Merge

United States · www.merge.dev · 20 vendors

Resilience scores

Technology vendors

Services catalogue

13 services in catalogue across 3 categories; runs on 20 sub-vendors.

Insights

Last updated 2026-08-16 · revision 1

20 direct vendors, 249 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Merge exhibits a solid foundation for migration readiness, primarily due to its adoption of Amazon Web Services (AWS) and a modern tech stack including React. The presence of "Multi-tenant architecture" and products like "Merge Unified" (Unified API) and "Merge Gateway" (LLM routing) suggests a modular and API-driven approach, which generally facilitates easier migration to cloud-native environments. However, several factors introduce uncertainty and potential challenges. The coexistence of "Single-tenant architecture" alongside multi-tenant could indicate legacy components or specific customer deployments that might require more complex migration strategies. There is no explicit mention of containerization (e.g., Docker, Kubernetes) or a microservices architecture, which are key indicators of high migration readiness. Crucially, "Vendor Lock-in Risk" is unknown, and without knowing the number of unique vendors for the "23 services," it's difficult to assess the potential complexity and cost of disentangling from existing vendor relationships during a migration. The "Total Vendors: 0" data point is inconsistent with other vendor details; assuming vendors exist, the lack of specific vendor count makes assessing lock-in challenging. Furthermore, there is no data on regulatory environment, data residency requirements, or financial stability, all of which can significantly impact the scope, cost, and feasibility of a migration project.

Compliance

7 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

Merge has achieved SOC 2 Type II certification, which is the most rigorous level of SOC 2 attestation (covering a period of time rather than a point-in-time assessment). As a cloud services and API integration platform handling sensitive customer data across hundreds of third-party integrations, SOC 2 is highly relevant and Merge has fully addressed it. Risk is Low because SOC 2 Type II certification demonstrates that Merge's controls for security, availability, and confidentiality have been independently audited and found effective over an audit period. The certification is listed in the Trust Center with a downloadable SOC 2 Report available upon request.

Evidence: https://trust.merge.dev/, https://www.merge.dev/security, https://www.merge.dev/

EU-US Data Privacy Framework — Compliant

Merge has self-certified under the EU-US Data Privacy Framework, Swiss-US DPF, and UK Extension to EU-US DPF, providing a legal mechanism for transferring personal data from the EU, Switzerland, and UK to the US. This is directly relevant to Merge's business model of processing EU customer data on US infrastructure. Risk is Low because Merge has proactively obtained all three DPF certifications, supplementing its SCCs in the DPA. The DPF was established in July 2023 following the Schrems II ruling and provides a robust legal transfer mechanism.

Evidence: https://trust.merge.dev/, https://www.merge.dev/eu, https://www.merge.dev/legal/data-processing-agreement

CCPA — Compliant

Merge is headquartered in the United States (New York/San Francisco) and processes personal data of California residents, making CCPA applicable. Risk is Low because Merge explicitly lists CCPA as a compliance framework in its Trust Center and security page, and has implemented the necessary privacy controls (data deletion, data access, privacy policy, cookie management). CCPA enforcement by the California Privacy Protection Agency (CPPA) is active, but Merge's proactive compliance posture significantly mitigates risk.

Evidence: https://trust.merge.dev/, https://www.merge.dev/security, https://www.merge.dev/legal/privacy-policy, https://www.merge.dev/cookie-settings

Financials

Three-year financials

Financial Resilience Score: 6/10

Merge is a well-funded, mid-stage private US SaaS company with approximately $74.5M in cumulative venture capital raised through its October 2022 Series B round led by Accel, with prior participation from NEA and Addition. The company benefits from strong institutional backing, a diversified blue-chip customer base spanning fintech (Ramp, Bill.com, Brex, Revolut, Airwallex), HR-tech (BambooHR, Handshake, Remote), compliance (Drata), and frontier-AI labs (OpenAI, Mistral, Perplexity), which reduces single-vertical concentration risk. Enterprise-grade certifications (SOC 2 Type II, ISO 27001, HIPAA, GDPR) support enterprise deal sizes and retention. However, the absence of audited financial disclosures means unit economics, burn rate, gross margin, and path to profitability cannot be verified. The last publicly announced funding round was in October 2022, meaning the company may need to raise additional capital or reach breakeven amidst a broader VC-market SaaS revaluation. Competitive pressure is intensifying in both the unified API/embedded iPaaS space (Finch, Nango, Paragon, Workato, Tray.ai, Apideck, Kombo) and the AI infrastructure space (LangChain, LlamaIndex, Portkey, OpenRouter), where Merge's newer products compete. The reported Series B valuation of $500-600M and expansion into AI infrastructure suggest positive momentum, but financial opacity keeps the resilience score moderate.

Key strengths: ~$74.5M cumulative venture funding from Accel, NEA, and Addition, Diversified blue-chip customer base across fintech, HR-tech, compliance, and frontier-AI verticals, Successful expansion into AI infrastructure with Agent Handler and Gateway products, Enterprise-grade certifications (SOC 2 Type II, ISO 27001, HIPAA, GDPR), Multi-product strategy enabling upsell/cross-sell, External validation via Forbes Cloud 100 Rising Stars (2022) and Forbes Next Billion-Dollar Startups (2023), 3,000+ organizations on platform as of Series B (Oct 2022)

Risk factors: No public financial transparency - unit economics, burn rate, and profitability unverifiable, Crowded unified API/iPaaS competitive landscape (Finch, Nango, Paragon, Workato, Tray.ai), Platform risk from hyperscalers and open MCP standards potentially commoditizing connectors, Increased R&D spend on unproven AI infrastructure market with well-funded competitors, No announced funding round since October 2022; future raise or breakeven required, Broader VC-market SaaS revaluation headwind, Dependency on third-party APIs outside Merge's control

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report