Mailinblack

France · www.mailinblack.com · 11 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 11 sub-vendors.

Insights

Last updated 2026-08-03 · revision 2

11 direct vendors, 219 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Mailinblack exhibits a medium level of migration readiness. Strengths include the 'Protect' product being available as SaaS and integrating natively with Microsoft 365 via API, suggesting experience with cloud-based deployments and modern integration patterns. The use of proprietary AI/ML and Zero-Knowledge architecture for their products indicates a sophisticated technical foundation that could be adaptable. The presence of vendor HQs in 3 unique countries (United States, France, Denmark) suggests a potentially diverse vendor landscape, which could offer more flexibility in choosing migration partners or tools. Challenges and unknowns include the internal tech stack's use of WordPress, which, depending on its implementation, could represent a legacy component requiring significant effort to migrate to a fully cloud-native environment. The 'On-Premise' option for 'Protect' also suggests their architecture might not be entirely cloud-native, and there is no explicit mention of containerization or microservices. Critical information regarding the regulatory environment and data residency requirements is missing. The absence of financial data makes it difficult to assess their capacity to fund a potentially large-scale migration effort. The 'Vendor Lock-in Risk' is 'Unknown,' and while 'Total Vendors: 0' is contradictory, the use of HubSpot and Salesforce (CRMs) implies reliance on specific SaaS vendors, which can introduce lock-in challenges during migration. The 'Total Services: 16' also suggests a number of external dependencies that would need to be considered.

Compliance

8 in-scope frameworks identified; showing 3.

France Cybersecurity Label — Compliant

Mailinblack explicitly displays the 'France Cybersecurity' label on its company page. This label is awarded by the French government (ANSSI-backed) to French cybersecurity products and services that meet defined security and quality criteria. It is a voluntary but prestigious certification that demonstrates compliance with French national cybersecurity standards and ANSSI ecosystem requirements. Risk is Low as the label is publicly displayed and is a core part of the company's market positioning.

Evidence: https://www.mailinblack.com/societe/

HDS — Compliant

Mailinblack explicitly displays the HDS (Hébergeur de Données de Santé) certification badge on its company page and markets dedicated healthcare solutions (CHR, CH, GHT) with 'solutions hébergées en France, certifiées HDS.' HDS is a mandatory French certification under Article L.1111-8 of the French Public Health Code for any entity hosting health data on behalf of healthcare providers. Compliance is confirmed by the company's own public disclosures and its active marketing to French hospitals. Risk is Low as the certification appears current and is a core part of the company's healthcare market proposition.

Evidence: https://www.mailinblack.com/societe/, https://www.mailinblack.com/

SOC 2 (source) — Assessment Required

Mailinblack is a cloud-based SaaS cybersecurity provider processing sensitive data (email content, credentials, security training data) for 26,000+ organisations. SOC 2 is a US-origin framework (AICPA) but is increasingly demanded by enterprise and international clients as evidence of security controls. As a cybersecurity company, the absence of a publicly disclosed SOC 2 report represents a reputational and commercial risk, particularly for clients in regulated industries or with US parent companies. The risk is Medium because: (1) SOC 2 is not legally mandated in France/EU; (2) Mailinblack may have ISO 27001 as an alternative assurance framework; (3) the company's primary market is French/EU SMEs and public sector, where SOC 2 is less commonly required than in US enterprise markets. However, the lack of any public evidence of SOC 2 is notable for a cybersecurity vendor.

Evidence: https://www.mailinblack.com/societe/

Financials

Three-year financials

Financial Resilience Score: 7/10

Mailinblack demonstrates solid qualitative financial resilience despite the lack of publicly disclosed statutory financials in this session. The company operates a recurring SaaS revenue model with a stated 96% customer renewal rate, indicating low churn and predictable cash flow. It serves a broad, diversified base of 24,000-26,000 organizations, reducing single-customer concentration risk. Strategic backing from Seven2 (formerly Apax Partners France) and NewAlpha Verto following a €50M+ round in 2022 provides growth capital and governance discipline, building on an earlier €14M round in 2019. Structural tailwinds are strong: NIS2, DORA, GDPR enforcement, and public-sector cyber mandates in France and the EU are increasing budgets for Mailinblack's core products. The company has meaningful moats in French public procurement through HDS certification, 'Cybersecurity Made in Europe' and 'France Cybersecurity' labels, and sovereign hosting. Product diversification since 2021 (Cyber Coach, Cyber Academy, Sikker password manager) reduces reliance on the legacy email security flagship. On the risk side, the email security segment is highly competitive with global players (Proofpoint, Mimecast, Barracuda, Vade) and Microsoft 365 native security threatening the low end. Revenue is heavily concentrated in France with limited international diversification, and at an estimated sub-€50M run-rate, R&D scale is far smaller than global suites. The 2022 PE round may have introduced leverage that cannot be assessed without access to statutory filings.

Key strengths: Recurring SaaS revenue model with 96% renewal rate, Diversified customer base of 24,000-26,000 organizations, Strategic PE backing from Seven2 and NewAlpha Verto (€50M+ round in 2022), EU regulatory tailwinds (NIS2, DORA, GDPR), Strong French public-sector positioning with HDS certification and sovereignty labels, Product diversification beyond email security (Cyber Coach, Cyber Academy, Sikker)

Risk factors: Intense competition from global players (Proofpoint, Mimecast, Barracuda, Vade), Microsoft 365 native security as a 'good enough' threat at the low end, Heavy geographic concentration in France with limited international diversification, Sub-scale R&D budget vs. global cybersecurity suites, Potential post-buyout leverage risk from 2022 PE round (unverifiable without filings), Dependence on customer uptake of awareness/training modules for cross-sell growth

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report