Koala

United States · getkoala.com · 10 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 10 sub-vendors.

Insights

Last updated 2026-08-11 · revision 1

10 direct vendors, 187 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Koala demonstrates high migration readiness. Its internal tech stack is highly modern and cloud-friendly, featuring Next.js, React, and leveraging services like Cloudflare, Okta, Google SSO, and Segment, which are typically cloud-native or offer robust cloud integrations. The architecture, particularly the 'AI Agent Swarm' and 'Automations & Sales Plays' with 'custom webhooks,' suggests a modular and API-driven approach, which significantly eases migration efforts to new environments or platforms. Proactive SOC 2 compliance via Vanta indicates mature security and operational practices that would streamline compliance during a migration. The lack of specified data residency requirements offers flexibility in choosing migration targets. The primary challenge to fully assessing migration readiness is the absence of financial data (revenue concentration, growth history), which makes it impossible to determine the company's financial capacity to fund a significant migration effort. Additionally, while vendor diversity is present, the specific 'Vendor Lock-in Risk' is unknown, which could present unforeseen complexities or costs during a migration if key services are tightly coupled with current vendors.

Compliance

4 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

Koala explicitly self-declares GDPR compliance and has appointed a Data Protection Officer (DPO) representative via DP-Dock GmbH in Hamburg, Germany, and a UK representative via DP Data Protection Services UK Ltd. The company processes personal data of EU/EEA and UK residents as part of its core B2B SaaS product (intent signals, web analytics, professional/employment data, IP addresses). While compliance declarations and DPO appointment are positive indicators, the company is a US-based data controller hosting data on US servers, which creates inherent cross-border transfer risk. The company's privacy policy acknowledges GDPR lawful bases (contractual necessity, legitimate interest, consent) and provides EU data subject rights. Risk is Medium rather than Low because: (1) the company processes significant volumes of EU personal data including behavioral tracking and enrichment data; (2) data is hosted in the US without explicit mention of SCCs or adequacy decisions; (3) the company is shutting down (acquired by Cursor, shutdown Sept 30), which creates data deletion/transfer obligations under GDPR.

Evidence: https://getkoala.com/security, https://getkoala.com/legal/privacy, https://www.dp-dock.com

ISO 27001 (source) — Assessment Required

No ISO 27001 certification is mentioned on Koala's website, security page, or trust center references. The company has achieved SOC 2 Type II (which covers overlapping information security controls) and uses Vanta for continuous compliance monitoring. ISO 27001 is not mandatory for US-based SaaS companies, and many companies at Koala's stage opt for SOC 2 instead. Risk is Low because: (1) SOC 2 Type II provides substantial overlapping assurance; (2) ISO 27001 is not legally required in Koala's operating jurisdictions; (3) the company is shutting down, making new certifications unlikely.

Evidence: https://getkoala.com/security

CCPA — Compliant

Koala explicitly declares CCPA compliance on its security page and has a comprehensive CCPA section in its privacy policy and terms of service. The company is headquartered in South San Francisco, CA, making CCPA directly applicable. The privacy policy includes all required CCPA disclosures: categories of personal data collected, sources, business purposes, third-party sharing, consumer rights (access, deletion, opt-out of sale), and a non-discrimination statement. The company explicitly states it does not sell personal data. Risk is Low given explicit compliance declarations, comprehensive policy coverage, and the company's California domicile creating strong incentive for compliance.

Evidence: https://getkoala.com/legal/privacy, https://getkoala.com/legal/terms, https://getkoala.com/security

Financials

Three-year financials

Financial Resilience Score: 6/10

Koala (Konfetti, Inc.) is a small, privately held US SaaS startup with no publicly disclosed financial statements. Standard financial metrics such as revenue, EBIT, equity, and ARR are unavailable. Qualitatively, the company demonstrated strong indicators of resilience prior to acquisition: an experienced founding team from Twilio Segment (which had a ~$3.2B exit in 2020), a blue-chip PLG SaaS customer base (Retool, Vercel, Sanity, Deepgram, Dolby, etc.), SOC 2 Type II certification, and high customer satisfaction reflected in a 5.0 G2 rating. However, Koala operated in a highly competitive intent data / signal-based selling market against well-funded competitors including 6sense, Demandbase, Clearbit/HubSpot, Common Room, Warmly, and UserGems. Its small headcount and single-product exposure limited standalone resilience. The company achieved a successful strategic exit through acquisition by Anysphere (Cursor) in 2025, though the Koala product is being sunset on September 30, 2025, ending its standalone revenue-generating existence. Deal terms were not disclosed.

Key strengths: Experienced ex-Segment founding team with prior successful exit track record, Blue-chip PLG SaaS customer base including Retool, Vercel, Sanity, Deepgram, Dolby, SOC 2 Type II certification reducing enterprise sales friction, High G2 rating (5.0) indicating strong product-market fit, Successful strategic exit via acquisition by Anysphere/Cursor in 2025, Product embedded in revenue-critical customer workflows creating sticky retention

Risk factors: Core Koala product being shut down on September 30, 2025, Small headcount and single-product exposure limited standalone resilience, Highly competitive market with well-funded competitors (6sense, Demandbase, Clearbit, Common Room), Rapid pace of AI change in GTM cited by founders as reason to join Cursor, No public disclosure of funding amounts, ARR, or financial performance, Customer migration required to alternative platforms

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report