Celanin ApS
Denmark · owned by Independent (Denmark) · neupart.net · 8 vendors
Celanin ApS is the personal investment vehicle of Lars Neupart, a Danish business angel and cybersecurity entrepreneur based in Copenhagen. Operating since at least 2017, it has made 40+ pre-seed investments with a strong focus on cybersecurity and B2B SaaS companies, primarily in Denmark. Lars Neupart is also an active board member of the DanBAN co-investment fund and founder of Resiliate.io.
Resilience scores
- Digital Sovereignty: 25
- Digital Resilience: 2
- Financial Resilience: 6
Technology vendors
- GoDaddy Inc. — Technology — United States
- Google LLC — Technology — United States
- WebPros International GmbH — Technology — Switzerland
Insights
Last updated 2026-09-15 · revision 14
3 direct vendors, 51 subvendors
Direct vendors by controlling owner country (sample)
- United States: 2
- Switzerland: 1
Subvendors by controlling owner country (sample)
- Bulgaria: 1
- Denmark: 2
- Israel: 1
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Celanin ApS demonstrates low migration readiness, largely due to its precarious financial position with null revenue and persistent negative gross profit, which severely constrains its capacity to fund any significant migration initiatives. The regulatory landscape presents considerable challenges, with existing compliance gaps (GDPR, DORA, NIS2, SOC 2) that would necessitate extensive effort and cost to address and re-certify within a new migrated environment. GDPR's data residency requirements for transfers outside the EU/EEA also add a layer of complexity. The company faces a medium vendor lock-in risk, which could complicate the process of disentangling from current services and re-establishing them with new providers. While the internal tech stack, consisting of 'Cookieless Website Infrastructure' and 'No Analytics or Tracking', is simple and might imply low technical debt, it also indicates a lack of modern, cloud-native architecture (e.g., containerization, microservices). This means the company is not inherently 'ready' for a modern cloud migration and would likely need to build new infrastructure from the ground up rather than simply re-platforming an existing complex system. The technical simplicity offers an opportunity for a clean start, but this is overshadowed by the significant financial and regulatory hurdles.
Compliance
8 in-scope frameworks identified; showing 3.
DORA (source) — Assessment Required
The Digital Operational Resilience Act applies to financial entities and their ICT third-party service providers. Celanin ApS provides GRC software to the financial sector, making it a direct subject of these third-party risk management rules.
As a provider of GRC software to financial entities, a failure in Celanin's systems could directly impact their clients' operational resilience and compliance. The financial sector is a primary target for cyberattacks, heightening the risk.
Evidence: https://tracxn.com/d/companies/neupart/__lKONF-i2xeMde4rjFH1MgnOIXoeH-xBAZ2wqtjjZzHk
ISO 27001 (source) — Assessment Required
ISO 27001 is a voluntary information security management standard, but it is effectively a requirement in the financial services sector for technology vendors. One source states Neupart is part of KMD, an ISO 27001 certified company.
Certification is a strong market expectation for a security software provider selling to regulated industries. Lacking it could be a significant competitive disadvantage and raise client concerns about security posture.
SOC 2 (source) — Assessment Required
SOC 2 is a voluntary assurance framework focused on controls related to security, availability, processing integrity, confidentiality, and privacy. It is frequently requested by customers in North America and is common for SaaS providers.
While not as prevalent as ISO 27001 in Europe, some clients, particularly those with US operations, may require a SOC 2 report. The risk is primarily related to missing specific commercial opportunities rather than broad market access.
Financials
Three-year financials
- 2025: gross profit DKK -116K, EBIT DKK -728K, equity DKK 7.81M
- 2024: gross profit DKK -226K, EBIT DKK -889K, equity DKK 13.4M
- 2023: gross profit DKK -221K, EBIT DKK -912K, equity DKK 13.7M
Financial Resilience Score: 6/10
Celanin ApS is a Danish one-person holding vehicle with a solid but eroding equity base of DKK 7.81M at end-2025, providing several years of cushion against the modest annual operating cash burn of DKK 0.7-0.9M. The lean cost structure (1 employee, no audit, minimal overhead) and long operating track record since 2001 support baseline resilience. The company has weathered previous down years, such as the DKK -6.28M net loss in 2022 followed by a DKK +10.6M profit windfall in 2023. However, the resilience profile is weakened by persistent operating losses every year in the four-year history, meaning the entity relies entirely on episodic investment income or capital events (dividends from subsidiaries, capital gains) to generate profit. Equity has fallen 43% over two years from DKK 13.7M (2023) to DKK 7.81M (2025), and the 2025 equity level has essentially cycled back to the 2022 base. Single-asset concentration, key-person risk (sole director Lars Neupart), unaudited accounts, and opaque revenue disclosure further limit external assurance and add structural fragility typical of a founder holding shell.
Key strengths: Solid equity base of DKK 7.81M relative to DKK 0.7-0.9M annual operating burn, Minimal fixed cost structure (1 employee, no audit), Long track record since 2001, Owner alignment with sole director/beneficial owner Lars Neupart, Demonstrated ability to recover from prior loss years (2022 to 2023 rebound)
Risk factors: Single-asset concentration typical of a holding vehicle, Persistent operating losses every year in the four-year history, Equity erosion of 43% over two years (DKK 13.7M to DKK 7.81M), Key-person risk with single director and single employee, Unaudited accounts (revision fravalgt) reduce third-party assurance, Opaque revenue disclosure as a Danish micro-entity
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 1
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.