Khoros

United States · khoros.com · 27 vendors

Khoros is a global customer engagement software company that provides a unified platform for online community management, social media marketing, social media analytics, and digital customer care. It helps enterprise brands manage customer interactions across various digital channels. The company's solutions are designed to build stronger customer relationships and improve brand loyalty.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 2 categories; runs on 27 sub-vendors.

Insights

Last updated 2026-08-11 · revision 7

27 direct vendors, 318 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Khoros exhibits high migration readiness, primarily driven by its modern and flexible technology architecture. The internal tech stack is largely cloud-native, leveraging Amazon Web Services (AWS), serverless architecture, React, and GraphQL, which are highly adaptable and facilitate seamless transitions. The company's new 'Aurora AI' and 'Iris® AI' platforms are AI-native, built on modern principles, and designed to replace legacy systems. A significant strength is the explicit and free migration path offered for 'Khoros Community Classic' customers to 'Aurora AI' until the end of 2026, demonstrating a proactive strategy and internal capability to manage large-scale migrations. Regulatory compliance is well-established (GDPR, SOC2, ISO 27001), meaning the necessary governance and security frameworks are in place to support data and system migrations without significant compliance hurdles. Data residency requirements are well-managed through AWS regional hosting options in the US, Ireland, and Australia, and the use of Standard Contractual Clauses for international transfers, providing flexibility for customers with specific data location needs. Financially, Khoros appears stable with estimated revenues of $200-250M, and the acquisition by IgniteTech in 2025 could provide additional resources for strategic migrations. The use of model-agnostic LLM integrations and open technologies like React further reduces technical lock-in. The primary unknown is the 'Vendor Lock-in Risk', as the specific details of contracts for the '44 services' are not provided. However, the geographic diversity of vendor HQs (8 countries) and the modern, open internal tech stack suggest a relatively low overall lock-in risk, making Khoros well-prepared for future migrations.

Compliance

9 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

Khoros is a US-headquartered SaaS company that explicitly processes personal data of EU/EEA, UK, and Swiss residents — both as a data controller (website visitors, employees, event attendees) and as a data processor on behalf of enterprise customers. The company has implemented several GDPR-aligned mechanisms: EU-U.S. Data Privacy Framework (DPF) certification, Standard Contractual Clauses (SCCs) for EEA/UK/Swiss data transfers, a named Data Protection Officer (Jacqueline Coyne), a Global Data Privacy Addendum, and explicit legal bases for processing. AWS infrastructure in Ireland provides EU data hosting. However, the status is 'Partially Compliant' rather than 'Compliant' because: (1) full independent GDPR audit evidence is not publicly available; (2) the company's social listening product (Iris AI) processes data across 187 languages and billions of social sources, creating complex data subject identification and consent challenges; (3) the privacy policy references Vista Equity Partners data sharing which may require careful GDPR scrutiny. Risk is Medium rather than High because the company has clearly invested in GDPR infrastructure and has a DPO, SCCs, and DPF certification in place.

Evidence: https://khoros.ai/privacy/, https://khoros.ai/trust-center/, https://khoros.ai/wp-content/uploads/2026/03/Khoros-Global-Data-Privacy-Addendum-v20260226.pdf, https://www.dataprivacyframework.gov, https://khoros.ai/legal/customer-agreements/

ISO 27701 — Compliant

Khoros displays an ISO 27701 certification badge on its Trust Center. ISO 27701 is an extension of ISO 27001 specifically addressing privacy information management and is directly aligned with GDPR requirements. It establishes requirements for a Privacy Information Management System (PIMS) for both data controllers and data processors. This certification is particularly significant given Khoros's dual role as both a data controller and data processor for EU personal data. Risk is Low given confirmed certification.

Evidence: https://khoros.ai/trust-center/

CPRA — Compliant

Khoros is headquartered in Austin, Texas, but as a SaaS company serving California residents and businesses, CCPA/CPRA applies. The company explicitly addresses CCPA in its privacy policy with a dedicated 'Additional California Privacy Rights' section, discloses categories of personal data collected and shared per CCPA requirements, confirms it has not sold consumer personal information in the preceding 12 months, and provides opt-out mechanisms. The company also references CCPA categories (A, B, D, F, I, K) in its disclosure. Risk is Low given explicit CCPA compliance measures documented in the privacy policy.

Evidence: https://khoros.ai/privacy/, https://khoros.ai/trust-center/

Financials

Three-year financials

Financial Resilience Score: 5/10

Khoros presents a mixed financial resilience profile. On the positive side, the company has a blue-chip customer base of approximately 2,000 brands, including roughly one-third of the Fortune 100, which provides high-quality recurring SaaS revenue with high switching costs typical of community platforms. The company is backed by well-capitalized owners in ESW Capital / IgniteTech, which has a track record of turning around mature enterprise software assets. New product launches (Aurora AI and Iris AI in 2026) represent a substantive replatforming that could revive growth. However, significant concerns exist. The company has undergone multiple rounds of layoffs (10-20% each) in 2022 and 2023, suggesting stalled or declining growth. Vista Equity Partners' exit to a roll-up acquirer like IgniteTech at an undisclosed price often signals value-preservation rather than growth. IgniteTech CEO Eric Vaughan's public statements about replacing 80% of staff across portfolio companies imply significant execution risk. Competitive pressure from Sprinklr, Salesforce, Sprout Social, and Hootsuite is intense, and headwinds from Google AI Overviews reducing community traffic by 40-49% create structural challenges. The complete opacity of financials (no audited disclosures, no SEC filings, private LLC structure) makes it impossible to verify liquidity, leverage, or profitability, which itself is a resilience concern for stakeholders.

Key strengths: Blue-chip customer base (~2,000 brands, ~1/3 of Fortune 100), Sticky SaaS/community platform with high switching costs, Well-capitalized owner (ESW Capital/IgniteTech/Trilogy), New AI product cycle (Aurora AI, Iris AI) launched 2026, Recurring SaaS revenue model

Risk factors: Opaque financials with no public audited disclosures, Ownership history suggests underperformance (Vista exit at undisclosed price), Aggressive workforce restructuring (~80% headcount reduction claims at group level), Multiple rounds of layoffs in 2022-2023 (10-20% each round), Intense competition from Sprinklr, Salesforce, Sprout Social, Hootsuite, Product transition risk from Classic platform to Aurora AI, AI answer-engine cannibalization (40-49% community traffic decline reported), Undisclosed acquisition price suggests distressed sale

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report