Maltego Technologies GmbH
Germany · www.maltego.com · 20 vendors
Resilience scores
- Digital Sovereignty: 25
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Demandware — Technology — United States
- Netlify, Inc. — Technology — United States
- and 17 more
Services catalogue
1 service in catalogue across 1 category; runs on 20 sub-vendors.
- Maltego
Insights
Last updated 2026-07-17 · revision 1
20 direct vendors, 257 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 1
- Australia: 1
- France: 1
Subvendors by controlling owner country (sample)
- Portugal: 1
- Netherlands: 3
- France: 8
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Maltego Technologies GmbH exhibits exceptionally high migration readiness, largely due to its cutting-edge and cloud-native internal tech stack. The extensive adoption of Microsoft Azure, Kubernetes, and Docker signifies a containerized and orchestrated environment, which is inherently portable across cloud platforms or within hybrid cloud models. The use of Infrastructure as Code (IaC) tools like Terraform and configuration management with Ansible ensures that their infrastructure can be provisioned and replicated consistently and efficiently, drastically simplifying any migration effort. Furthermore, robust CI/CD practices via Azure Pipelines and Azure DevOps facilitate continuous deployment and rapid iteration, which are key enablers for agile migration strategies. The mention of 'SaaS Platform Architecture' and the use of multiple modern programming languages (Java, Python, Go, Rust, Node.js) suggest a microservices-oriented design, further enhancing modularity and ease of migration. While the company is heavily invested in Microsoft Azure, their containerized and IaC approach significantly mitigates platform-specific lock-in, making a transition to another cloud provider or a hybrid setup highly feasible. The absence of specified data residency requirements or complex regulatory environments (beyond general compliance managed by Vanta) also reduces potential migration hurdles. Financial stability data is missing, which could impact the ability to fund a large-scale migration, but the technical foundation is outstanding.
Compliance
7 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
Maltego is a cloud-based SaaS platform serving enterprise customers including government agencies, law enforcement, financial institutions (BNP Paribas, Santander), and large corporations (BASF, Deloitte, Hitachi). Enterprise and government customers — particularly US-based ones (FBI is listed as a customer) — frequently require SOC 2 Type II reports as a vendor due diligence prerequisite. The absence of a publicly confirmed SOC 2 certification represents a potential commercial and compliance risk, particularly for US government and enterprise procurement. Risk is Medium because: (1) Maltego has ISO 27001:2022 certification which provides significant security assurance overlap; (2) the Trust Center is powered by Vanta (a compliance automation platform commonly used for SOC 2 preparation); (3) however, without a confirmed SOC 2 report, enterprise customers in regulated industries may face procurement barriers. The risk is not High because ISO 27001 partially substitutes for SOC 2 in many European procurement contexts.
Evidence: https://trust.maltego.com/, https://www.maltego.com/blog/maltego-is-now-iso-27001-2022-certified/, https://www.maltego.com/
NIS2 (source) — Assessment Required
NIS2 (EU Directive 2022/2555, transposed into German law via the NIS2UmsuCG) potentially applies to Maltego on two grounds: (1) As a 'digital provider' — specifically a managed security service provider or online marketplace/platform — Maltego could qualify as an Important Entity under Annex II of NIS2, given it provides cybersecurity investigation tools to critical infrastructure operators, government agencies, law enforcement, and financial institutions across the EU; (2) As an ICT service management company serving essential and important entities, Maltego may fall under the 'ICT service management (B2B)' category. Risk is Medium because: NIS2 applicability depends on precise employee count and annual turnover thresholds (50+ employees OR €10M+ turnover for Important Entities), which are not publicly disclosed. The company serves 2,000+ government organizations and 4,000+ private companies globally, suggesting it likely meets size thresholds. Non-compliance with NIS2 carries fines up to €7M or 1.4% of global annual turnover for Important Entities. Germany's BSI (Bundesamt für Sicherheit in der Informationstechnik) is the competent authority and is actively enforcing NIS2 requirements. The cybersecurity sector nature of Maltego's business means it is likely already implementing many NIS2-required security measures (incident response, supply chain security, etc.) through its ISO 27001:2022 certification.
