OpenUp

South Africa · openup.org.za · 13 vendors

OpenUp is a non-profit civic technology organization based in South Africa. It develops tools, liberates data, and offers data training to empower citizens and enhance collaboration between communities and governments. The organization's mission is to promote informed decision-making and drive social change through the strategic application of data and technology.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 13 sub-vendors.

Insights

Last updated 2026-08-11 · revision 4

13 direct vendors, 156 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

OpenUp exhibits high migration readiness, primarily driven by its modern and cloud-native oriented tech stack. The extensive use of Docker and Docker Compose indicates strong containerization practices, making applications highly portable across different environments. Existing cloud infrastructure (AWS, RDS, Netlify) and the adoption of open data standards and REST APIs further facilitate seamless migration to alternative cloud providers or self-hosted solutions. While the 'Total Vendors: 0' is an ambiguous data point, the presence of 17 services and vendor geographic diversity across 5 countries suggests a reasonable level of vendor flexibility rather than extreme lock-in, which would complicate migration. However, critical unknowns that could impact migration planning include specific regulatory compliance requirements, data residency requirements, and the company's financial stability to fund a potentially large migration project. The use of Heroku and Dokku, while offering platform benefits, might require some refactoring or adaptation if migrating away from these specific PaaS environments, though the underlying Docker usage significantly mitigates this challenge.

Compliance

8 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognised standard for information security management systems (ISMS). OpenUp processes government data, open civic data, and personal information of South African citizens on behalf of public entities. No ISO 27001 certification has been publicly disclosed. The risk is medium because: (1) OpenUp's government clients (National Treasury, SALGA, municipalities) may increasingly require ISO 27001 or equivalent security assurance from technology vendors; (2) OpenUp handles sensitive government financial and parliamentary data (Vulekamali, Municipal Money, PMG); (3) The absence of ISO 27001 certification may become a competitive disadvantage in government procurement; (4) South Africa's Cybersecurity Policy Framework and the Cybercrimes Act 19 of 2020 are increasing security expectations for technology organisations.

Evidence: https://cdn.prod.website-files.com/5d6298cd18659ff156042e30/61fcbf6092b74d161cf11249_2022_public_privacy_policy.pdf, https://openup.org.za/projects

GDPR (source) — Assessment Required

OpenUp is headquartered in South Africa (not EU/EEA) and its primary operations are South Africa-focused. However, GDPR applies extraterritorially to any organisation that processes personal data of EU/EEA residents, regardless of where the organisation is based (Article 3(2) GDPR). OpenUp's website is publicly accessible globally, its newsletter mailing list is open to international subscribers, its open data tools (Wazimap, Africa Data Hub) may be used by EU/EEA residents, and it uses international cloud infrastructure (Netlify CDN, Webflow, Google Analytics) that may process EU visitor data. The privacy policy references GDPR case law (Google v Spain, consent standards) suggesting awareness of GDPR principles. The risk is medium rather than high because: (1) OpenUp does not appear to target EU/EEA residents specifically; (2) it does not offer goods/services to EU residents as a primary market; (3) it does not monitor EU resident behaviour as a core activity. However, the use of Google Analytics on EU visitors without a GDPR-compliant consent mechanism could constitute a violation. Fines under GDPR can reach €20 million or 4% of global annual turnover.

Evidence: https://openup.org.za/cookie-policy, https://cdn.prod.website-files.com/5d6298cd18659ff156042e30/61fcbf6092b74d161cf11249_2022_public_privacy_policy.pdf

South Africa Electronic Communications and Transactions Act — Partially Compliant

ECTA governs electronic communications and transactions in South Africa, including requirements for websites to disclose certain information (Section 43), rules on electronic contracts, spam (Section 45), and data message authentication. OpenUp operates multiple websites and sends newsletters. The website discloses contact information, physical address, and organisational details consistent with Section 43 requirements. However, the cookie policy does not implement a full ECTA-compliant consent mechanism for electronic communications, and the newsletter subscription process should comply with Section 45 anti-spam provisions. The risk is medium because ECTA enforcement in South Africa has been limited but is increasing.

Evidence: https://openup.org.za/cookie-policy, https://openup.org.za

Financials

Three-year financials

Financial Resilience Score: 5/10

OpenUp is a small South African non-profit organisation with a limited financial disclosure profile. The only hard revenue number publicly disclosed is approximately ZAR 11.6M for FY2021-22, and no EBIT, equity, or reserves figures are made public. Since then, the organisation has experienced declining absolute income due to the sunset of major core grants (notably Luminate and OSF-SA), though the decline was less severe than planned (under 20% versus a projected 30%). Despite the contraction, OpenUp has demonstrated notable resilience by successfully pivoting its income mix from 74% grant-dependent (FY2022-23) to 86% client-funded (FY2024-25) — an unusually strong diversification outcome for a civic-tech NPO. The organisation maintains a lean cost base, remote-friendly operations, and a strategic focus on building cash reserves. However, its small absolute scale (~USD 700-800k in the last disclosed year), human-capital-heavy cost structure (94% of opex on people), client concentration in South African public sector, and exposure to a shrinking civic-tech philanthropy environment temper its overall resilience score.

Key strengths: Successful income diversification from 74% grants to 86% client-funded over three years, Managed loss of major grants with smaller-than-expected income drop (<20% vs planned 30%), Written multi-year funding strategy (2022-2024, 2025-2030) with decentralised business development, Low fixed-cost base with remote-friendly operations and minimal travel spend, Strong repeat client relationships with National Treasury, CoGTA, and municipalities, Open-source product portfolio reducing vendor lock-in risk, Stated strategic focus on building cash reserves for cash flow security

Risk factors: Small absolute scale (~ZAR 11.6M / USD 700-800k) limits shock absorption, Declining absolute revenue since FY2022-23 as core grants sunset, Volatile funder ecosystem with contracting civic-tech philanthropy in Africa, Human-capital-heavy cost base (94% of opex on people) limits variable-cost flexibility, Client concentration in South African public sector brings tender/procurement cyclicality and political risk, No published audited AFS limits third-party verification, Currency exposure with USD-denominated grants and ZAR-denominated costs, Global aid environment narrowing for African civic-tech organisations

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report