PLAID, Inc.
Japan · plaid.co.jp · 17 vendors
PLAID, Inc. is a Japanese company that develops and operates the customer experience (CX) platform KARTE. This platform enables businesses to collect and analyze user behavior data from websites and smartphone applications, facilitating personalized communication and marketing through real-time analytics, multi-channel campaigns, and targeted ad delivery. The company's mission is to maximize the value of people with the power of data.
Resilience scores
- Digital Sovereignty: 12
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Anthropic, PBC — Technology — United States
- Netlify, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 15 more
Services catalogue
5 services in catalogue across 3 categories; runs on 17 sub-vendors.
- ACH verification
- Personal Data Processing
- Crowdfunding platform integration
Insights
Last updated 2026-06-24 · revision 2
17 direct vendors, 216 subvendors
Direct vendors by controlling owner country (sample)
- United States: 15
- Japan: 2
Subvendors by controlling owner country (sample)
- India: 1
- Norway: 3
- Poland: 1
Migration Readiness: 10/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
PLAID exhibits exceptionally high migration readiness, primarily driven by its cutting-edge, cloud-native, and containerized technology stack. The extensive use of Google Cloud Platform (GCP), Amazon Web Services (AWS), Google Kubernetes Engine (GKE), Kubernetes, and Docker signifies a highly portable and flexible infrastructure. Their existing multi-cloud environment demonstrates proficiency in managing diverse cloud platforms, which greatly simplifies any future migration efforts or shifts between cloud services. The company's focus on distributed systems, data engineering, and the development of internal platforms like "KARTE Craft" (PaaS) and "Craft Cross CMS" (AI-native headless CMS) further enhances their agility and reduces dependency on monolithic, difficult-to-move systems. The absence of specified data residency requirements removes a common and complex hurdle for cloud migrations. While the "Total Vendors: 0" data point is ambiguous, the fact that they utilize 19 services from vendors with headquarters in two different countries (United States and Japan), combined with their highly flexible internal tech stack, suggests a low risk of vendor lock-in that would impede migration. The lack of financial stability data prevents an assessment of funding capacity for large migrations, and regulatory environment details are missing, but these are minor considerations given the overwhelming technical strengths. PLAID's architecture is ideally suited for seamless migration and adaptation.
Compliance
9 in-scope frameworks identified; showing 3.
Japan Telecommunications Business Act — Partially Compliant
The 2023 amendments to Japan's Telecommunications Business Act introduced new rules on 'external transmission' (外部送信) of user information by website operators using third-party analytics and advertising tools. PLAID, Inc. explicitly references these rules in its privacy policy and provides a detailed disclosure table of all third-party tools used on its website (Google Analytics, LinkedIn Insight, Facebook Ads, Microsoft Advertising, etc.) and the information transmitted. This demonstrates awareness and partial compliance. However, as the operator of the KARTE platform — which itself is a tool used by other website operators for behavioral analytics — PLAID may also have obligations as a 'specified telecommunications service provider' under the Act. Risk is Medium because the regulatory framework is relatively new (2023), enforcement is evolving, and PLAID's dual role as both a website operator and a provider of analytics tools creates complex obligations.
Evidence: https://plaid.co.jp/privacy/, https://www.soumu.go.jp/main_sosiki/joho_tsusin/d_syohi/gaibusoushin_kiritsu.html
ISO 27001 (source) — Compliant
PLAID, Inc. has publicly confirmed ISO/IEC 27001 certification on its official company overview page and displays the certification badge on its website. ISO 27001 is an internationally recognized standard for information security management systems (ISMS). Certification requires a third-party audit by an accredited certification body and demonstrates that PLAID has implemented a systematic approach to managing sensitive information. The risk is Low because: (1) certification is confirmed from official sources; (2) the company also holds ISO/IEC 27017 (cloud security controls), indicating a comprehensive security posture; (3) the Information Security Policy (情報セキュリティ基本方針) published on the website aligns with ISO 27001 requirements including risk assessment, incident management, and continuous improvement.
Evidence: https://plaid.co.jp/company/overview/, https://plaid.co.jp/privacy/security/, https://plaid.co.jp/
GDPR (source) — Assessment Required
PLAID, Inc. is headquartered in Japan with no confirmed EU/EEA offices or subsidiaries identified. However, GDPR applicability cannot be ruled out because: (1) KARTE is a CX/analytics SaaS platform that could be used by clients who serve EU/EEA residents, meaning PLAID may act as a data processor under GDPR Article 28; (2) PLAID's website uses tools such as LinkedIn Insight, Google Analytics, Microsoft Advertising, and Facebook Ads — some of which may collect data from EU visitors; (3) PLAID's enterprise clients may include companies operating in the EU. If PLAID processes personal data of EU/EEA residents (even indirectly as a processor), GDPR applies. The risk is Medium because there is no confirmed EU establishment, but the nature of the KARTE platform (web analytics and behavioral data processing at scale) creates a plausible pathway for GDPR applicability. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://plaid.co.jp/privacy/, https://plaid.co.jp/company/overview/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
PLAID, Inc. demonstrates moderate financial resilience characteristic of a growth-stage Japanese SaaS company. The company achieved a significant milestone in October 2024 by crossing ¥10 billion in total Group ARR, indicating meaningful scale and recurring revenue visibility from its KARTE CX platform. The subscription-based business model provides revenue predictability, and the company benefits from a diversified product portfolio spanning KARTE Datahub, Blocks, Signals, Message, Craft, RightSupport, and newer AI-native products like KARTE AI and Context Lake. Strategic partnerships with Google, Mitsui & Co., and Hakuhodo DY ONE add credibility and distribution leverage. Paid-in capital of ¥2.67 billion provides a reasonable equity base. However, the company has historically prioritized growth over profitability, which is typical of post-IPO Japanese SaaS firms, and exact margin trends could not be verified in this session. The aggressive M&A strategy (EmotionTech, RightTouch, Agito, CODATUM, CloudFit) creates integration risk and likely increases goodwill/intangibles on the balance sheet. Domestic concentration (~100% Japan) limits diversification and exposes the company to local market cycles. Competition from global CDP/CX vendors (Adobe, Salesforce, Treasure Data, Braze) is intensifying, and the pivot to AI-native products represents both the primary growth opportunity and a key execution risk.
Key strengths: Recurring SaaS revenue model with Group ARR exceeding ¥10 billion as of October 2024, Diversified CX product portfolio including KARTE, Datahub, Blocks, Signals, Message, Craft, and AI products, Strategic partnerships with Google, Mitsui & Co., and Hakuhodo DY ONE, Active M&A-driven growth strategy expanding capabilities (EmotionTech, RightTouch, Agito, CODATUM, CloudFit), Listed company governance on TSE Growth Market since December 2020 with audited disclosures, Strong technical certifications (ISO/IEC 27001, ISO/IEC 27017, PrivacyMark), Paid-in capital of ¥2.67 billion providing equity base
Risk factors: History of operating losses and thin profitability typical of growth-stage SaaS, Heavy domestic concentration with essentially 100% Japan revenue exposure, Customer concentration in Japanese e-commerce, retail, and financial services sectors, M&A activity increases goodwill/intangibles and creates integration risk, Intense competition from global CDP/CX vendors (Adobe, Salesforce, Treasure Data, Braze), Execution risk on AI-native product pivot (KARTE AI, Context Lake, PLAID ALPHA), Sensitivity to consumer-spending and ad-budget cycles
Revenue by geography
- Japan: 100%
Revenue by product/service
- KARTE SaaS (Recurring/Subscription): 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.