Permido A/S
Denmark · owned by Independent (Denmark) · www.permido.com · 25 vendors
Permido A/S offers an AI-powered platform for secure email and digital mail, integrating with Outlook and e-Boks. It provides zero-touch encryption, intelligent data classification, and ensures compliance with regulations like GDPR and NIS2 for businesses and the public sector. The company's solutions aim to simplify secure communication and data handling.
Resilience scores
- Digital Sovereignty: 16
- Digital Resilience: 7
- Financial Resilience: 9
Technology vendors
- jQuery Foundation — Technology — United States
- Lenis — Technology — France
- Netlify, Inc. — Technology — United States
- and 22 more
Services catalogue
1 service in catalogue across 1 category; runs on 25 sub-vendors.
- Permido Secure Email
Insights
Last updated 2026-03-12 · revision 3
25 direct vendors, 232 subvendors
Direct vendors by controlling owner country (sample)
- Bangladesh: 1
- Israel: 1
- Germany: 1
Subvendors by controlling owner country (sample)
- Czech Republic: 1
- Denmark: 4
- Canada: 8
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Permido A/S exhibits a medium level of migration readiness, scoring 45. The primary challenge stems from its current infrastructure setup, which involves "Servers hosted in Denmark" and "Servers hosted in the Netherlands" (own/co-located data center infrastructure). This indicates a traditional, non-cloud-native deployment model, implying that a migration to a public cloud environment would likely require a significant lift-and-shift or re-platforming effort, rather than a straightforward cloud-native transition. There is no mention of containerization or microservices, which are common indicators of high migration readiness. The company's strong focus on "GDPR compliance automation" and "NIS2 compliance automation" is a double-edged sword; while positive for regulatory adherence, these regulations often impose strict data residency and security requirements. Although "Data Residency Requirements: Not specified", it is highly probable given their handling of sensitive email data and integration with Danish public-sector digital post (CPR and CVR validation), which could significantly complicate cloud migration choices and architectures. Furthermore, there is no data available on the company's financial stability or growth history, making it impossible to assess its capacity to fund a potentially complex migration. Regarding vendor relationships, while "Total Vendors: 0" is stated, the presence of "49 services" from vendors across "8 unique countries" suggests a reliance on external services. The unknown "Vendor Lock-in Risk" and the lack of clarity on the number of unique vendors providing these services could introduce complexity in migrating these dependencies. On the positive side, the company's core products feature modern technologies like AI-driven classification and end-to-end encryption, suggesting a potentially adaptable codebase. Its deep integration with "Microsoft 365 / Exchange" could also simplify migration efforts if targeting the Microsoft Azure cloud ecosystem, though their current server hosting indicates they haven't fully leveraged this for their core infrastructure.
Compliance
4 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for cybersecurity companies as it demonstrates information security management system maturity. Many enterprise customers expect security service providers to have ISO 27001 certification. Risk is medium because while not legally mandated, lack of ISO 27001 could impact competitive positioning and customer trust, especially for a company positioning itself as a security leader ('En af Nordens sikreste og mest innovative løsninger').
GDPR (source) — Compliant
Company is headquartered in Denmark (EU member state) and processes personal data as part of their email encryption services. They have implemented comprehensive GDPR compliance measures including privacy policy, data retention policies (6 months for user data, 3 months for emails), and explicit GDPR compliance statements on their website. As a cybersecurity company serving EU clients, they have strong incentives to maintain compliance. Risk is low due to their business model being built around data protection and their explicit compliance statements.
Evidence: https://permido.dk/privatlivspolitik/, https://permido.dk/
SOC 2 (source) — Assessment Required
As a cloud-based email encryption service provider, SOC2 compliance would be highly relevant for demonstrating security controls to enterprise customers. Many B2B SaaS companies pursue SOC2 to meet customer requirements. However, SOC2 is voluntary and primarily driven by US market demands. Risk is medium because while not legally required, lack of SOC2 could limit business opportunities with enterprise customers, especially US-based ones.
Financials
Three-year financials
- 2022: revenue 25,000,000 DKK, EBIT 3,500,000 DKK, equity 12,000,000 DKK
- 2021: revenue 22,000,000 DKK, EBIT 2,800,000 DKK, equity 10,000,000 DKK
- 2020: revenue 19,000,000 DKK, EBIT 2,000,000 DKK, equity 8,500,000 DKK
Financial Resilience Score: 9/10
Permido A/S exhibits strong financial resilience based on the available data: Consistent Revenue Growth: The company has demonstrated robust year-over-year revenue growth (15.79% in 2021 and 13.64% in 2022). This indicates a healthy demand for its services and an ability to expand its customer base, which is crucial for long-term stability. Strong Profitability: Operating income has grown significantly, even outpacing revenue growth in some periods (e.g., 40% EBIT growth vs. 15.79% revenue growth in 2021). This suggests effective cost management and a scalable business model, leading to improved margins. Strengthening Equity Base: The consistent increase in equity (17.65% in 2021 and 20.00% in 2022) indicates that the company is retaining earnings and building a solid financial foundation. A higher equity base provides a buffer against unforeseen economic downturns and supports future investments without excessive reliance on debt. Nature of Business: Operating in the secure digital communication and compliance sector, Permido A/S benefits from ongoing regulatory requirements (like GDPR) and increasing cybersecurity threats, creating a resilient demand for its core offerings. This market is generally less cyclical than others. Cash Flow (Inferred): While explicit cash flow data is not provided here, strong and growing operating income typically correlates with healthy operating cash flows, which are vital for liquidity and self-funding growth. The company's consistent growth in both top-line and bottom-line figures, coupled with a strengthening balance sheet, positions it well to withstand economic fluctuations and pursue strategic opportunities.
Key strengths: Consistent Revenue Growth, Strong Profitability, Strengthening Equity Base, Nature of Business (Secure Digital Communication/Compliance), Cash Flow (Inferred from Operating Income)
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.