PheedLoop Inc.
Canada · pheedloop.com · 16 vendors
Resilience scores
- Digital Sovereignty: 6
- Digital Resilience: 5
- Financial Resilience: 6
Technology vendors
- HubSpot, Inc. — Technology — United States
- Mailendo — Media & Marketing — Poland
- Meta Platforms, Inc. — Technology — United States
- and 13 more
Services catalogue
1 service in catalogue across 1 category; runs on 16 sub-vendors.
- PheedLoop
Insights
Last updated 2026-08-14 · revision 1
16 direct vendors, 228 subvendors
Direct vendors by controlling owner country (sample)
- Canada: 1
- United States: 12
- Denmark: 1
Subvendors by controlling owner country (sample)
- Ireland: 3
- Canada: 7
- Hong Kong: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
PheedLoop Inc. exhibits a medium to high level of migration readiness (Score: 65). This is largely driven by its existing adoption of a modern internal tech stack, particularly its use of AWS, which indicates a foundational cloud presence. The implementation of a REST API architecture further suggests a modular and decoupled system, which is generally more amenable to migration and modernization efforts compared to monolithic legacy systems. The company's use of various external services like Zapier and Stripe also points towards an architecture that can integrate with external components. However, several critical data points are missing, which introduce uncertainty and limit a higher readiness score. There is no information available on financial stability (revenue concentration, growth history), which is crucial for assessing the company's capacity to fund a significant migration. Similarly, the absence of data on regulatory environment and data residency requirements means potential compliance complexities that could impact migration planning are unknown. While "Vendor Geographic Diversity" is noted across four countries, the "Vendor Lock-in Risk" is explicitly unknown. This is a significant gap, as high vendor lock-in could complicate or impede migration efforts, especially if moving away from specific proprietary services. The contradictory "Total Vendors: 0" data point, despite the listed tech stack, makes a precise assessment of vendor-related migration challenges difficult. Overall, while the technical foundation is strong for migration, the lack of comprehensive financial, regulatory, and vendor lock-in data necessitates a cautious assessment.
Compliance
9 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is the international standard for information security management systems (ISMS). It is highly relevant for SaaS companies like PheedLoop that process personal data for thousands of organizations globally. No ISO 27001 certification has been publicly disclosed. Risk is MEDIUM because: (1) ISO 27001 is not legally mandated in Canada but is a strong market expectation for enterprise SaaS vendors; (2) Government clients (Government of Canada, NASA, Global Affairs Canada) typically require vendors to demonstrate robust information security practices, often via ISO 27001 or equivalent; (3) Absence of certification may create competitive disadvantage and procurement barriers with security-conscious clients; (4) The company's Terms of Use state data is hosted in the US, making security assurance documentation more critical.
Evidence: https://pheedloop.com/more/privacy, https://pheedloop.com/customers/government
WCAG 2.1 — Partially Compliant
PheedLoop explicitly claims WCAG 2.1 AA and ADA compliance on its government customer page, stating 'Provide the highest level of accessibility with our built-in accessibility widget - WCAG 2.1 AA and ADA compliant.' This is a positive indicator. Risk is LOW because: (1) The claim is self-declared without third-party audit evidence; (2) WCAG 2.1 AA is the standard required for US federal government contractors (Section 508) and many Canadian government procurements (AODA in Ontario); (3) PheedLoop serves government clients who require accessibility compliance; (4) Self-declared compliance without VPAT (Voluntary Product Accessibility Template) or third-party audit creates some residual risk.
Evidence: https://pheedloop.com/customers/government, https://pheedloop.com/products/languages-and-accessibility
PCI DSS (source) — Partially Compliant
PheedLoop explicitly states in its Privacy Policy that it does not collect, store, process, or transmit payment card details, and that all payment processing is handled by a PCI DSS Level 1-certified third-party payment processor. This significantly reduces PheedLoop's PCI DSS scope. Risk is LOW because: (1) PheedLoop has appropriately outsourced payment processing to a PCI DSS Level 1 certified processor; (2) PheedLoop only receives non-sensitive transaction identifiers (transaction ID, payment intent ID); (3) This architecture (direct browser-to-processor transmission) is a recognized PCI DSS scope reduction method; (4) However, PheedLoop should maintain a SAQ (Self-Assessment Questionnaire) to document its reduced PCI DSS scope.
Evidence: https://pheedloop.com/more/privacy, https://pheedloop.com/more/terms
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
PheedLoop Inc. is a privately held Canadian event-technology SaaS company with a decade of continuous operations since 2015. As a private corporation, no audited financial statements, revenue figures, EBIT, or equity data are publicly available, which limits any quantitative counterparty or credit analysis. However, qualitative indicators point to a resilient business: long operating history, a diversified and reputable customer base including NASA, Microsoft, IBM, Deloitte, Scotiabank, Shopify, and multiple Canadian government agencies, cumulative scale of 20,000+ events powered and ~6 million attendees reached, and a broad product suite spanning registration, mobile apps, on-site badging, and virtual/hybrid events. The company demonstrated significant operational adaptability during the COVID-19 pandemic by pivoting from on-site events to virtual/hybrid in 2020, then back to on-site solutions. It appears to be bootstrapped/founder-owned with no publicly disclosed venture funding, meaning resilience depends entirely on cash flow rather than a capital reserve. Key risks include cyclical exposure to live events, intense competition from well-funded players like Cvent, Bizzabo, and Eventbrite, potential pricing pressure in the SMB/mid-market segment, and complete opacity of financials. Overall, qualitative signals suggest a moderately resilient business, but the lack of financial disclosure prevents a higher confidence score.
Key strengths: Decade-long operating history since 2015, Blue-chip and diversified customer base (NASA, Microsoft, IBM, Deloitte, Scotiabank, Shopify, Government of Canada agencies), Cumulative scale: 20,000+ events, 3,000+ event planners, ~6 million attendees, Broad product suite reducing single-product concentration risk, Demonstrated pandemic pivot from on-site to virtual/hybrid and back, Strong customer reviews (4.8/5 on G2 with 300+ reviews), Sticky public-sector and association contracts, Bootstrapped/founder-owned structure suggests disciplined operations
Risk factors: Cyclical exposure to live events and corporate travel budgets, Highly competitive market with well-funded players (Cvent, Bizzabo, Hopin, Eventbrite), No disclosed external capital or funding war chest, SMB/mid-market focus may limit ARPU vs enterprise-focused peers, Complete opacity of financial disclosure limits counterparty assessment, Potential pricing pressure in competitive SaaS event-tech market
Revenue by geography
- North America: 90%
- Other International: 10%
Workforce by country
- Canada: 75
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.