Evidence: https://www.maltego.com/about-us/, https://trust.maltego.com/, https://www.maltego.com/, https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Kritische-Infrastrukturen/NIS-2/nis-2_node.html
ISO 27001 (source) — Compliant
Maltego Technologies GmbH has publicly confirmed ISO 27001:2022 certification, which is the most current version of the international information security management standard. This certification is prominently displayed on the company homepage, about page, and in the website footer ('© 2018-2026 by Maltego Technologies. ISO 27001:2022 Certified'). ISO 27001:2022 certification requires a formal third-party audit by an accredited certification body and demonstrates that Maltego has implemented a comprehensive Information Security Management System (ISMS) covering risk assessment, security controls, incident management, business continuity, and continuous improvement. Risk is Low because active certification is confirmed, and the 2022 version (the latest) is in place, indicating up-to-date compliance with current security standards.
Evidence: https://www.maltego.com/, https://www.maltego.com/about-us/, https://www.maltego.com/blog/maltego-is-now-iso-27001-2022-certified/, https://trust.maltego.com/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Maltego Technologies GmbH exhibits a qualitatively strong financial resilience profile despite the absence of publicly retrievable statutory figures. The company operates a sticky, subscription-based B2G/B2B software model with high retention typical of intelligence and investigation tools embedded in analyst workflows. Its customer base is highly diversified, spanning 2,000+ government organizations, 4,000+ private-sector customers, and 200,000+ users worldwide, including 60%+ of the Dow 30 and marquee logos such as BASF, Santander, BNP Paribas, Telefónica, and the FBI. The company is backed by The Carlyle Group (Carlyle Europe Technology Partners) since November 2021, which implies audited accounts, professional governance, and access to growth capital. Maltego benefits from strong secular tailwinds in OSINT, cyber-threat intelligence, and defense-tech spend, and holds a category leadership position recognized by the Frost & Sullivan 2025 Product Leadership Award. ISO 27001:2022 certification and BDSV membership provide a regulatory moat for sales into sensitive customers. However, risks include government/defense customer concentration exposing the company to procurement cycles and export-control regulation, potential PE-related leverage that is not publicly disclosed, competitive pressure from Palantir, IBM i2, Babel Street, and others, and data-partner dependency across 120+ third-party providers. Currency exposure exists between a EUR-heavy cost base and USD-denominated US revenue. Overall the qualitative profile is attractive but precise financials are not verifiable.
Key strengths: Sticky subscription-based SaaS model with high retention, Highly diversified customer base across government and Fortune-scale enterprises, Backed by top-tier PE sponsor Carlyle since 2021, Category leader recognized by Frost & Sullivan 2025, ISO 27001:2022 certification and BDSV membership, Strong secular tailwinds in OSINT and cyber-threat intelligence, Product diversification via Search, Monitor, Evidence, Data, Cases, Admin, and Hunchly
Risk factors: Government/defense customer concentration exposes company to procurement cycles and export-control regulation, PE ownership may involve undisclosed leverage, Competitive pressure from Palantir, IBM i2, Babel Street, Fivecast, ShadowDragon, Dependency on 120+ third-party data partners in Transform Hub, Currency mismatch between EUR cost base and USD revenue, Increasing NGO/press scrutiny of OSINT tools
Revenue by geography
- EMEA: 50%
- Americas: 42%
- APAC: 8%
Revenue by product/service
- Maltego Graph (desktop client): 70%
- Maltego Search/Monitor/Evidence/Cases/Admin (cloud): 20%
- Maltego Data (marketplace) and Hunchly: 10%
Workforce by country
- Germany: 120
- Rest of EU: 50
- North America: 25
- Other: 5
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.