Mave
Netherlands · mave.io · 16 vendors
Resilience scores
- Digital Sovereignty: 63
- Digital Resilience: 7
- Financial Resilience: 4
Technology vendors
- Mistral AI — Technology — France
- Mollie B.V. — Netherlands
- Proton AG — Other — Switzerland
- and 14 more
Services catalogue
1 service in catalogue across 1 category; runs on 16 sub-vendors.
- Mave.io
Insights
Last updated 2026-08-15 · revision 1
16 direct vendors, 212 subvendors
Direct vendors by controlling owner country (sample)
- Belgium: 1
- United States: 4
- Netherlands: 2
Subvendors by controlling owner country (sample)
- France: 11
- South Korea: 1
- Denmark: 9
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Mave exhibits a high level of migration readiness, scoring 82. This is primarily driven by its modern, cloud-friendly tech stack, including Elixir for backend services, TypeScript and Vue.js for frontend, and a clear adoption of Scaleway as its primary cloud infrastructure (transitioning from Cloudflare, indicating a willingness to migrate core infrastructure). The platform's architecture, featuring a REST API, web components, and options like 'bring-your-own CDN' and 'managed cloud distribution', suggests inherent flexibility and a design philosophy that supports portability and integration. A significant strength is Mave's deep expertise and focus on regulatory compliance, particularly GDPR, cookieless operations, and European data sovereignty. Their products are built around these stringent requirements, including a 'self-hosted metrics option for full data sovereignty', which implies a sophisticated understanding and capability to manage data residency and compliance during migration. This expertise reduces the complexity and risk associated with migrating to new environments that must adhere to similar regulations. While the data states 'Total Vendors: 0', which is contradictory to the 'Total Services: 22' and vendor geographic data, Mave's architectural flexibility (e.g., BYO CDN) and demonstrated willingness to switch core cloud providers (Cloudflare to Scaleway) suggest a low practical vendor lock-in risk for critical infrastructure. The main weakness in assessing migration readiness is the absence of financial stability data, which would provide insight into Mave's capacity to fund a significant migration effort. Despite this, the technical and operational readiness is exceptionally strong.
Compliance
7 in-scope frameworks identified; showing 3.
WCAG 2.2 AA — Partially Compliant
Mave displays a WCAG 2.2 AA self-assessment badge on its website footer, indicating active engagement with accessibility standards. However, this is a self-assessment rather than a third-party certified audit, which introduces some uncertainty about full compliance. Risk is Low because: (1) WCAG is not a direct legal requirement for Mave's current operations (though the EU Web Accessibility Directive applies to public sector bodies, and the European Accessibility Act will expand requirements from 2025); (2) Mave's proactive self-assessment demonstrates good faith compliance efforts; (3) the video platform nature of the business makes accessibility (subtitles, player controls) a natural product feature, as evidenced by Mave's automatic subtitle feature.
Evidence: https://www.mave.io/, https://www.mave.io/blog/mave-accessible-video-player-wcag-2-2-aa/
ISO 27001 (source) — Compliant
Mave has achieved ISO 27001 certification, as publicly announced on April 28, 2026, and certified by DNV (a globally recognized accredited certification body). The DNV ISO/IEC 27001 badge is displayed on the Mave website footer with a direct link to the certification announcement. This represents full compliance with the international standard for information security management systems. Risk is Low because: (1) certification is confirmed by an accredited third-party auditor (DNV); (2) ISO 27001 requires ongoing surveillance audits and recertification, indicating a sustained commitment; (3) the certification covers the Mave ISMS including risk management, access control, incident response, and continuous improvement; (4) this directly reduces information security risk for Mave and its customers.
Evidence: https://www.mave.io/blog/mave-achieves-iso-27001-certification/, https://www.mave.io/
ISAE 3000 (source) — Assessment Required
ISAE 3000 is an assurance framework used by auditors to provide independent assurance on non-financial information, including sustainability reports, internal controls, and data processing practices. It is not a direct regulatory requirement for Mave's industry. Risk is Low because: (1) ISAE 3000 is not mandated for video hosting platforms; (2) Mave's ISO 27001 certification provides stronger and more directly relevant assurance for its customer base; (3) ISAE 3000 engagements (such as ISAE 3402 for service organizations) may be requested by large enterprise customers but are not a standard requirement for Mave's current market segment; (4) no evidence of ISAE 3000 engagement has been found. The framework may become relevant if Mave grows to serve large financial institutions or regulated industries requiring ISAE 3402 reports.
Evidence: https://www.mave.io/, https://www.mave.io/blog/mave-achieves-iso-27001-certification/
Financials
Three-year financials
- null:
Financial Resilience Score: 4/10
mave.io B.V. is a small, privately held Dutch SaaS company with credible product differentiation in EU-sovereign, GDPR-compliant video hosting. The company benefits from a recurring subscription revenue model (starting at €19/month), ISO 27001 certification, and favorable regulatory tailwinds such as the Digital Markets Act and the upcoming Dutch Archives Act (Jan 2027), which support demand from EU public-sector and enterprise buyers. Reference customers like Sketch and Freedom Internet lend credibility. However, the company discloses no public financials, has no confirmed external venture funding, and is likely bootstrapped or founder-funded. Its small scale (single-digit to low-double-digit headcount inferred), heavy competition from Vimeo, Wistia, Cloudflare Stream, Mux, and Bunny Stream, and founder/key-person concentration risk (David van Leeuwen as the visibly active leader) all weigh on resilience. Infrastructure cost concentration on Scaleway and disclosure opacity as a small Dutch B.V. further limit visibility into cash runway. Overall, the score reflects a promising but fragile small business with limited financial transparency.
Key strengths: Recurring SaaS subscription revenue model (€19+/month), ISO 27001 certification lowers enterprise procurement friction, EU sovereignty/GDPR positioning aligned with regulatory tailwinds (DMA, Dutch Archives Act 2027), Credible reference customers (Sketch, Freedom Internet), Lean, product-led operations with open-source components reducing CAC
Risk factors: No confirmed external funding; likely bootstrapped with limited capital buffer, Very small absolute scale; likely low six- to low seven-digit EUR revenue (inferred), Heavy competition from Vimeo, Wistia, Cloudflare Stream, Mux, Bunny Stream, Infrastructure cost concentration on single vendor (Scaleway), Founder/key-person risk concentrated in David van Leeuwen, Limited public financial disclosure as a small Dutch B.V., Only two named reference customers; potential customer concentration risk
Revenue by geography
- European Union (Netherlands, Germany, broader EU): 100%
Revenue by product/service
- Video SaaS Platform (hosting, player components, analytics, API): 100%
Workforce by country
- Netherlands: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.