APIs. This architecture is inherently modular and adaptable, significantly easing migration efforts both to and from their platform. The explicit use of open-source LLMs further reduces proprietary vendor lock-in. The company demonstrates a robust understanding and management of a complex regulatory environment, including GDPR, NIS2, and PCI DSS, alongside clear data residency requirements with data centers in Norway. While these regulations can introduce constraints, JCloud's established processes for compliance are a strong asset for managing data movement and security during migration. The 'Integrations' product also indicates a platform designed for interoperability, facilitating connections with third-party systems. The geographic diversity of vendor headquarters across 11 countries suggests a potentially less concentrated vendor landscape, which can reduce the complexity and risk of vendor lock-in during migration. The main challenges or unknowns include the lack of financial stability data, which prevents an assessment of the company's capacity to fund large-scale migration initiatives. Additionally, the conflicting data regarding 'Total Vendors: 0' versus detailed vendor geographic information introduces ambiguity about the precise number of internal vendors and potential concentration, which could impact migration planning.

Compliance

7 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

GDPR applies with high certainty as JCloud AS is located in Norway (EEA member) and processes personal data as a cloud service provider handling customer data, employee data, and potentially EU/EEA resident data. Non-compliance can result in fines up to 4% of annual turnover or €20M. As a cloud provider, they are likely a data processor and potentially a data controller, making GDPR compliance critical. The company claims GDPR compliance on their website, but this requires verification through audit evidence.

Evidence: https://jcloud.no

PCI DSS (source) — Assessment Required

PCI DSS is likely applicable as JCloud AS appears to process payment card data (they mention Vipps payment issues in their news, indicating payment processing). As a cloud provider that may store, process, or transmit cardholder data, PCI DSS compliance is required. The company claims PCI compliance on their website. Non-compliance can result in fines from card brands and potential loss of ability to process payments.

Evidence: https://jcloud.no

SOC 2 (source) — Assessment Required

SOC2 is highly relevant for cloud service providers like JCloud AS as it demonstrates security, availability, processing integrity, confidentiality, and privacy controls. While not legally mandated, SOC2 compliance is often required by enterprise customers and can significantly impact business competitiveness. The risk is medium as lack of SOC2 may limit customer acquisition but won't result in regulatory fines.

Financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report