Keepit A/S

Denmark · owned by TRISTATE INVEST I ApS (Denmark) · keepit.com · 39 vendors

Keepit A/S is a Danish cloud data protection company that owns and operates a vendor-independent cloud platform purpose-built for backing up and recovering SaaS application data, including Microsoft 365, Salesforce, Google Workspace, and more. The company provides immutable, air-gapped backup and recovery services with no third-party sub-processors, supporting compliance with frameworks such as GDPR, NIS2, DORA, and HIPAA. Headquartered in Copenhagen, Denmark, Keepit serves customers globally through offices in the US, UK, Germany, Poland, France, Brazil, and the Netherlands.

Resilience scores

Disruption prediction

Keepit A/S has an estimated 21% probability of disruption in the next 6 months.

22 of Keepit A/S's 39 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 39 sub-vendors.

Insights

Last updated 2026-09-13 · revision 35

39 direct vendors, 349 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Keepit operates its own 'vendor-neutral' cloud infrastructure across multiple global data centers, suggesting a highly controlled and potentially custom-built environment. This implies internal expertise in managing complex distributed systems. Their focus on 'blockchain-verified' data integrity and a 'private cloud infrastructure' indicates a modern, resilient, and likely containerized or microservices-based architecture. The 'vendor-neutral' aspect also suggests minimal lock-in to a single public cloud provider, enhancing their migration readiness to different underlying infrastructures. (Confidence: Medium, Inferred from architectural descriptions and service offerings, not explicit tech stack details)

Compliance

8 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Compliant

As a provider of backup and recovery services, customers in the technology sector expect internationally recognized information security standards. ISO 27001 is a key requirement for enterprise customers.

For a data protection company, lacking this fundamental security certification would be a major commercial disadvantage and could deter enterprise customers. A security breach would have severe reputational and financial consequences.

Evidence: https://scsd.ch/events-safe-url/rails/active_storage/blobs/proxy/eyJfcmFpbHMiOnsiZGF0YSI6MjkzMTg4LCJwdXIiOiJibG9iX2lkIn19--1b394b02657459e49956dfed65e250d9a294484c/Keepit-cybersecurity-factsheet.pdf, https://www.keepit.com/blog/end-to-end-iso-iec-27001-certified/

DORA (source) — Assessment Required

Keepit provides services to hundreds of financial institutions in the EU. The Digital Operational Resilience Act requires these financial entities to manage their third-party ICT risk, making Keepit indirectly subject to its requirements.

As a critical ICT third-party provider to the financial sector, a failure to meet DORA's standards could result in loss of business and potential inclusion in oversight frameworks. The risk is medium as the direct obligation falls on their clients.

Evidence: https://lp.keepit.com/hubfs/content-assets/EN/Keepit-DORA-factsheet.pdf, https://www.keepit.com/security/compliance/, https://www.keepit.com/resources/dora-factsheet/, https://www.keepit.com/blog/what-is-dora/, https://termly.io/resources/articles/brazils-general-data-protection-law/, https://www.keepit.com/blog/dora-compliance-backup/

EU AI Act (source) — Assessment Required

Keepit has announced its "AI Truth Cloud" and is developing AI-driven services for data governance and compliance. As a provider placing AI systems on the EU market, they will be subject to the EU AI Act.

As Keepit integrates AI into its services, non-compliance with the EU AI Act could lead to fines and restrictions on market access. The risk is currently medium as the AI services are new and their classification under the Act is not yet clear.

Evidence: https://www.datacentre.solutions/news/22795-keepit-expands-funding-to-enhance-ai-growth, https://www.keepit.com/press/ai-truth-cloud/, https://dealroom.co/news/136638-keepit-upsizes-credit-facilities-to-90m-as-it-bets-on-ai-data-services/, https://www.modelop.com/ai-governance/ai-regulations-standards/eu-ai-act, https://airia.com/blog/eu-ai-act-risk-categories-which-tier-is-your-ai-system/, https://www.onetrust.com/glossary/ai-act-high-risk-systems/

Financials

Three-year financials

Financial Resilience Score: 7/10

Keepit A/S demonstrates strong financial resilience for a private growth-stage SaaS company, underpinned by a well-diversified capital base of approximately USD 90M in cumulative equity funding and a USD 60M senior credit facility (upsized and refinanced in September 2025). Management has explicitly stated that cash reserves are projected to remain robust for years ahead, with only a portion of the previous credit facility drawn. The investor base spans specialist growth equity (One Peak), a state-backed Danish promotional bank (EIFO), and a global venture/innovation lender (HSBC Innovation Banking), reducing single-source funding risk. The business model benefits from recurring SaaS revenue with reportedly high customer retention, rapid customer base growth (from ~10,000 customers in late 2024 to over 18,000 by September 2025), and strong regulatory tailwinds from NIS2, DORA, GDPR, and HIPAA. The company holds defensible positioning as a vendor-independent, immutable cloud backup provider, recognized as a Leader by IDC MarketScape and QKS Spark Matrix. However, the score is constrained by the absence of public profitability disclosure—press releases emphasize growth and retention but not EBITDA or profitability, suggesting the company is likely still loss-making, typical of VC/growth-equity-backed SaaS scale-ups. Capital intensity is elevated due to owning data centers across 7 regions, and channel-only distribution (since January 2024) creates dependency on distributor relationships. Competition from well-funded players (Veeam, Rubrik, Druva, Cohesity-Veritas, AvePoint) is intensifying.

Key strengths: Cumulative equity funding of ~USD 90M from One Peak, EIFO, and others, USD 60M credit facility from HSBC Innovation Banking and EIFO (Sept 2025), Management states multi-year cash runway with only partial credit facility drawn, Diversified investor base (growth equity, state-backed bank, innovation lender), Recurring SaaS revenue model with high customer retention, Rapid customer growth: 10,000+ (late 2024) to 18,000+ (Sept 2025), Strong regulatory tailwinds (NIS2, DORA, GDPR, HIPAA), Leader recognition by IDC MarketScape, QKS Spark Matrix, Canalys, ISO/IEC 27001 certified, SOC 2 Type 1, TISAX audit completed

Risk factors: No public profitability disclosure; likely still loss-making, High capital intensity from owning data centers in 7 regions, Channel-only distribution dependency since January 2024, Heavy concentration in Microsoft 365 / Entra ID workloads, Well-funded and consolidating competition (Veeam, Rubrik, Druva, Cohesity-Veritas, AvePoint), FX exposure across USD/EUR/GBP invoicing with DKK reporting, Microsoft policy or pricing changes on backup APIs is a strategic risk

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report