Paylike

Denmark · owned by Lunar Group A/S (Denmark) · paylike.io · 13 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 13 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

13 direct vendors, 227 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Paylike exhibits high migration readiness, primarily driven by its modern and cloud-native oriented tech stack. The use of Node.js, JavaScript, Docker, and AWS indicates existing adoption of containerization and cloud infrastructure, which are key enablers for seamless migration and microservices architecture. The reliance on REST APIs suggests a modular system design, facilitating component-based migration. Additionally, the availability of Open Source SDKs can simplify integration during migration processes. Despite these strengths, critical information regarding the regulatory environment and data residency requirements is missing. For a payment company, these factors can significantly impact migration strategy, compliance efforts, and potential costs. Financial stability data is also absent, making it difficult to assess their capacity to fund a potentially complex migration. The 'Vendor Lock-in Risk' is unknown, and the contradictory data point of 'Total Vendors: 0' versus the presence of AWS in the tech stack and listed vendor geographic diversity creates ambiguity. While the listed vendor geographic diversity (6 countries for 13 services) suggests they are not overly concentrated with a single vendor, the exact number of distinct vendors and the nature of their contracts are unclear. Despite these unknowns, Paylike's strong technical foundation with existing cloud and containerization adoption positions it with high migration readiness.

Compliance

11 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SOC 2 is an auditing framework developed by the AICPA applicable to service organizations that store, process, or transmit customer data in the cloud. Paylike, as a cloud-based payment processing platform providing services to merchants, is a strong candidate for SOC 2 compliance — particularly as enterprise merchants and B2B customers increasingly require SOC 2 Type II reports as part of vendor due diligence. Risk is Medium because: (1) SOC 2 is not legally mandated but is a strong market expectation for payment technology providers, (2) Absence of SOC 2 certification may limit enterprise customer acquisition, (3) The underlying security controls required for SOC 2 overlap significantly with PCI DSS and DORA requirements, suggesting some control framework is in place, (4) Without a SOC 2 report, customers cannot independently verify security controls. Risk is not High because SOC 2 non-compliance does not carry regulatory fines.

Evidence: https://paylike.io, https://www.lunar.app/en/personal, https://www.aicpa-cima.com/resources/landing/soc-2

AML — Assessment Required

AML/CFT compliance is a core regulatory obligation for any EU payment service provider and bank. Paylike, as a payment acquirer processing merchant transactions, and Lunar Bank A/S, as a licensed bank, are both obliged entities under the EU AML Directives (AMLD4, AMLD5, AMLD6) and Danish AML legislation (Hvidvaskloven). The financial sector is the primary target of AML enforcement. Risk is High because: (1) Payment processors are high-risk for money laundering due to transaction volumes and merchant diversity, (2) Denmark's AML supervisory authority (Finanstilsynet and Hvidvasksekretariatet) actively enforces compliance, (3) Denmark has faced EU scrutiny over AML enforcement effectiveness, (4) Non-compliance can result in criminal prosecution, license revocation, and substantial fines, (5) The upcoming EU AML Authority (AMLA) will add a new layer of direct supervision for high-risk financial entities from 2025/2026.

Evidence: https://www.lunar.app/en/personal, https://www.finanstilsynet.dk/en/Supervision/Anti-money-laundering, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32015L0849, https://www.retsinformation.dk/eli/lta/2017/651

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS). For a payment service provider and bank processing sensitive financial and personal data, ISO 27001 certification is a strong market expectation and increasingly a regulatory expectation (referenced in DORA and NIS2 as a recognized framework). Risk is Medium because: (1) ISO 27001 is not legally mandated but is expected by enterprise customers, regulators, and partners, (2) Absence of certification may indicate weaker information security governance, (3) The controls required for ISO 27001 overlap with PCI DSS, DORA, and NIS2 requirements, (4) Danish financial regulators increasingly reference ISO 27001 as a benchmark for ICT risk management. Risk is not High because ISO 27001 non-certification does not carry direct regulatory penalties, though it may indicate gaps in security controls that could lead to other regulatory violations.

Evidence: https://paylike.io, https://www.lunar.app/en/personal, https://www.iso.org/isoiec-27001-information-security.html, https://www.ds.dk/en

Financials

Three-year financials

Financial Resilience Score: 4/10

Paylike is a small Danish payment gateway ApS that appears to have been acquired by Lunar Group A/S around 2022, with its domain now redirecting to Lunar's website. As an independent entity, Paylike historically filed only abbreviated årsrapporter with limited disclosure typical of small Danish ApS companies. No specific financial figures for revenue, EBIT, or equity could be verified in this research session. On the positive side, being absorbed into a licensed Danish bank (Lunar Bank A/S, supervised by Finanstilsynet with EU passporting rights) meaningfully strengthens regulatory standing and balance sheet backing. Paylike had product-market fit in the growing European online card payments market with transparent pricing that differentiated it from larger competitors, and access to Lunar's ~1 million user base creates cross-sell opportunities. However, significant risks weigh on resilience: Lunar Group has reported group-level losses of several hundred million DKK per year in 2021-2023 per Danish media, meaning Paylike is now exposed to parent-level cash burn. The company faces scale disadvantages against well-capitalized global PSPs (Stripe, Adyen, Mollie, Nexi), regulatory/interchange fee compression in the EU, customer concentration in small e-commerce merchants sensitive to macro downturns, and integration/brand risk as the Paylike brand appears to be sunsetting.

Key strengths: Acquired by Lunar Group A/S (licensed Danish bank) providing regulatory strength and balance sheet backing, Product-market fit in growing European online card payments market, Transparent per-transaction pricing differentiator vs. Stripe/Adyen for SMBs, Access to Lunar's ~1 million user base for cross-sell opportunities, EU passporting via Lunar Bank A/S regulated status

Risk factors: Parent Lunar Group reporting losses of several hundred million DKK per year (2021-2023), Scale disadvantage vs. Stripe, Adyen, Mollie, Nets/Nexi, EU regulatory and interchange fee compression affecting gateway economics, Customer concentration in small e-commerce merchants sensitive to consumer downturns, Brand sunset risk - paylike.io domain now redirects to lunar.app, potentially causing merchant churn, Historically small independent ApS with limited capitalization pre-acquisition

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report