Modular Finance
Sweden · www.modularfinance.se · 9 vendors
Resilience scores
- Digital Sovereignty: 33
- Digital Resilience: 6
- Financial Resilience: 8
Technology vendors
- Anthropic, PBC — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Mandrill (an Intuit company) — United States
- and 6 more
Services catalogue
3 services in catalogue across 1 category; runs on 9 sub-vendors.
- IR Tools
- MFN News Feed
- Share Price Widget
Insights
Last updated 2026-08-19 · revision 2
9 direct vendors, 134 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- Denmark: 2
- Netherlands: 1
Subvendors by controlling owner country (sample)
- Denmark: 1
- Norway: 4
- Ireland: 1
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Modular Finance demonstrates medium migration readiness. A significant strength is its highly modern and cloud-native oriented tech stack, including GCP, CI/CD, SIEM, API-first data delivery, SaaS, and LLM integration. This architecture is inherently conducive to migration, suggesting a flexible and modular system that would facilitate moving to new environments or platforms. However, the primary challenges for migration readiness stem from the complex regulatory environment and stringent data residency requirements. The company faces numerous 'Assessment Required' or 'Partially Compliant' statuses for critical regulations such as GDPR, MAR (High risk), NIS2, SOC 2, ISO 27001, MiFID II, UK GDPR, and Swedish financial supervision. Any migration would necessitate meticulous planning and validation to ensure continuous compliance, especially for sensitive data under MAR and GDPR, and to address the lack of public third-party audits. Data residency requirements are strict, mandating primary processing within the EU/EEA (Sweden for Strictlog), adherence to UK GDPR for UK operations, and the unique constitutional protection of the Swedish YGL for the Holdings database. These requirements impose significant constraints on where data can be stored and processed, complicating any cross-border or multi-cloud migration strategies. Financial stability to fund a migration is unknown due to missing revenue and growth data. Furthermore, with 12 services supported by vendors from only 3 unique HQ countries (US, Denmark, Netherlands), there is a high risk of vendor lock-in, which would significantly complicate and increase the cost of disentangling services during a migration.
Compliance
9 in-scope frameworks identified; showing 3.
Swedish Securities Market Act — Assessment Required
Modular Finance operates in the Swedish capital markets ecosystem, providing services to listed companies, banks, and financial advisors. The Swedish Securities Market Act implements MiFID II in Sweden and is enforced by Finansinspektionen (FI). As a provider of regulatory news distribution (MFN), shareholder data services, and MAR compliance tools, Modular Finance may be subject to FI oversight or registration requirements. Risk is Medium because: operating regulated financial market infrastructure without proper authorization carries significant legal and reputational risk; however, the company's services may be classified as information/technology services rather than regulated financial services.
Evidence: https://modularfinance.com/mfn, https://modularfinance.com/strictlog, https://www.fi.se/en/, https://www.fi.se/en/our-registers/
SOC 2 (source) — Assessment Required
Modular Finance is a cloud-based SaaS provider serving financial institutions, listed companies, banks, and investment firms across Nordic markets and the UK. SOC 2 (developed by AICPA) is not legally mandated in the EU but is increasingly required by enterprise customers — particularly financial institutions — as a condition of vendor onboarding. Customers such as NatWest (a major UK bank) and Nordnet (a Nordic financial services company) are likely to have vendor due diligence requirements that include SOC 2 or equivalent assurance reports. The Strictlog page references being 'delivered by an ISO- and FSQS-aligned supplier,' suggesting awareness of third-party assurance requirements, but no SOC 2 report has been publicly disclosed. Risk is Medium because: (1) enterprise financial sector customers increasingly mandate SOC 2 Type II reports; (2) absence of SOC 2 may create competitive disadvantage or contract risk; (3) the company's handling of sensitive insider/PDMR data and shareholder data makes security assurance particularly important.
Evidence: https://modularfinance.com/strictlog, https://modularfinance.com/about-modular-finance
ISAE 3000 (source) — Assessment Required
ISAE 3000 is an international assurance standard used for non-financial assurance engagements, including data security, privacy, and sustainability reporting. For a SaaS company like Modular Finance serving financial institutions, ISAE 3402 (assurance on controls at service organizations) or ISAE 3000-based reports may be requested by enterprise clients as an alternative to SOC 2. No ISAE 3000 or ISAE 3402 report has been publicly disclosed by Modular Finance. Risk is Low because ISAE 3000 is not legally mandated and is less commonly required than ISO 27001 or SOC 2 in the Nordic/UK market. However, as the company grows and serves larger financial institutions, demand for such assurance reports may increase.
Evidence: https://modularfinance.com/strictlog, https://modularfinance.com/about-modular-finance
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 8/10
Modular Finance AB demonstrates strong qualitative financial resilience despite the absence of publicly retrievable numeric figures in this session. The company operates a recurring-revenue SaaS model across seven+ products serving Investor Relations, regulatory compliance, and shareholder data segments. This subscription-based structure typically generates high revenue visibility, strong gross margins, and predictable cash flows. Historical commentary from founders indicated consistent profitability and healthy double-digit growth. The company benefits from significant competitive moats including network effects on ownership data, regulatory tailwinds from MAR and transparency directives, and a diversified product portfolio spanning both listed-company IR customers and financial institutions. Institutional backing from Sprints Capital and Rite Ventures, combined with founder/staff majority ownership, provides governance strength. The 2024 Breakit SaaS Company of the Year award signals strong growth and profitability metrics per jury criteria. Risks include exposure to cyclical listed-equity markets, competition from global players (Nasdaq IR, S&P Global, Euronext), a finite Nordic addressable market requiring successful UK/international expansion, and dependencies on data providers like Euroclear. Overall, the qualitative profile suggests above-average resilience for a private Nordic SaaS company.
Key strengths: Recurring-revenue SaaS subscription model with high visibility, Network effects on ownership data creating defensible moat, Diversified portfolio of 7+ products reducing concentration risk, Regulatory tailwinds (MAR, transparency directives) driving sticky demand, Blue-chip international customers (NatWest, Rightmove), Strong institutional backing (Sprints Capital, Rite Ventures), Experienced board with independent chairman Lars-Åke Norling, Breakit SaaS Company of the Year 2024 award
Risk factors: Small Nordic home-market base with finite addressable market, Customer concentration in cyclical listed-equity ecosystem, Competition from global players (Nasdaq IR, S&P Global, Euronext, Q4), Data-provider dependencies (Euroclear) and GDPR/privacy risks, Limited public visibility into cash, debt, and churn metrics, Growth dependency on successful UK and international expansion
Revenue by geography
- Norway: 0%
- Sweden: 0%
- Denmark: 0%
- Finland: 0%
- United Kingdom: 0%
Revenue by product/service
- Dataflow (API): 0%
- Datablocks (IR websites): 0%
- Estimates (analyst consensus): 0%
- Add-ons (CRM Pro, Bonds, Uncover): 0%
- MFN (regulatory news distribution): 0%
- Strictlog (MAR/insider-list compliance): 0%
- Monitor / Holdings (shareholder data & IR CRM): 0%
Workforce by country
- Sweden: 0
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.