Nexudus

United Kingdom · www.nexudus.com · 22 vendors

Nexudus offers a white-label software-as-a-service platform designed for coworking and flexible workspace operators. It helps manage operations, automate tasks such as bookings, billing, and member management, and provides tools to scale businesses. The platform supports thousands of workspaces in over 90 countries.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 22 sub-vendors.

Insights

Last updated 2026-08-11 · revision 2

22 direct vendors, 229 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Nexudus exhibits good migration readiness, primarily driven by its modern, cloud-native architecture on Microsoft Azure, extensive use of REST APIs, and the availability of a comprehensive .NET SDK. This API-first approach and modular design facilitate easier integration and potential re-platforming. The company's adherence to robust compliance frameworks (SOC 2, PCI DSS, GDPR) indicates mature processes that can support a structured and compliant migration. The geographic diversity of vendor HQs also suggests a potentially less concentrated vendor landscape. However, significant unknowns exist: 'Data Residency Requirements' are not specified, which could introduce substantial complexity and cost if strict rules apply. 'Vendor Lock-in Risk' is also unknown; while there are 22 services and diverse vendor locations, the actual number of distinct vendors and the nature of their contracts are not provided, which could pose challenges if there is deep coupling or high lock-in with critical vendors. Finally, the absence of financial data prevents an assessment of the company's capacity to fund a major migration initiative.

Compliance

6 in-scope frameworks identified; showing 3.

SOC 2 (source) — Partially Compliant

Nexudus explicitly references SOC 2 on its Security and Compliance page, stating it 'complies with the SOC 2 framework' and that 'controls are designed in accordance with the SOC 2 Security Trust Services Criteria.' However, the company does not publicly disclose a completed SOC 2 Type I or Type II audit report from an accredited CPA firm, nor does it reference a specific audit period or auditor. This distinction is significant: designing controls in accordance with SOC 2 criteria is not equivalent to receiving a formal SOC 2 attestation report. For enterprise customers evaluating Nexudus as a cloud service provider, the absence of a publicly available or customer-requestable SOC 2 report represents a medium compliance risk. Risk is Medium because: (1) the company is actively working toward SOC 2 alignment; (2) enterprise customers increasingly require SOC 2 Type II reports; (3) without a formal report, the compliance claim cannot be independently verified.

Evidence: https://nexudus.com/security/

GDPR (source) — Compliant

Nexudus explicitly self-declares GDPR compliance on its official Security and Compliance page, and as a UK-headquartered SaaS platform serving 3,000+ coworking spaces across 90+ countries — including EU/EEA member states — GDPR applicability is unambiguous. The company processes significant volumes of personal data (member profiles, visitor records, billing data, CRM data) on behalf of its customers, making it a data processor under GDPR. Risk is rated Medium rather than Low because: (1) the company acts as a data processor for thousands of operators globally, amplifying the scope of any potential breach; (2) no independent third-party GDPR audit or DPO appointment is publicly disclosed; (3) UK post-Brexit adequacy status (UK GDPR / Data Protection Act 2018) adds a layer of cross-border transfer complexity for EU customers. Fines under GDPR can reach €20M or 4% of global annual turnover. Enforcement by EU DPAs against SaaS processors has increased materially since 2021.

Evidence: https://nexudus.com/security/, https://help.nexudus.com/docs/privacy-policy, https://help.nexudus.com/docs/terms-and-conditions

UK Cyber Essentials — Compliant

Nexudus explicitly states it holds UK Government-backed Cyber Essentials certification on its Security and Compliance page. Cyber Essentials is a UK government-backed scheme that verifies five basic technical controls: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and patch management. Certification is granted by an accredited certification body. Risk is Low because: (1) the certification is confirmed and publicly disclosed; (2) Cyber Essentials is a well-established UK government scheme with clear certification criteria; (3) the certification demonstrates a baseline of cyber hygiene appropriate for a UK-based technology company.

Evidence: https://nexudus.com/security/, https://www.ncsc.gov.uk/cyberessentials/overview

Financials

Three-year financials

Financial Resilience Score: 7/10

Nexudus demonstrates strong qualitative financial resilience despite the absence of publicly disclosed revenue and EBIT figures. The company has been bootstrapped since its founding in 2012, growing without any external funding, which strongly implies sustained profitability and disciplined cost management. Surviving the COVID-19 pandemic and the WeWork-related downturn in the coworking industry without needing outside capital is a compelling signal of underlying financial health and operational efficiency. The company benefits from sticky recurring SaaS revenue embedded in daily customer operations (billing, access, bookings), high switching costs, and global diversification across 3,000+ locations in 90+ countries. Category leadership recognition (G2 Grid Leader Spring 2025, SoftwareReviews Gold Medallist 2022) and a deep integration ecosystem of 60+ partners further reinforce competitive positioning. However, resilience is tempered by end-market concentration in coworking/flexible workspace, which is sensitive to hybrid-work trends and commercial real-estate cycles. The small operational scale (~50 employees) limits R&D throughput versus larger competitors, and limited financial transparency under the UK small-company filing regime constrains external assessment. Founder-led structure and FX exposure across a multi-country customer base add additional risk layers.

Key strengths: Bootstrapped since 2012 with no external funding — implies operating cash flow profitability, Sticky recurring SaaS revenue with high switching costs, Global diversification across 3,000+ locations in 90+ countries, Category leadership (G2 Grid Leader Spring 2025, SoftwareReviews Gold Medallist 2022), Deep integration ecosystem with 60+ native integrations (Stripe, Xero, QuickBooks, Salto KS, Kisi, Brivo, Cisco Meraki), Survived COVID-19 downturn without outside capital

Risk factors: End-market concentration in coworking/flexible workspace sensitive to hybrid-work and CRE cycles, Small operational scale (~50 employees) limits R&D throughput vs larger competitors, Limited financial transparency under UK small-company filing regime, FX exposure from multi-country customer base with GBP-reporting entity, Key-person/founder-led risk with small leadership team, Competitive pressure from OfficeRnD, essensys, Yardi Kube, Cobot, Optix, andcards

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report