MLR Cloud

United States · mlrcloud.com · 9 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 9 sub-vendors.

Insights

Last updated 2026-08-17 · revision 2

9 direct vendors, 151 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

MLR Cloud exhibits moderate migration readiness, leaning towards the lower end of the spectrum due to significant unknowns. The company utilizes several modern, API-driven services such as Stripe for payments, OpenAI for AI tooling, and Cloudflare for infrastructure, indicating a willingness to adopt contemporary solutions. The presence of an 'Email API Platform' and 'Webhook Integration' suggests an API-first approach and potentially modular architecture, which can facilitate migration. There is also a moderate vendor diversity with 11 vendors across 3 unique countries. However, several critical factors for migration readiness are unknown: vendor lock-in risk, specific data residency requirements, and the regulatory environment. The lack of financial stability data (revenue concentration, growth history) also means the ability to fund a significant migration effort is unassessed. Furthermore, while they use modern external services, their core infrastructure relies on 'data center hosting' from OVHcloud, Interserver.net, and Velia.net, rather than explicitly cloud-native platforms (e.g., AWS, GCP, Azure PaaS/SaaS). This suggests their internal systems might not be fully containerized or microservices-based, potentially increasing the complexity and effort required for a cloud migration.

Compliance

6 in-scope frameworks identified; showing 3.

CAN-SPAM Act — Partially Compliant

As an email marketing platform serving global customers, Mailercloud is directly subject to and facilitates compliance with email marketing laws including the US CAN-SPAM Act, Canada's Anti-Spam Legislation (CASL), and the EU's ePrivacy Directive. The company has published an Anti-Spam Policy and references strict compliance with spam laws. Risk is Medium because: (1) as a platform provider, Mailercloud bears responsibility for ensuring its platform is not used for spam; (2) the company has anti-abuse reporting mechanisms; (3) however, enforcement of customer compliance is challenging at scale; (4) CAN-SPAM violations can result in fines up to $51,744 per email; CASL violations up to CAD $10M per violation.

Evidence: https://www.mailercloud.com/anti-spam-policy, https://www.mailercloud.com/terms-and-conditions, https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, effective October 2024) may apply to Mailercloud as a digital provider. Mailercloud operates as a SaaS/cloud-based email marketing platform serving customers globally, including EU/EEA customers. Under NIS2, 'digital providers' — specifically 'online marketplaces', 'online search engines', and 'cloud computing services' — are classified as Important Entities if they meet the size threshold (50+ employees OR €10M+ annual turnover). Mailercloud's exact employee count and revenue are not publicly disclosed, making size threshold assessment uncertain. However, as a global SaaS platform with operations since 2013/2018 and a worldwide customer base, it is plausible the thresholds are met. Additionally, NIS2 applies to entities providing services within the EU, which Mailercloud does. The risk is Medium because: (1) if applicable, non-compliance with NIS2 carries fines up to €7M or 1.4% of global annual turnover for Important Entities; (2) NIS2 requires incident reporting, security measures, and supply chain risk management — areas where Mailercloud has some controls but no NIS2-specific compliance evidence; (3) the company is UK-based (post-Brexit), so NIS2 applies only to its EU service delivery, not its UK operations (which fall under UK NIS Regulations 2018).

Evidence: https://www.mailercloud.com/gdpr, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

SOC 2 (source) — Assessment Required

Mailercloud is a cloud SaaS provider handling customer data at scale, making SOC 2 highly relevant from a market expectation and enterprise customer trust perspective. SOC 2 is not a legal requirement but is a de facto standard for cloud service providers, particularly when serving enterprise customers in the US and globally. The risk is Medium because: (1) absence of a SOC 2 report may limit Mailercloud's ability to win enterprise contracts, particularly with US-based customers who routinely require SOC 2 Type II reports in vendor due diligence; (2) Mailercloud has implemented many overlapping controls (ISO 27001-aligned ISMS, access controls, encryption, incident response, BCP, penetration testing, vulnerability management, audit logging) that would support a SOC 2 audit; (3) no SOC 2 report has been publicly disclosed, creating a gap in third-party assurance for customers. The business risk of not having SOC 2 is primarily commercial (lost enterprise deals) rather than regulatory (no legal penalty).

Evidence: https://www.mailercloud.com/gdpr, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

Financials

Three-year financials

Financial Resilience Score: 4/10

MLR Cloud (Mailercloud) is a privately held email marketing SaaS company with no public financial disclosures available. No revenue, EBIT, equity, or headcount data has been published, and the company does not file with the SEC. The business appears to operate under a recurring subscription SaaS model with low capital intensity, which typically supports reasonable working-capital dynamics and margin scalability. The company has a multi-year operating history dating to 2013 (rebranded as Mailercloud in 2018), suggesting it has survived at least one macroeconomic downturn without visible failure. It maintains active product development, with recent launches including Email API, Email Verifier, AMP for Email, and MCP AI integration, indicating ongoing investment. However, financial resilience cannot be quantitatively assessed. The company operates in an extremely competitive category dominated by well-capitalized incumbents (Mailchimp/Intuit, Brevo, Klaviyo, HubSpot, MailerLite, ActiveCampaign), creating significant pricing and margin pressure. Its narrow single-product focus on email marketing makes it vulnerable to buyers consolidating on multi-channel platforms. Additionally, jurisdictional ambiguity between the stated US HQ and English-law Terms of Service, combined with no visible venture funding announcements, adds uncertainty. Overall, resilience is rated below average due to the complete absence of financial transparency and competitive risks.

Key strengths: SaaS subscription revenue model implies recurring revenue and reasonable working-capital dynamics, Low capital intensity typical of pure-play email marketing SaaS, Pricing scalability with free tier, pay-as-you-go, and enterprise/dedicated IP tiers, ISO and GDPR compliance claims signal baseline enterprise-readiness, Long operating history for a private SaaS (product roots to 2013, rebranded 2018), Active product investment with recent launches (Email API, Email Verifier, AMP, MCP AI integration)

Risk factors: Extremely competitive category dominated by well-capitalized incumbents (Mailchimp, Brevo, Klaviyo, HubSpot, MailerLite, ActiveCampaign), Regulatory and deliverability risk from ISP blocklists, Google/Yahoo bulk-sender policies, GDPR/CAN-SPAM enforcement, No public financial transparency for liquidity, profitability, or funding runway assessment, Concentration on a single product line (email marketing) vulnerable to multi-channel platform consolidation, No visible venture funding announcement; unclear if bootstrapped or funded, Jurisdictional ambiguity between stated US HQ and English-law Terms of Service

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report