OODALOOP Technologies ApS

Denmark · owned by !JUST Capital ApS (Denmark) · OODALOOP.eu · 6 vendors

OODALOOP Technologies ApS is a Nordic defence tech company developing and mass-producing pilot-assisted, expendable drone systems for the defence of Europe. Their OODA Drone Systems are cost-optimized, modular platforms covering offensive (strike), defensive (C-UAS interceptor), and training operations. The company holds a NATO NCAGE code (R01D0) and is based in Denmark.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 1

6 direct vendors, 81 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

OODALOOP Technologies ApS demonstrates low to medium migration readiness, largely due to critical unknowns regarding its core technology stack and financial capacity. The most significant challenge is the lack of information on the architecture of their core drone systems (e.g., cloud-native, containerization, microservices), making it impossible to assess the complexity and feasibility of migrating these critical components. The absence of data on revenue concentration and growth history also hinders the assessment of their financial ability to fund a potentially extensive migration project. Furthermore, the vendor lock-in risk is explicitly stated as 'Unknown,' which is a major impediment to planning a smooth migration, despite the moderate geographic diversity of their vendor base (United States, Israel). While 'Data Residency Requirements' are 'Not specified,' which could offer some flexibility in cloud region selection, it also suggests a potential lack of prior strategic consideration for data governance in a cloud environment. The website's tech stack (Wix) is a managed platform, and its migration would be a platform-specific task rather than an infrastructure migration, offering little insight into the readiness of their core operational systems.

Compliance

11 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SOC 2 is not a legal requirement but is increasingly expected by enterprise and government customers, particularly in the defence sector. OODALOOP Technologies ApS develops drone systems with autonomous capabilities, likely involving cloud-based ground control systems, data telemetry, and software platforms. If the company provides software-as-a-service components or cloud-connected systems to defence customers, SOC 2 Type II certification may be contractually required by NATO member state defence ministries or prime contractors. Risk is MEDIUM because: (1) defence customers increasingly mandate SOC 2 or equivalent assurance; (2) no SOC 2 certification was found; (3) as a startup, formal SOC 2 readiness programs may not yet be in place; (4) the autonomous/AI nature of the drone systems implies significant data processing that customers may want independently assured.

Evidence: https://www.oodaloop.eu, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

Danish Security Clearance Requirements — Assessment Required

Risk is HIGH because OODALOOP Technologies ApS explicitly requires employees to obtain security clearances from the Danish Defense Intelligence Service (Forsvarets Efterretningstjeneste / FE). This indicates the company handles classified information and is subject to Danish national security regulations. Key risk factors: (1) handling classified NATO/EU information requires facility security clearances (FSC) in addition to personnel security clearances (PSC); (2) the company's NATO NCAGE code (R01D0) confirms defence supply chain integration where classified information handling is likely; (3) non-compliance with security clearance requirements can result in loss of defence contracts and criminal prosecution; (4) the requirement that employees' full households must have resided in NATO/EU countries for 7 years indicates NATO SECRET or higher classification levels may be involved.

Evidence: https://www.oodaloop.eu/unsolicitedapplication, https://www.fe-ddis.dk/en/, https://www.retsinformation.dk/eli/lta/2013/976

ISO 27001 (source) — Assessment Required

ISO 27001 certification is critically important for OODALOOP Technologies ApS given its defence sector context. Risk is HIGH because: (1) the company holds a NATO NCAGE code (R01D0), indicating participation in NATO supply chains where ISO 27001 or equivalent ISMS is frequently mandated; (2) Danish and NATO defence procurement standards typically require suppliers to demonstrate information security management maturity; (3) the company processes sensitive defence-related data, R&D intellectual property for autonomous weapons systems, and security-cleared employee data; (4) no ISO 27001 certification was found publicly; (5) a cybersecurity incident affecting drone system software or design data could have national security implications; (6) EU defence procurement frameworks increasingly require ISO 27001 as a baseline.

Evidence: https://www.oodaloop.eu, https://www.iso.org/standard/27001, https://www.ds.dk/en/standards/iso-27001

Financials

Three-year financials

Financial Resilience Score: 4/10

OODALOOP Technologies ApS is an early-stage Danish defence-tech company (CVR 45601021, likely incorporated in 2024) with no publicly available financial statements yet. As a private ApS, it will file abbreviated accounts under Danish accounting class B, which typically omit revenue disclosure. The company is well-positioned in a strong tailwind sector—European defence spending is expanding rapidly post-2022, with drone and counter-UAS capabilities being top procurement priorities for NATO members and Ukraine-support programs. Strategic strengths include a modular product portfolio spanning offensive (FPV/wing strike), defensive (C-UAS interceptor), and training drones, all sharing a common Ground Control Station platform. NCAGE registration (R01D0) enables NATO/government contract bidding, and the Nordic sovereignty narrative aligns with EU/EDF priorities. An asset-light reseller distribution model reduces early-stage working capital burn. However, significant risks weigh on resilience: as a newly formed ApS, capitalization is likely thin with dependence on venture funding or grants; no public evidence of Series A/B rounds exists. Manufacturing scale-up from prototype to serial production is capital-intensive, and defence sales typically hinge on a small number of MoD contracts creating concentration risk. The European expendable-drone segment is crowded with competitors including Helsing/Tekever, Nordic Air Defence, Skyeton, Quantum Systems, Terma, and numerous Ukrainian OEMs. Export-control regulation and supply-chain re-sourcing (away from Chinese components) add further cost and execution risk.

Key strengths: Strong European defence spending tailwind post-2022, Modular product portfolio across strike, C-UAS, and training drones, NATO NCAGE code (R01D0) enabling government contract bidding, Nordic sovereignty positioning aligned with EU/EDF priorities, Asset-light reseller-based go-to-market model, Presence in Odense, Denmark's national drone hub

Risk factors: Early-stage thin capitalization with likely limited equity buffer, Manufacturing scale-up execution risk from prototype to serial production, Customer concentration risk on small number of MoD contracts, Dual-use export-control and regulatory risk, Intense competition from European and Ukrainian drone OEMs, Supply chain dependence on components historically sourced from China, No public funding rounds or contract wins disclosed

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report