meoo
Denmark · owned by Independent (Denmark) · www.meoo.dk · 11 vendors
meoo is a Danish AI-powered conversation partner that listens in on conversations and automatically generates meeting minutes, tasks, and insights. It serves a range of use cases including meetings, medical appointments, therapy sessions, sales, and recruitment. The product is designed to streamline documentation and follow-up across professional and healthcare contexts.
Resilience scores
- Digital Sovereignty: 36
- Digital Resilience: 5
- Financial Resilience: 3
Technology vendors
- HubSpot, Inc. — Technology — United States
- Microlink — Spain
- Supabase, Inc. — Technology — United States
- and 8 more
Insights
Last updated 2026-09-01 · revision 29
11 direct vendors, 191 subvendors
Direct vendors by controlling owner country (sample)
- Belgium: 1
- Spain: 1
- United States: 7
Subvendors by controlling owner country (sample)
- Netherlands: 1
- Sweden: 6
- France: 6
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
meoo exhibits medium migration readiness. A key strength is its modern, cloud-friendly tech stack, including Next.js, Supabase, AI/LLM, and existing GDPR-compliant EU/EEA cloud infrastructure. This suggests a relatively agile and modular architecture that would facilitate re-platforming or migration to new cloud environments, with no explicit legacy systems mentioned. However, several significant challenges reduce migration readiness. The regulatory environment is highly complex and restrictive, with mandatory compliance for GDPR and the Danish Data Protection Act, along with potential applicability of NIS2 and ePrivacy Directive. Coupled with stringent data residency requirements (mandating EU/EEA data storage, use of SCCs, and Transfer Impact Assessments for any third-country transfers), these factors will impose considerable constraints on target environments and necessitate extensive compliance planning, increasing the complexity, cost, and timeline of any migration effort. The unknown financial stability could also hinder the ability to fund a major migration project. Vendor lock-in risk is unclear; while there is geographic diversity among vendor HQ countries, the actual number of distinct vendors for the 15 services is not specified, making it difficult to assess concentration and potential lock-in. The contradictory vendor data ('Total Vendors: 0' vs. 'Total Services: 15' and vendor countries) further adds to this uncertainty.
Compliance
8 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC2 risk is rated Medium because meoo is a cloud-based SaaS platform that processes sensitive personal data including health information for business customers. Enterprise and healthcare clients increasingly require SOC2 Type II reports as a condition of vendor onboarding. Without a SOC2 report, meoo faces commercial risk (inability to win enterprise contracts) and reputational risk if a security incident occurs without demonstrated third-party assurance. The risk is Medium rather than High because SOC2 is a voluntary framework (not legally mandated in the EU), and meoo's current apparent market focus appears to be SMB/individual users rather than large enterprise clients requiring formal SOC2 attestation.
Evidence: https://www.meoo.dk/home/privacy, https://www.meoo.dk
ISO 27001 (source) — Assessment Required
ISO 27001 risk is rated Medium because meoo processes sensitive health data and audio recordings via an AI platform, making information security management critically important. Without ISO 27001 certification, meoo lacks a formally audited and internationally recognised security management framework. This creates commercial risk (enterprise clients may require ISO 27001 as a procurement condition), reputational risk in the event of a security breach, and potential GDPR Article 32 compliance gaps (which requires 'appropriate technical and organisational measures'). The risk is Medium rather than High because ISO 27001 is voluntary in the EU, and GDPR Article 32 compliance can be demonstrated through other means.
Evidence: https://www.meoo.dk/home/privacy, https://www.meoo.dk
EU AI Act (source) — Assessment Required
The EU AI Act risk is rated High because meoo's core product is an AI system that processes audio recordings and generates transcriptions, summaries, and insights from conversations — including medical consultations and therapy sessions. AI systems used in healthcare contexts may be classified as 'high-risk' under Annex III of the EU AI Act (specifically, AI systems used in health and safety, or AI systems used to make decisions affecting individuals in healthcare). High-risk AI systems face stringent requirements including conformity assessments, technical documentation, human oversight mechanisms, transparency obligations, and registration in the EU database. The EU AI Act's high-risk provisions began applying from August 2026, making this an urgent compliance priority.
Evidence: https://www.meoo.dk, https://www.meoo.dk/home/privacy, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 3/10
meoo (menii ApS) is a very early-stage Danish AI startup based in Copenhagen with only three known headcount (the co-founders). No public financial figures were retrievable in the research session, and no external funding has been disclosed on the company website, suggesting the company is likely bootstrapped or friends-and-family funded with a limited financial buffer. As a Danish ApS, the company is legally required to file annual reports with Erhvervsstyrelsen, but these would typically only disclose limited figures for a klasse B entity (gross profit, net result, equity, employee band). Qualitatively, the company shows some strengths including focused product-market fit signals across multiple high-value verticals (meetings, healthcare, therapy, sales, recruitment), a Danish/GDPR-native positioning advantage for clinical and public-sector use cases, and a lean team structure keeping burn low. However, the risks are substantial: intense competition in the commoditising AI meeting assistant category, margin compression from underlying LLM API costs, heavy regulatory exposure under GDPR Article 9 and potentially MDR for healthcare use, extreme key-person risk with only three founders, and likely customer concentration on a handful of pilot customers. Overall resilience is low given the early stage and lack of visible funding.
Key strengths: Focused product-market fit across multiple high-value verticals (meetings, healthcare, therapy, sales, recruitment), Danish/GDPR-native positioning provides data-residency and trust advantage for clinical and public-sector customers, Lean three-founder structure keeps burn low and preserves runway, Live product with public pricing page and free trial indicating monetisation has begun
Risk factors: Very small entity with no visible external funding disclosed; likely bootstrapped with limited financial buffer, Highly competitive category with commoditising AI meeting/transcription assistants (Otter, Fireflies, Read, tl;dv), Margin compression from underlying LLM API costs (OpenAI, Anthropic), Regulatory exposure under GDPR Article 9 (special-category data) and potentially MDR for healthcare use cases, Extreme key-person risk with only three founders and no disclosed additional staff, Likely customer concentration on a handful of pilot customers at this early stage
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 3
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.