Locize

Switzerland · locize.com · 15 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 15 sub-vendors.

Insights

Last updated 2026-07-16 · revision 2

15 direct vendors, 180 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Locize exhibits very high migration readiness due to its highly modern, cloud-native, and modular technical architecture. The core infrastructure is built on Amazon Web Services (AWS) with a strong emphasis on REST APIs and CDN-based delivery, suggesting a decoupled, service-oriented approach that is inherently portable. The company maintains its own open-source i18next framework, providing deep control and flexibility over its core technology. The 'Bring Your Own Key' (BYOK) model for AI translation (OpenAI, Google Gemini, Mistral AI, DeepL) significantly reduces lock-in to any single AI vendor. Furthermore, support for numerous standard translation file formats (XLIFF, Gettext, Android XML, RESX, Fluent) enhances interoperability. While 'Data Residency Requirements' are not explicitly specified, the use of AWS Ireland and BunnyCDN Storage in the EU indicates a strong focus on EU data residency, which could be a factor in any migration strategy outside the EU. The 'Vendor Lock-in Risk' is stated as unknown, but the diverse set of vendors for different services (cloud, CDN, payments, AI) and the modular architecture suggest a lower overall risk. Financial stability data is missing, which could impact the ability to fund a large-scale migration, but the technical foundation is exceptionally strong for such an undertaking.

Compliance

7 in-scope frameworks identified; showing 3.

CCPA — Partially Compliant

Locize has published dedicated CCPA terms on its website, indicating active awareness and compliance efforts. The company serves global customers including those in California. Risk is Low because: (1) Locize has published CCPA-specific terms; (2) The company is unlikely to meet CCPA's applicability thresholds (annual gross revenue >$25M, OR buying/selling/receiving/sharing personal information of 100,000+ California consumers/households, OR deriving 50%+ of annual revenue from selling personal information) given its small size; (3) Even if thresholds are not met, publishing CCPA terms demonstrates good-faith compliance posture; (4) The data processed (translation platform account data) is relatively low-sensitivity.

Evidence: https://locize.com/ccpa, https://locize.com/privacy

ISO 27001 (source) — Assessment Required

Locize's Security page explicitly states it has an 'Information Security Management System built on three pillars: people, processes, and technology' and an 'Information Security Policy applies across the inweso organization.' This language is directly aligned with ISO 27001 ISMS terminology. However, no ISO 27001 certification has been publicly disclosed. Risk is Medium because: (1) The company has implemented ISMS-like controls but lacks a certified audit; (2) Enterprise customers (e.g., ABB, ZKB) may require ISO 27001 certification as a vendor prerequisite; (3) The absence of certification is a commercial and reputational risk for enterprise market segments; (4) Obtaining ISO 27001 certification for a small company is resource-intensive. Risk is not High because the company's data (translation strings) is relatively low-sensitivity, and compensating controls are documented.

Evidence: https://locize.com/security, https://locize.com/privacy, https://aws.amazon.com/compliance/iso-27001-faqs/

SOC 2 (source) — Assessment Required

Locize is a cloud-based SaaS platform (Translation Management System) that stores customer data (translation resources, project metadata, account information) on behalf of its customers — precisely the type of service for which SOC 2 Type II reports are commonly expected by enterprise customers. The risk is Medium because: (1) No SOC 2 report or certification has been publicly disclosed by Locize; (2) Enterprise customers (e.g., ABB, ZKB/Zürcher Kantonalbank as referenced on the website) may require SOC 2 as part of vendor due diligence; (3) The absence of SOC 2 could be a commercial barrier for enterprise sales and a reputational risk; (4) However, Locize is a small company and SOC 2 audits are resource-intensive — many SME SaaS providers operate without them. The risk is not High because Locize's data processing is relatively low-sensitivity (translation strings, not financial or health data), and the company has implemented compensating controls (encryption, MFA, RBAC, DRP, BCP).

Evidence: https://locize.com/security, https://locize.com/dpa, https://aws.amazon.com/compliance/soc-faqs/

Financials

Three-year financials

Financial Resilience Score: 6/10

Locize (inweso GmbH) is an independently owned, founder-led Swiss SaaS company that has operated continuously since 2016, with the underlying i18next open-source library dating back to 2011. Its resilience is anchored by a bootstrapped, lean cost structure (single-director GmbH, cloud-native infrastructure via AWS, BunnyCDN and Stripe, no traditional sales team), high-margin recurring SaaS revenue with flat-tier pricing, and a strong inbound distribution moat via the i18next open-source library which enjoys tens of millions of weekly npm downloads. The company's Swiss jurisdiction, dual FADP/GDPR compliance, and EU data residency provide a differentiated regulatory positioning that has won lighthouse references such as ZKB, Swiss Red Cross, and ABB. On the risk side, financial opacity is significant: as a small Swiss GmbH, inweso is not required to publish accounts and does not do so, meaning revenue, EBIT and equity are entirely undisclosed. The company also faces material key-person risk (single named director Adriano Raiano), sub-scale relative to well-funded competitors like Phrase (Carlyle-owned), Lokalise, and Crowdin, exposure to AI-driven commoditisation of machine translation, cloud-provider concentration on AWS and Stripe, and FX headwinds from a CHF cost base against EUR/USD revenues. Operationally, however, the 2024–2026 change log shows active reinvestment (Locize AI, MCP integration, new CDN, DR snapshots), suggesting an ongoing growth posture rather than maintenance mode.

Key strengths: Independently owned, bootstrapped, no VC/PE pressure, Lean cloud-native cost structure with self-serve product-led model, Distribution moat via i18next open-source library (tens of millions of weekly npm downloads), 10+ years of continuous operation since 2016, Swiss jurisdiction + FADP/GDPR compliance as monetisable regulatory positioning, Sticky infrastructure-type product with high switching costs, Active product reinvestment through 2024–2026 (AI, MCP, CDN, DR)

Risk factors: Key-person risk: single-director GmbH (Adriano Raiano), Sub-scale versus VC/PE-backed competitors (Phrase, Lokalise, Crowdin), Financial opacity — no public accounts filed, barrier for enterprise procurement, AI/LLM commoditisation of underlying machine translation layer, Cloud-provider concentration on AWS and Stripe, FX exposure: CHF cost base vs EUR/USD revenues, Very small headcount (estimated under ~15 people) limits enterprise sales reach

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report