Numero AI

United States · www.numero.ai · 7 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 7 sub-vendors.

Insights

Last updated 2026-08-11 · revision 2

7 direct vendors, 142 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Numero AI's migration readiness is moderate, primarily driven by its modern technology but hampered by regulatory complexities and data unknowns. The company's internal tech stack is modern and cloud-oriented, leveraging Astro, Cloudinary, and U.S.-based cloud infrastructure. The development of a native iOS app and the use of AI/ML suggest an agile and adaptable technical foundation, which generally facilitates migration. However, significant challenges exist. The highly regulated nature of their industry (political fundraising, FEC compliance) poses a considerable hurdle; any migration would require meticulous planning to ensure continuous adherence to complex regulatory requirements. Data residency requirements are 'Not specified,' but given their U.S.-centric operations, it is probable that data must remain within the U.S., potentially limiting migration options to specific cloud regions or providers. Crucially, there is no available data on financial stability (revenue, growth), making it impossible to assess the company's capacity to fund a potentially costly migration effort. Vendor relationships are unclear due to conflicting data ('Total Vendors: 0' versus 'Total Services: 10' and vendor geographic diversity), and the 'Vendor Lock-in Risk' is unknown, which could introduce unforeseen complexities and costs during a migration.

Compliance

6 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 certification is not legally mandated but is a globally recognized benchmark for information security management. Numero AI processes highly sensitive political donor data, financial contribution records, personal contact information (names, addresses, phone numbers, email addresses, dates of birth), voice recordings, and payment-adjacent data for 1,000+ campaigns. The company is a small organization (~17 employees) based in the US, where ISO 27001 is less commonly mandated than in Europe. However, the sensitivity of the data processed — particularly given the political nature of the campaigns and the potential for targeted attacks on political infrastructure — elevates the importance of formal ISMS controls. No ISO 27001 certification has been identified. The risk is Medium because the company's small size makes full ISO 27001 certification less likely at this stage, but the data sensitivity warrants formal security management practices.

Evidence: https://www.numero.ai, https://app.numero.ai/privacy

FEC — Compliant

FEC compliance is the single most critical regulatory requirement for Numero AI given its core business. The company processes political contributions, manages donor databases, and operates contribution forms for federal campaigns subject to FEC jurisdiction. Non-compliance with FEC requirements — including proper disclosure of donor information (name, address, occupation, employer), contribution limits, and reporting obligations — could expose Numero's campaign clients to significant legal and financial penalties, and could expose Numero itself to regulatory scrutiny. The risk level is High not because Numero appears non-compliant, but because the consequences of any FEC compliance failure in this sector are severe and the regulatory scrutiny of political campaign technology is intense. The company explicitly claims FEC compliance and has built FEC-required data capture into its contribution forms.

Evidence: https://www.numero.ai, https://app.numero.ai/privacy, https://www.fec.gov

CPRA — Assessment Required

Numero AI is incorporated and headquartered in Costa Mesa, California (695 Town Center Drive, Suite 1100, Costa Mesa, CA 92626). As a California-based business, CCPA/CPRA applicability depends on whether Numero meets the statutory thresholds: (1) annual gross revenues exceeding $25 million; (2) annually buys, sells, or shares personal information of 100,000+ consumers or households; or (3) derives 50%+ of annual revenues from selling or sharing consumers' personal information. Given that Numero serves 1,000+ campaigns with 8,000+ staff and processes donor databases containing millions of US donor records (the website references '206 million donors in America' and '100 million 1-click donors'), it is plausible that Numero processes personal information of 100,000+ consumers annually, which would trigger CCPA/CPRA. However, there is an important nuance: CCPA/CPRA exempts certain political activities and voter/donor data may have specific treatment. The risk is Medium because the threshold applicability is uncertain without revenue and data volume figures, and because political data has complex CCPA treatment.

Evidence: https://app.numero.ai/privacy, https://www.numero.ai, https://cppa.ca.gov

Financials

Three-year financials

Financial Resilience Score: 5/10

Numero is a small, private, US-only political-fundraising SaaS company with no publicly disclosed financial statements. The company is not an SEC registrant and does not publish revenue, EBIT, or equity figures. Available directional data includes a flat-rate pricing model ($1,080/month), a customer base of 1,000+ campaigns historically, and cumulative client-raised donations exceeding $2B. Applied to lifetime customers, this implies an order-of-magnitude ARR in the low-to-mid seven figures at most. Qualitatively, Numero benefits from a sticky vertical SaaS product with deep workflow integration, referenceable high-profile clients (Polis, Schiff, Kim, Aguilar, McBath campaigns), a lean 17-person cost base, and recurring subscription revenue. However, the company faces significant structural risks: extreme concentration on a single US political party (Democrats), biennial election-cycle seasonality creating cash-flow volatility, competition from the dominant incumbent NGP VAN (backed by PE roll-up Bonterra), and limited scale/cash reserves as a small private company with no disclosed funding rounds. Given the lack of disclosure and combination of niche strengths with structural single-vertical, single-party, single-geography risks, the resilience score is middling. The company appears operationally viable but structurally fragile relative to larger, more diversified competitors.

Key strengths: Sticky vertical SaaS product with high switching costs, Flat-rate pricing model ($1,080/month) with clear unit economics, Referenceable high-profile Democratic campaign clients, Lean 17-person, US-based operating footprint, Recurring subscription revenue model, Cumulative client fundraising exceeding $2B across 1,000+ campaigns

Risk factors: Extreme customer concentration on Democratic Party (halves addressable market), Biennial election-cycle seasonality creating revenue volatility, Small scale with limited disclosed cash reserves, Competitive pressure from dominant incumbent NGP VAN (Bonterra/Apax-backed), Regulatory exposure to FEC and state campaign-finance rule changes, Single-vertical, single-geography (100% US, 100% political) with no diversification, Key-person risk on founder-CEO, No public financial disclosure limits transparency

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report