Kyriba

United States · www.kyriba.com · 34 vendors

Kyriba Corp. is a global leader in cloud-based treasury and finance solutions. It provides a Liquidity Performance Platform that empowers CFOs and finance teams to connect, protect, forecast, and optimize their liquidity, cash, payments, and risk management globally. The platform is a secure and scalable SaaS solution that integrates with banks and ERPs.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 34 sub-vendors.

Insights

Last updated 2026-08-16 · revision 1

34 direct vendors, 313 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Kyriba's migration readiness is moderate, primarily driven by its highly modern and cloud-native technical architecture. The use of Amazon Web Services (AWS), a multi-tenant SaaS platform, Next.js, Databricks, and open REST APIs provides a strong foundation for portability and flexibility. Adherence to standards like ISO 20022 further simplifies potential integrations during a migration. However, significant unknowns introduce considerable risk and complexity, pulling the overall readiness score down. The 'Vendor Lock-in Risk' is explicitly stated as 'Unknown', which is a critical factor for migration. While 'Vendor Geographic Diversity' across 7 countries is positive, the actual number of distinct vendors is unclear ('Total Vendors: 0' is contradictory to other vendor data, and 'Total Services: 34' implies a potentially complex vendor landscape). More importantly, 'Data Residency Requirements' and the specific 'Regulatory Environment' are 'Not specified'. For a global financial technology company, these are paramount and can dictate the feasibility, cost, and timeline of any migration. The absence of financial stability data (revenue concentration, growth history) also means the ability to fund a significant migration effort cannot be fully assessed. Therefore, while the technical foundation is excellent, the substantial missing information regarding vendor relationships, data residency, and regulatory compliance significantly lowers the overall migration readiness.

Compliance

11 in-scope frameworks identified; showing 3.

CPRA — Compliant

Kyriba explicitly addresses California privacy rights on its legal compliance page, including a dedicated 'Notice of Right to Opt-Out of Sale of Personal Information for California Residents,' which is a specific CCPA/CPRA requirement. Kyriba is headquartered in San Diego, California, and serves California residents, making CCPA/CPRA directly applicable. The existence of a California-specific opt-out notice and a comprehensive privacy policy demonstrates active CCPA compliance. Risk is Low given documented compliance measures.

Evidence: https://www.kyriba.com/legal-pages/privacy-legal-compliance/, https://www.kyriba.com/legal-pages/notice-of-right-to-opt-out-of-sale-of-personal-information-ca-residents/, https://www.kyriba.com/legal-pages/privacy-policy/

GDPR (source) — Compliant

Kyriba explicitly self-declares GDPR compliance on its Trust Center page ('Compliant with GDPR, Data Protection and Data Subject Rights for EU Residents'). The company has implemented a comprehensive privacy framework including a Data Privacy Framework (DPF) certification from the U.S. Department of Commerce (covering EU-US and Swiss-US data transfers), a dedicated Data Privacy Framework Notice, a Business Contacts Privacy Notice, a Kyriba Technology Platform Customer Privacy Notice, and a Candidate Privacy Policy — all of which are GDPR-aligned instruments. Kyriba operates in France (Paris HQ origin), Germany, the UK, and other EU/EEA markets, and processes personal data of EU residents as a SaaS provider to 4,000+ global organizations. The DPF certification further reduces cross-border transfer risk. Risk is Low given the strong documented compliance posture and multiple overlapping privacy controls.

Evidence: https://www.kyriba.com/company/trust-center/, https://www.kyriba.com/legal-pages/privacy-legal-compliance/, https://www.kyriba.com/legal-pages/data-privacy-framework-notice/, https://www.kyriba.com/legal-pages/kyriba-technology-platform-customer-privacy-notice/, https://www.kyriba.com/legal-pages/business-contacts-privacy-notice/, https://www.kyriba.com/legal-pages/privacy-policy/, https://www.dataprivacyframework.gov/list

TISAX — Compliant

Kyriba explicitly holds TISAX certification as disclosed on its Trust Center. TISAX is the automotive industry's information security assessment standard, managed by ENX Association, and is required by major automotive OEMs (e.g., BMW, Volkswagen, Mercedes-Benz) for their suppliers and service providers. Kyriba's TISAX certification indicates it serves automotive sector clients and has passed a rigorous third-party assessment of its information security controls. Risk is Low given confirmed certification.

Evidence: https://www.kyriba.com/company/trust-center/

Financials

Three-year financials

Financial Resilience Score: 7/10

Kyriba is a mature, PE-owned SaaS company with strong qualitative fundamentals including recurring subscription revenue, a blue-chip customer base of approximately 4,000 customers (many Fortune 500), high switching costs typical of treasury management systems, and deep-pocketed private equity backers (Bridgepoint, General Atlantic, Sumeru Equity Partners). The company was valued at approximately US$1.2 billion in the 2019 Bridgepoint buyout and had ARR of ~$130-150M growing 25-30% at that time. It has since continued strong double-digit ARR growth and repeatedly appeared on the Inc. 5000 list. However, financial transparency is a significant limitation—Kyriba is privately held and does not file with the SEC or publish audited annual reports. The 2019 PE buyout likely resulted in a leveraged capital structure, exposing the company to interest-rate sensitivity. Competition is intense from ION Group, FIS, GTreasury, Coupa Treasury, and SAP. Heavy investment in AI (TAI agentic AI) may pressure near-term margins, and Bridgepoint's extended hold period creates a PE exit overhang. Overall, qualitative resilience is strong but unverifiable without direct financial disclosure.

Key strengths: SaaS recurring-revenue model with high gross retention (>95% typical for enterprise TMS), Blue-chip diversified customer base (Spotify, Trane, Barilla, Avery Dennison, Baxter, HelloFresh), Deep-pocketed PE ownership (Bridgepoint, General Atlantic, Sumeru), Recognized market leader (IDC MarketScape, Euromoney World's Best TMS 2025), High switching costs due to deep ERP and banking integration, Scale in bank connectivity (~10,000 banks), ~4,000 customers processing $51 trillion in payments annually

Risk factors: No public financial transparency - no audited statements available, Likely leveraged capital structure from 2019 PE buyout at $1.2B valuation, Intense competition from ION Group, FIS, GTreasury, Coupa, SAP, Concentration in mid-to-large enterprise segment sensitive to IT spending cycles, Heavy AI/R&D investment may weigh on near-term margins, PE exit overhang - Bridgepoint has held since 2019, IPO/sale likely

Revenue by geography

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report