northfive ApS
Denmark · owned by Evolve Holding ApS (Denmark) · www.n5.team · 5 vendors
northfive (N5) is an AI-native managed cloud operations company headquartered in Denmark, offering AI enablement for people, processes, and operations as a modern alternative to the traditional MSP model. They deliver agentic, observable, and sovereign cloud operations, along with targeted AI workshops and process automation for enterprise clients. Operating with Nordic roots and European reach, they serve organisations primarily across the Nordic and Baltic regions.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 9
- Financial Resilience: 4
Disruption prediction
northfive ApS has an estimated 40% probability of disruption in the next 6 months.
5 of northfive ApS's 5 vendors monitored for disruptions.
Technology vendors
- Anthropic, PBC — Technology — United States
- Google LLC — Technology — United States
- Microsoft Corporation — Technology — United States
- and 7 more
Services catalogue
2 services in catalogue across 2 categories; runs on 5 sub-vendors.
- Agentic AI
- AI-Native Managed Cloud Operations
Insights
Last updated 2026-09-02 · revision 2
5 direct vendors, 150 subvendors
Direct vendors by controlling owner country (sample)
- United States: 5
Subvendors by controlling owner country (sample)
- Sweden: 5
- United Kingdom: 2
- China: 7
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
northfive ApS exhibits very high migration readiness, scoring 90. This is largely due to its advanced and flexible technology stack, which is explicitly cloud-native, multi-cloud/hybrid, and incorporates AI-native operations. The use of modern frameworks like Next.js and inferred Vercel deployment, alongside 'Sovereign cloud infrastructure' as a key technology, indicates a design philosophy geared towards portability and minimal infrastructure lock-in. The company's focus on 'Compliance-by-design' suggests that any regulatory requirements are likely integrated into their architecture, simplifying potential migrations. Data residency requirements are 'Not specified', which, in the absence of strict mandates, simplifies the migration process. The vendor relationship data is contradictory: 'Total Vendors: 0' is stated, while 'Total Services: 15' are listed with vendor geographic information. If 'Total Vendors: 0' is accurate for core infrastructure, it implies very low vendor lock-in, which is a significant enabler for migration. Even if there are external vendors for 15 services, the overall architectural approach suggests a high degree of independence from specific vendor platforms. The 'Vendor Lock-in Risk' is 'Unknown', but the tech stack points to inherent flexibility. Financial stability data (revenue concentration, growth history) is not available, which could impact the ability to fund a large-scale migration, but the current architecture suggests migrations would be less disruptive and costly than for legacy systems.
Compliance
7 in-scope frameworks identified; showing 3.
Danish Bookkeeping Act — Assessment Required
The Danish Bookkeeping Act (Bogføringsloven, Act No. 700 of 24 May 2022) applies to all Danish companies and includes new digital bookkeeping requirements phased in from 2024. Risk is Low because this is a standard business compliance requirement applicable to all Danish companies, and non-compliance risk is manageable with standard accounting practices. The company's privacy policy references compliance with Danish bookkeeping law for retention of accounting records, suggesting awareness.
Evidence: https://www.n5.team/privacy/, https://erhvervsstyrelsen.dk/bogfoeringsloven, https://www.retsinformation.dk/eli/lta/2022/700
SOC 2 (source) — Assessment Required
northfive ApS provides managed cloud operations and AI services to enterprise clients, operating client infrastructure and data environments. SOC 2 (developed by the AICPA) is not a legal requirement but is a widely expected market standard for technology service providers and MSPs, particularly when serving enterprise or regulated-industry clients. Risk is Medium because: (1) clients entrusting their cloud infrastructure and AI operations to northfive will likely request SOC 2 Type II reports as part of vendor due diligence; (2) absence of SOC 2 certification may be a commercial barrier to enterprise sales; (3) the company's positioning around 'sovereignty', 'auditability', and 'compliance built in' creates an implicit expectation of formal assurance. The risk is not High because SOC 2 is voluntary and the company is early-stage.
Evidence: https://www.n5.team/, https://www.n5.team/ai-operations/, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy
Danish Data Protection Act — Partially Compliant
The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with national specifications applicable to all Danish companies. Risk mirrors GDPR risk: the company has demonstrated awareness through its privacy policy but has not publicly evidenced full compliance with Danish-specific provisions such as employee data processing rules (§12), processing of CPR numbers (Danish personal identification numbers), or specific consent requirements. As a company with employees in Denmark, employee data processing under the Danish Act is directly applicable.
Evidence: https://www.n5.team/privacy/, https://www.datatilsynet.dk/english, https://www.retsinformation.dk/eli/lta/2018/502
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 4/10
northfive ApS is a newly registered Danish company (CVR 45146375, registered in 2024) with no publicly filed financial statements yet available. As an early-stage ApS, its financial resilience cannot be verified from public data. The company benefits from an experienced founding team of four senior Nordic technology practitioners, timely market positioning in AI-native managed cloud operations and European data sovereignty, and a low-capital-intensity services/consulting model that can achieve positive cash flow relatively quickly with high utilization. However, significant risks weigh on resilience: no trading history, minimum ApS share capital (likely around DKK 20,000) providing limited balance sheet buffer, high key-person dependency across only four named founders, a crowded competitive landscape (Netcompany, Devoteam, Twoday, Nordcloud, hyperscaler partners), likely customer concentration typical of boutique consultancies, and long enterprise procurement cycles in the Nordics that can strain cash flow. Overall the score reflects a plausible but unproven early-stage firm with credible leadership but no financial track record.
Key strengths: Experienced multi-founder leadership team with senior Nordic tech backgrounds, Timely positioning in AI-native cloud ops and EU data sovereignty (aligned with EU AI Act tailwinds), Low capital-intensity services/consulting model, European-only delivery reduces non-EU regulatory friction and appeals to regulated Nordic clients
Risk factors: Very early-stage company with no trading history or filed accounts, Minimum ApS share capital implies limited balance-sheet buffer, High key-person dependency across four named founders and a small team, Crowded competitive market of Nordic/European IT consultancies pivoting to AI, Likely customer concentration risk typical of young boutique consultancies, Long enterprise AI/sovereignty sales cycles in the Nordics can strain cash
Revenue by geography
- Norway: 0%
- Sweden: 0%
- Denmark: 0%
- Finland: 0%
- Lithuania: 0%
Revenue by product/service
- AI Operations: 0%
- AI for People: 0%
- AI in Processes: 0%
Workforce by country
- Norway: 0
- Denmark: 0
- Lithuania: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.