Lean-On A/S
Denmark · owned by Independent (Denmark) · www.lean-on.com · 26 vendors
Lean-On A/S is a Danish private cloud provider specializing in high-performance Desktop-as-a-Service (DaaS), Software-as-a-Service (SaaS), and secure cloud computing solutions. The company delivers secure-by-design virtual desktops and cloud infrastructure tailored for industries requiring high performance and compliance, including CAD, AI, HPC, and mission-critical applications. Founded in Denmark in 2001, Lean-On operates globally with certified data centers in Denmark and the United States.
Resilience scores
- Digital Sovereignty: 35
- Digital Resilience: 8
- Financial Resilience: 5
Disruption prediction
Lean-On A/S has an estimated 17% probability of disruption in the next 6 months.
10 of Lean-On A/S's 26 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Netlify, Inc. — Technology — United States
- and 23 more
Insights
Last updated 2026-09-13 · revision 13
26 direct vendors, 270 subvendors
Direct vendors by controlling owner country (sample)
- France: 3
- Belgium: 2
- United States: 17
Subvendors by controlling owner country (sample)
- Bulgaria: 1
- Ukraine: 1
- Poland: 4
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Lean-On A/S exhibits a high degree of migration readiness, largely due to its core business model and advanced technological offerings. The company specializes in providing cloud-based DaaS, VDI, SaaS, HPC, and AI/LLM services, indicating deep expertise in modern cloud architectures and virtualization technologies (e.g., NVIDIA vGPU, Citrix HDX). Their 'Private Cloud with Public Integrations' service, including Microsoft Azure integration, demonstrates a hybrid cloud strategy and capability to connect diverse environments, which is crucial for complex migrations. The company's 'Application Management' service, covering deployment, versioning, and optimization, directly translates to strong internal capabilities for managing application portfolios during a migration. Furthermore, their 'License Advisory and Optimization' service for key vendors like Microsoft and Citrix is a significant asset, as license management is often a major hurdle in cloud migrations. Lean-On's existing compliance with and management of stringent data residency requirements (GDPR, EU/US data centers) demonstrates their ability to navigate complex regulatory environments during infrastructure shifts. While the specific internal architecture (e.g., extent of containerization or microservices adoption beyond 'software-defined cloud production') is not fully detailed, their product portfolio strongly suggests a modern, agile approach. The primary limitation in this assessment is the 'Unknown' status of vendor lock-in risk and the lack of financial data to assess funding capacity for large-scale migrations. However, based on their inherent cloud expertise, service offerings, and regulatory navigation capabilities, Lean-On is well-positioned for future migrations.
Compliance
7 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
NIS2 risk is assessed as High for the following reasons: (1) Lean-On A/S is a cloud computing service provider and managed service provider (MSP) operating in Denmark (EU) — cloud computing providers are explicitly listed as 'Important Entities' under NIS2 Annex II; (2) Lean-On explicitly markets NIS2 compliance support to its customers, demonstrating awareness of the directive; (3) A customer testimonial on the homepage directly references NIS2 compliance ('By complying with NIS 2, we can maintain a great and secure collaboration'); (4) As a DaaS/SaaS/VDI provider serving mission-critical industries (engineering, energy sector via Babcock & Wilcox, manufacturing), Lean-On likely meets the 'Important Entity' threshold; (5) Size threshold (50+ employees or €10M+ turnover) is unconfirmed from public sources but the company has been operating since 2001 with offices in Denmark (2 locations) and the USA, suggesting it may meet thresholds; (6) Non-compliance with NIS2 carries fines up to €7M or 1.35% of global turnover for Important Entities, plus potential management liability. Denmark transposed NIS2 via the 'Lov om net- og informationssikkerhed' (NIS2-loven), effective October 2024.
