Kindly
Norway · www.kindly.ai · 14 vendors
Kindly provides an AI-powered platform for building and managing chatbots and conversational AI agents. The company specializes in artificial intelligence and automation solutions for customer service and communication, aiming to enhance customer experience and drive sales for businesses, particularly in e-commerce.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 7
- Financial Resilience: 5
Technology vendors
- Detectify AB — Cybersecurity — Sweden
- Google LLC — Technology — United States
- HubSpot, Inc. — Technology — United States
- and 11 more
Services catalogue
2 services in catalogue across 2 categories; runs on 14 sub-vendors.
- Chatbot
- Kindly
Insights
Last updated 2026-07-02 · revision 1
14 direct vendors, 234 subvendors
Direct vendors by controlling owner country (sample)
- United States: 11
- Sweden: 2
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Brazil: 1
- Germany: 6
- Unknown: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Kindly exhibits high migration readiness primarily due to its highly modern, cloud-oriented, and API-driven tech stack. The use of EU-based Cloud Data Centers, autoscaling infrastructure, and a comprehensive suite of developer APIs (Application API, Handover API, Chat Transcript API, Statistics API, Moderation API, Webhooks) indicates a modular and flexible architecture that is well-suited for migration to other cloud environments or platforms. The company's focus on AI/ML, Generative AI, and Conversational AI platforms also suggests a forward-looking infrastructure. Kindly's strong existing regulatory compliance framework, including GDPR, EU AI Act, and ISO/IEC 27001:2022 certification, along with its experience in managing EU-based data residency requirements (e.g., EU-based configuration for Kindly GPT), means it is well-prepared to handle complex compliance considerations during a migration. This maturity in regulatory adherence can streamline the process of migrating to target environments that also meet these stringent requirements. However, several factors introduce uncertainty. The lack of financial data (revenue concentration, growth history) makes it impossible to assess Kindly's financial capacity to fund a significant migration effort. The vendor lock-in risk is unknown, and while Kindly uses 13 services from vendors in 2 unique countries (United States, Sweden), the actual number of unique vendors is not provided. If these 13 services are concentrated among a few critical vendors, it could present challenges in disentangling dependencies during a migration. Additionally, the explicit data residency requirement for EU-based data, while well-managed, will limit migration options to specific cloud regions within the EU.
Compliance
10 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
Kindly is a cloud-based SaaS platform (AI support agents delivered via cloud infrastructure) serving enterprise clients, which is precisely the profile for which SOC2 Type II reports are commonly requested by customers during vendor due diligence. While Kindly has not publicly disclosed a SOC2 report, they have implemented many equivalent controls (ISO 27001, penetration testing, vulnerability assessments, access controls, audit logs, incident response). The risk is Medium because: (1) Enterprise customers — particularly those in regulated industries like banking and finance — may require SOC2 reports as part of vendor risk management; (2) Absence of a SOC2 report could be a commercial barrier; (3) However, Kindly's ISO 27001 certification partially substitutes for SOC2 in European markets where ISO 27001 is the more commonly accepted standard.
Evidence: https://trust.kindly.ai/, https://www.kindly.ai/company/security, https://trust.kindly.ai/?itemUid=722b9671-c0d5-4a19-a5f7-0ad8fd81307c&source=click, https://trust.kindly.ai/?itemUid=223a40ab-9393-4afe-97e4-e760c9cdede0&source=click
PIPEDA — Assessment Required
Kindly lists PIPEDA (Personal Information Protection and Electronic Documents Act — Canada's federal privacy law) as a compliance item in their Trust Center. This suggests Kindly has Canadian clients or processes personal data of Canadian residents. Risk is Low because: (1) Kindly has proactively addressed PIPEDA; (2) Their GDPR-compliant framework provides strong overlap with PIPEDA's 10 fair information principles; (3) Canada is not a primary market based on available evidence; (4) PIPEDA is being superseded by Bill C-27 (Consumer Privacy Protection Act), which Kindly will need to monitor.
Evidence: https://trust.kindly.ai/, https://trust.kindly.ai/?itemUid=712426e6-2709-4c3d-8b3c-e5e8f50fd666&source=click
NIS2 (source) — Assessment Required
Kindly operates as an AI-powered chatbot/virtual agent SaaS platform serving enterprise clients across Europe, including clients in sectors explicitly covered by NIS2 (banking/finance, transport, utilities/energy). As a digital service provider and ICT service management company, Kindly may qualify as an 'Important Entity' under NIS2's 'digital providers' category (specifically managed service providers or online marketplace/search engine/cloud computing service providers). Norway, while not an EU member, is an EEA member and is expected to implement NIS2-equivalent legislation. The risk is Medium because: (1) Kindly's exact classification under NIS2 digital provider categories is not definitively confirmed; (2) Norway's NIS2 transposition timeline is still being assessed; (3) Kindly's employee count and revenue figures are not publicly disclosed, making size threshold verification uncertain. However, given that Kindly serves critical-sector clients and operates as a cloud-based SaaS platform, NIS2 applicability is plausible and warrants formal legal assessment.
Evidence: https://www.kindly.ai/company/security, https://trust.kindly.ai/, https://trust.kindly.ai/?itemUid=5c93ca3e-519a-4260-a50a-a9de78294538&source=click, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 5/10
Kindly AS is a venture-backed Norwegian SaaS scale-up founded in 2016 with a long operating history relative to peers in the GenAI space. The company benefits from a blue-chip European customer base including Norwegian Air Shuttle, Vy, Posten/Bring, Elkjøp, Kahoot!, Scandic, Tele2, and Voi, which provides sticky enterprise SaaS revenue. It has raised significant capital, most notably a ~NOK 65M Series A in 2020 led by SNÖ Ventures with DNB Ventures and Idékapital, and has strong Nordic language expertise as a defensible market anchor. However, Kindly has historically reported operating losses in the tens of NOK millions, consistent with VC-backed SaaS growth-stage companies. Revenue has been in the low double-digit NOK millions range (2020-2022), meaning the company remains dependent on continued financing or a clear path to profitability. Competitive pressure from well-funded global players (Intercom Fin, Zendesk AI, Salesforce Einstein, Ada, Sierra, Cognigy) and commoditization risk from GenAI/LLMs pressuring traditional chatbot moats present material risks. The 2022 acquisition by/merger with Polish AI firm Zowie adds ownership complexity that should be verified.
Key strengths: Blue-chip European enterprise customer base with sticky SaaS contracts, Long operating history since 2016 with established integrations, Strong investor backing (SNÖ Ventures, DNB Ventures, Idékapital), ~NOK 65M Series A raised in 2020, Nordic language expertise as defensible market anchor, Multilingual capability (100+ languages)
Risk factors: Persistent operating losses typical of VC-backed SaaS scale-ups, Dependence on continued financing for runway, Intense competition from well-funded global AI players, Product commoditization risk from GenAI/LLMs eroding traditional chatbot moats, Concentration in Nordic mid-market limiting TAM, Ownership/consolidation complexity after Zowie transaction
Workforce by country
- Norway: 65
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.