One.com Group AB
Denmark · owned by Oakley Capital (United Kingdom) · www.one.com · 12 vendors
One.com is a European web hosting and domain registration company headquartered in Copenhagen, Denmark. It provides services including domain registration, web hosting, website building tools, business email, SSL certificates, and WordPress hosting. The company serves millions of customers across Europe, with a strong presence in Denmark, Norway, Sweden, Finland, Germany, and other markets.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 6
- Financial Resilience: 4
Disruption prediction
One.com Group AB has an estimated 13% probability of disruption in the next 6 months.
10 of One.com Group AB's 12 vendors monitored for disruptions.
Technology vendors
- Google LLC — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- Netlify, Inc. — Technology — United States
- and 13 more
Services catalogue
19 services in catalogue across 5 categories; runs on 12 sub-vendors.
- and Email
- One.com Hosting
- MailAnyone
Insights
Last updated 2026-09-16 · revision 3
12 direct vendors, 229 subvendors
Direct vendors by controlling owner country (sample)
- United States: 10
- Australia: 1
- Sweden: 1
Subvendors by controlling owner country (sample)
- Canada: 4
- Taiwan: 1
- Denmark: 6
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
One.com Group AB exhibits medium migration readiness. Strengths include a strong financial position to fund migration efforts. The tech stack incorporates modern components like Next.js, React, AI/ML, and mentions 'Cloud Hosting Infrastructure' and a proprietary 'Cloud CDN,' suggesting existing cloud adoption and capabilities. A robust regulatory compliance framework (GDPR, ISO 27001, NIS2) is already in place, which, while adding constraints, means established processes for data governance. The most significant challenge is the strict data residency requirement, with all data centers in Denmark and data processing within the EU/EEA. This severely limits flexibility in choosing cloud providers and regions for migration, potentially increasing complexity and costs. While the tech stack has modern elements, the underlying PHP/Linux infrastructure for web hosting might require substantial refactoring for a fully cloud-native, microservices architecture. The numerous third-party integrations (e.g., Microsoft 365, SiteLock, Termly, SocialPilot) imply a complex vendor ecosystem, which could lead to integration challenges and potential lock-in risks during a migration, despite the stated 'Vendor Geographic Diversity: 4 unique countries.' The 'Total Vendors: 0' data point is inconsistent and makes a precise assessment of vendor lock-in difficult.
Compliance
4 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
As a cloud services provider offering hosting, VPS, and data storage services, SOC2 compliance would be highly beneficial for customer trust and competitive positioning. The medium risk reflects potential customer requirements for SOC2 attestation, especially for business customers storing sensitive data. Non-compliance could result in lost business opportunities and reduced customer confidence.
Evidence: https://www.one.com/en-gb/hosting/, https://www.one.com/en-gb/vps/
GDPR (source) — Compliant
One.com is headquartered in Denmark (EU) and processes extensive personal data including customer information, payment data, and website visitor data. While they have a comprehensive privacy policy demonstrating GDPR compliance efforts, the medium risk reflects the complexity of their data processing operations across multiple jurisdictions and the significant penalties for non-compliance (up to 4% of annual turnover). Their privacy policy shows proper legal bases, data subject rights, and international transfer safeguards.
Evidence: https://www.one.com/en-gb/legal/privacy/, https://www.one.com/en-gb/legal/terms/
ISO 27001 (source) — Assessment Required
As a technology company handling customer data and providing hosting services, ISO 27001 certification would demonstrate systematic information security management. The medium risk reflects the importance of information security in their business model and potential customer expectations, especially for enterprise clients. While not legally mandated, certification gaps could impact competitive positioning.
Financials
Three-year financials
- 2025: revenue SEK 367.1M, EBIT SEK -93.2M, equity SEK -70.3M
- 2024: revenue SEK 3712.9M, EBIT SEK -703.4M, equity SEK 848.0M
- 2023: revenue SEK 2764.3M, EBIT SEK -397.5M, equity SEK 2681.0M
Financial Resilience Score: 4/10
One.com Group AB presents a mixed financial resilience profile. On the positive side, the company operates a subscription-based, recurring-revenue business model in domains, web hosting, and SMB website tools with historically sticky customers. It is audited by Deloitte AB (a Big Four firm), and historical top-line growth was strong (74.7% in FY23 and 34.3% in FY24 on a consolidated basis). The group continues to expand via M&A, including the September 2025 acquisition of Veebimajutus.ee in Estonia. However, several significant concerns weigh on resilience. The consolidated group has posted persistent large net losses (−MSEK 916.5 in FY23, −MSEK 1,603.8 in FY24, −MSEK 150.9 in FY25) driven by heavy intangible amortisation and interest costs. Leverage has historically been very high, with long-term bank debt of MSEK 9,039 at 30-Sep-2024 supporting an acquisitive strategy. Equity ratio (soliditet) fell from 6.2% in FY24 to −6.0% in FY25. Additionally, the FY 2024/25 accounts reflect a major structural reorganisation where most operating subsidiaries appear to have been transferred out of the Swedish sub-consolidation, causing a 90% drop in revenue and a collapse in balance sheet total from MSEK 13,774 to MSEK 1,164. Prior years had compliance flags including a late filing, an internal control deficiency, and tax payment issues, all of which raise governance concerns.
Key strengths: Subscription-based recurring revenue model with sticky SMB customer base, Big Four auditor (Deloitte AB) providing governance credibility, Strong historical top-line growth (74.7% FY23, 34.3% FY24), Continued M&A expansion in CEE region (Veebimajutus.ee, Estonia), Portfolio of regional hosting brands across Europe
Risk factors: Persistent large net losses (−MSEK 1,603.8 in FY24, −MSEK 916.5 in FY23), Very high historical leverage (MSEK 9,039 long-term bank debt at FY24), Equity ratio turned negative (−6.0%) in FY25, Major structural reorganisation in FY25 obscures trend visibility, Historical compliance flags: late filing, internal control deficiency, tax payment issues, Heavy intangible amortisation burden (goodwill MSEK 5,696.7 at FY24), No dividend track record over past five years, No public segment split disclosed
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.