Evidence: https://lean-on.com/make-compliance-easy/, https://lean-on.com/tap-into-the-cyber-resilience-era/, https://lean-on.com/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/da/cybertruslen/nis2/
Danish Data Protection Act — Partially Compliant
As a Danish-incorporated company, Lean-On A/S is subject to the Danish Data Protection Act (Act No. 502 of 23 May 2018), which supplements GDPR with national specifications. Risk is Medium because: (1) The company has a named DPO and published privacy policy, indicating awareness; (2) However, the DPA imposes additional requirements beyond GDPR (e.g., specific rules on employee data, criminal record processing, CPR number handling) that cannot be verified externally; (3) Datatilsynet actively enforces both GDPR and the national DPA.
Evidence: https://lean-on.com/privacy-policy/, https://www.datatilsynet.dk/, https://www.retsinformation.dk/eli/lta/2018/502
SOC 2 (source) — Assessment Required
SOC 2 risk is High because: (1) Lean-On is a cloud service provider (SaaS, DaaS, VDI, HPC) — SOC 2 is the de facto standard for cloud providers, especially those serving US and enterprise customers; (2) Lean-On explicitly references 'SOC 1 and SOC 2' alignment on its compliance page, indicating awareness but not confirmed certification; (3) The company has a US subsidiary and serves US customers (e.g., Babcock & Wilcox), where SOC 2 reports are commonly required in vendor due diligence; (4) Without a SOC 2 Type II report, enterprise customers — particularly in regulated industries — may be unable to use Lean-On's services, creating significant commercial and reputational risk; (5) The absence of a publicly disclosed SOC 2 report is a notable gap for a cloud provider of this profile.
Evidence: https://lean-on.com/make-compliance-easy/, https://lean-on.com/about-lean-on/, https://lean-on.com/armored-appspace/
Financials
Three-year financials
- 2025: gross profit DKK 22.1M, EBIT DKK 3.22M, equity DKK 8.48M
- 2024: gross profit DKK 20.6M, EBIT DKK 2.76M, equity DKK 8.04M
- 2023: gross profit DKK 17.5M, EBIT DKK 2.32M, equity DKK 7.29M
Financial Resilience Score: 5/10
Lean-On A/S is a small-to-medium Danish A/S operating in the cloud/SaaS/DaaS niche with a focus on high-performance virtual desktops, CAD-as-a-Service, HPC/AI workloads, and secure compliant workspaces. The company demonstrates qualitative strengths through its recurring-revenue SaaS model, which typically provides predictable cash flow and high gross margins, and through its differentiated niche positioning combining Autodesk ADN partnership with secure EU sovereign cloud delivery. Regulatory tailwinds from NIS2 and GDPR compliance requirements, combined with blue-chip references like Babcock & Wilcox, further support its commercial credibility. However, the company faces meaningful structural risks. As a small player, it competes against hyperscaler DaaS offerings (Microsoft Azure Virtual Desktop, AWS WorkSpaces, Citrix), creating persistent pricing pressure. The capital intensity of cloud/HPC infrastructure (GPUs, data-center capacity, energy costs) can strain cash flow during uneven growth periods. Customer concentration risk is typical for niche Danish A/S firms, and limited scale reduces the company's ability to absorb FX, energy-price, or churn shocks. Because official financial filings (revenue, EBIT, equity, employees) from datacvr.virk.dk and proff.dk could not be retrieved in this session, a precise quantitative resilience score cannot be anchored to figures. The midpoint score reflects the balance between a defensible niche with regulatory tailwinds and the structural risks of small scale, capital intensity, and hyperscaler competition.
Key strengths: Recurring-revenue SaaS/DaaS subscription model providing predictable cash flow, Niche differentiation in high-performance VDI for CAD, HPC, and AI, Regulatory tailwind from NIS2 and GDPR compliance positioning, Geographic diversification across Denmark and the United States, Blue-chip reference customers including Babcock & Wilcox
Risk factors: Capital intensity of cloud/HPC infrastructure (GPU servers, data-center capacity), Direct competition from hyperscalers (Azure Virtual Desktop, AWS WorkSpaces, Citrix), Customer concentration risk typical for small Danish niche A/S, Limited scale to absorb FX, energy-cost, or churn shocks, Reduced disclosure under Danish regnskabsklasse B limits external visibility
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.