Nrich.ai
United Kingdom · nrich.ai · 19 vendors
N.Rich is a European Account-Based Marketing (ABM) platform for B2B companies, headquartered in Finland. It provides an AI-powered platform that leverages intent data and programmatic advertising to help businesses target ideal customer profiles, generate engagement, and demonstrate revenue impact. The platform automates complex marketing tasks, including campaign planning, content development, and media buying.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 8
- Financial Resilience: 5
Technology vendors
- Demandware — Technology — United States
- HubSpot, Inc. — Technology — United States
- Netlify, Inc. — Technology — United States
- and 25 more
Services catalogue
2 services in catalogue across 2 categories; runs on 19 sub-vendors.
- N.Rich
- Nrich.ai
Insights
Last updated 2026-08-04 · revision 1
19 direct vendors, 230 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 1
- United States: 13
- Japan: 1
Subvendors by controlling owner country (sample)
- United Kingdom: 2
- Sweden: 5
- South Korea: 1
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Nrich.ai exhibits moderate migration readiness. The company's modern tech stack, particularly the 'next-generation AI-powered GTM operating layer' (GTM OS) and 'AI ABM Copilot', suggests an architecture that could be amenable to cloud migration, potentially leveraging microservices or containerization. The existing strong regulatory compliance framework (ISO, GDPR, IAB TCF) means Nrich.ai has the processes and expertise to manage compliance during a migration, although adhering to these standards will add complexity. The use of SaaS platforms like HubSpot CMS and Teamtailor for certain functions reduces the migration burden for those specific areas. However, several critical unknowns significantly impact readiness. 'Data Residency Requirements' are not specified, which could introduce substantial challenges if strict regional data storage is mandated. The 'Vendor Lock-in Risk' is also unknown, and with 29 services, there's a potential for complex vendor relationships and contracts that could impede or increase the cost of migration. The presence of regional data centers implies some self-managed infrastructure, which typically requires more effort to migrate compared to a purely cloud-native environment. Finally, the absence of financial stability data makes it impossible to assess the company's capacity to fund a potentially large-scale migration initiative.
Compliance
9 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Compliant
N.Rich Technologies Oy holds a current ISO 27001:2022 certification, which is the most recent version of the standard (upgraded from ISO 27001:2013). This is the highest level of publicly verifiable compliance evidence available for information security management. The certification demonstrates that an accredited external certification body has audited and confirmed that N.Rich's ISMS meets all requirements of ISO/IEC 27001:2022, covering all 93 controls across organisational, people, physical, and technological themes. The company commits to regular external audits to maintain certification. Risk is Low because: (1) active certification is confirmed with publicly available certificate; (2) the standard directly addresses cyber risk, data protection, and regulatory compliance (GDPR, NIS); (3) regular surveillance audits are required to maintain certification; (4) the CEO has publicly committed to ongoing compliance. The primary residual risk is that certification scope may not cover all systems or geographies, and the certificate's exact scope and expiry date are not confirmed from the fetched content.
Evidence: https://nrich.io/iso-certification, https://nrich.io/hubfs/NRich_ISO27001_Certificate_u.pdf, https://nrich.io/about-us
NIS2 (source) — Assessment Required
NIS2 Directive (EU 2022/2555) applies to 'Important Entities' in the digital sector, specifically including 'digital providers' such as online marketplaces, online search engines, and cloud computing services, as well as managed service providers and managed security service providers. N.Rich Technologies Oy is a Finnish company providing a B2B SaaS platform (ABM advertising, intent data, analytics) operating across the EU. The company likely meets the size threshold (60+ employees, global operations, Gartner Magic Quadrant recognition suggesting significant revenue). As a digital service provider operating in the EU with a SaaS platform, N.Rich may fall under NIS2 as an 'Important Entity' in the digital providers category. However, the exact classification depends on whether N.Rich meets the specific NIS2 definitions for digital providers (online marketplace, online search engine, or cloud computing service) or ICT service management. ABM/AdTech platforms are not explicitly listed but may be captured under broader digital infrastructure or ICT service management categories. Finnish NIS2 transposition (Kyberturvallisuuslaki, effective April 2024) applies. Risk is Medium because: non-compliance with NIS2 can result in fines up to €7M or 1.4% of global turnover for Important Entities; the company's ISO 27001:2022 certification provides a strong foundation for NIS2 technical requirements; but formal NIS2 registration and compliance assessment status is unknown. A formal legal assessment of NIS2 applicability and registration with the Finnish Transport and Communications Agency (Traficom) is required.
Evidence: https://nrich.io/iso-certification, https://nrich.io/about-us, https://nrich.io/hubfs/NRich_ISO27001_Certificate_u.pdf
GDPR (source) — Partially Compliant
N.Rich Technologies Oy is a Finnish company (EU-incorporated) that processes large volumes of personal data of EEA residents as both a data controller and data processor. GDPR is unambiguously applicable. The company demonstrates significant compliance maturity: it holds ISO 27701:2019 certification (a GDPR-aligned privacy management standard), publishes detailed multi-tier privacy notices, maintains a dedicated DPO contact (privacy@n.rich), participates in the IAB Europe TCF (Vendor ID 20), implements consent management, and explicitly references GDPR legal bases (consent, legitimate interests) in its privacy notice. However, the status is 'Partially Compliant' rather than 'Compliant' because: (1) no independent GDPR audit report or supervisory authority clearance is publicly available; (2) the company processes behavioural data at scale across millions of websites globally, creating inherent complexity and residual risk; (3) the Belgian Market Court ruling of May 2025 confirmed TC Strings are personal data and that TCF participants (including N.Rich) are joint controllers with IAB Europe, introducing new compliance obligations that may still be in the process of being fully addressed; (4) cross-border data transfers outside the EEA occur for certain advanced capabilities, requiring ongoing Article 46 safeguard maintenance. Risk is Medium rather than High because of the strong documented compliance framework (ISO 27701, TCF participation, DPO, privacy notices), but the scale of data processing and evolving regulatory landscape (TCF ruling) maintain meaningful residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://nrich.io/iso-certification, https://privacy.nrich.ai/privacy-notice, https://nrich.io/hubfs/NRich_ISO27701_Certificate_u.pdf, https://nrich.io/hubfs/NRich_ISO27001_Certificate_u.pdf, https://iabeurope.eu/vendor-list-tcf/, https://nrich.io/privacy-notice-for-users/, https://nrich.io/privacy-notice-for-suppliers, https://nrich.io/privacy-notice-for-potential-customers/
Financials
Financial Resilience Score: 5/10
N.Rich Technologies Oy is a privately held Finnish SaaS company with approximately 10 years of operating history and a recurring-revenue ABM/GTM platform business model. The company demonstrates several strengths supporting moderate financial resilience: a recurring-revenue SaaS model that typically produces predictable, high-gross-margin revenue; an enterprise customer base including Fortune 500 clients like GE Healthcare, JetBrains, and Wärtsilä; analyst recognition via Gartner Magic Quadrant (2023 and 2025) and Frost & Sullivan Frost Radar 2024; ISO 27001:2022 and ISO 27701:2019 certifications supporting enterprise sales; and geographic diversification across Europe, US, and APAC. However, significant risks temper this assessment. The company competes in a highly competitive ABM category against much larger, better-funded US competitors (6sense, Demandbase, ZoomInfo, RollWorks, Bombora, Terminus). Its small scale (~60 employees) limits R&D pace and enterprise sales coverage. The proprietary DSP business exposes N.Rich to ad-tech pressures including cookie deprecation and privacy regulation. The 2026 launch of GTM OS represents both an opportunity and product transition risk. Unhedged FX exposure across USD/GBP/JPY/EUR is typical for a company this size. No verified financial figures (revenue, EBIT, equity) were available from the source report, as the company is private and filings from the Finnish PRH/YTJ registry were not accessible during the research session. A definitive resilience assessment would require review of official Finnish Trade Register filings. The mid-range score reflects credible qualitative signals of a viable mid-stage SaaS business balanced against unverified financials and intense competitive pressure.
Key strengths: Recurring-revenue SaaS model with typically high gross margins, Enterprise customer base including Fortune 500 (GE Healthcare, JetBrains, Wärtsilä, QAD, AutoStore, NFON, Signicat), Gartner Magic Quadrant Niche Player recognition (2023 and 2025) - only European-HQ vendor featured, Frost & Sullivan Frost Radar 2024 recognition, ISO 27001:2022 and ISO 27701:2019 certified, 10-year operating history (founded 2015), Geographic diversification across Europe, US, and APAC, Global partnership network including Dentsu for Japan, 300% new customer growth reported in 2022, 250+ GTM teams as customers by 2025
Risk factors: Highly competitive category against larger, better-funded US competitors (6sense, Demandbase, ZoomInfo, RollWorks, Bombora, Terminus), Small scale (~60 employees) limits R&D and sales coverage, Private-company financial opacity - no public disclosure of revenue, EBIT, or equity, Ad-tech/DSP business exposed to cookie deprecation and privacy regulation, Product transition risk from 2026 GTM OS launch potentially diluting focus, Unhedged FX exposure across USD/GBP/JPY/EUR, Capital-intensive proprietary DSP operations
Workforce by country
- Finland (HQ - Helsinki): 0
- United Kingdom (London office): 0
- United States (New York office): 0
- Japan (Tokyo office via SalesIntell partnership): 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.