PlanetHoster

Canada · planethoster.com · 26 vendors

Resilience scores

Technology vendors

Services catalogue

4 services in catalogue across 2 categories; runs on 26 sub-vendors.

Insights

Last updated 2026-08-12 · revision 2

26 direct vendors, 252 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

PlanetHoster exhibits high migration readiness, primarily driven by its modern, internally managed cloud infrastructure and minimal external vendor lock-in. The company's internal use of OpenStack as its private cloud infrastructure provides a flexible, API-driven environment that is highly adaptable for migration scenarios. Support for multiple programming languages (PHP, Node.js, Python, Ruby), Git, WP-CLI, Composer, SSH/SFTP, and native CI/CD indicates a developer-friendly ecosystem conducive to modern deployment and migration practices. The provision of S3-compatible object storage (N0C Storage) further simplifies data migration. A significant strength is the reported 'Total Vendors: 0' for core infrastructure, implying very low external vendor lock-in for its primary hosting platform. While PlanetHoster utilizes proprietary systems like the N0C control panel, Auto Peak Power, and Hardware Anti-DDoS, these are internally developed and managed, meaning the company has full control over their migration paths. The diversity of service/component sourcing from 7 countries also suggests a flexible supply chain. The main limitations in assessing migration readiness are the absence of data on financial stability (which could impact funding for large-scale migrations), specific regulatory environments, and data residency requirements. However, the strong technical foundation and low external dependency position PlanetHoster very well for future migrations.

Compliance

10 in-scope frameworks identified; showing 3.

PCI DSS (source) — Compliant

PlanetHoster explicitly displays PCI DSS certification badges across its website, company page, and all three data center pages (Paris, Montreal, Lausanne). As a hosting provider that processes payment card data for its own billing operations and provides infrastructure to e-commerce clients (WooCommerce, PrestaShop, Magento), PCI DSS compliance is directly relevant. Risk is Low because: (1) PCI DSS is explicitly claimed and consistently displayed; (2) it is present across all data center locations; (3) the company's security controls (WAF, DDoS, encryption, access controls) align with PCI DSS requirements; (4) the company is an ICANN-accredited registrar handling payment transactions. The residual risk is that PCI DSS compliance level (SAQ vs. full QSA audit) is not specified.

Evidence: https://www.planethoster.com/en/Datacenter, https://www.planethoster.com/en/The-Company, https://www.planethoster.com/en

ISAE 3000 (source) — Partially Compliant

PlanetHoster's Lausanne data center explicitly displays an ISAE 3402 badge (a specific ISAE standard for service organization controls, equivalent to SOC 1). ISAE 3402 is the international equivalent of SSAE 16/SOC 1 and falls under the ISAE 3000 framework. The company also references SSAE 16 on its company page. Risk is Low because: (1) ISAE 3402 is explicitly claimed at the Lausanne facility level; (2) SOC 1 Type II (SSAE 16 equivalent) is claimed for data centers; (3) ISAE 3000 is a broad framework and the company demonstrates assurance reporting capability through SOC 1/SOC 2 reports. The risk is not 'None' because ISAE 3000 broader assurance engagements (beyond ISAE 3402) are not explicitly addressed, and organizational-level assurance reporting is not publicly documented.

Evidence: https://www.planethoster.com/en/Datacenter, https://www.planethoster.com/en/The-Company, https://www.planethoster.com/en/gdpr

ICANN Compliance — Compliant

PlanetHoster is an ICANN-accredited domain registrar, which requires ongoing compliance with ICANN's Registrar Accreditation Agreement (RAA), WHOIS accuracy requirements, domain transfer policies, and dispute resolution procedures. The company explicitly states ICANN compliance on its GDPR page and lists ICANN accreditation as a key certification. Risk is Low because: (1) ICANN accreditation is a formal, ongoing regulatory relationship with clear compliance requirements; (2) the company has maintained ICANN accreditation since 2014; (3) ICANN compliance is a prerequisite for continued domain registration operations; (4) the company also holds accreditations from AFNIC, CIRA, DNSbe, DNSlu, Eurid, LDNS, and Switch, demonstrating broad registrar compliance.

Evidence: https://www.planethoster.com/en/The-Company, https://www.planethoster.com/en/gdpr, https://www.icann.org/en, https://www.planethoster.com/en

Financials

Three-year financials

Financial Resilience Score: 7/10

PlanetHoster demonstrates strong qualitative financial resilience despite the absence of public financial disclosures. As a privately held Canadian corporation with unchanged shareholder base for over 15 years and no external capital, the company benefits from stable ownership, no PE overhang, and reduced refinancing risk. Its subscription-based web hosting and domain renewal model generates sticky recurring cash flows with typical industry gross margins of 60-75%, providing predictable revenue streams. The company's vertical integration—owning data centers in Canada, France, and Switzerland, its proprietary AS53589 network, in-house DDoS hardware, and the N0C control panel—reduces vendor dependency and cost inflation exposure. Geographic diversification across three data-center locations and multiple country-specific markets buffers exposure to any single regulatory or currency zone. With approximately 150,000 customers and 500,000 hosted sites, operational scale supports an inferred (undisclosed) annual revenue in the low-to-mid tens of millions CAD. However, resilience is constrained by intense competition from GoDaddy, OVHcloud, Hostinger, IONOS, AWS, and Cloudflare, which create structural margin pressure on smaller players. The capex-heavy business model requires ongoing data center investment sensitive to European electricity prices. Multi-currency exposure (EUR, CHF, GBP, CAD, USD) appears unhedged based on public info, and SMB/prosumer segment concentration implies higher churn during economic downturns. Zero financial transparency limits external due diligence to operational proxies.

Key strengths: Stable ownership with unchanged shareholders for 15+ years and no outside capital, Recurring subscription-based revenue model with 60-75% typical industry gross margins, Vertical integration: owns data centers, network AS53589, DDoS hardware, and N0C control panel, Geographic diversification across Canada, France, and Switzerland, Operational scale: 150,000 customers and 500,000 hosted websites, Strong certifications: ICANN, CIRA, AFNIC, TIER III/IV, ISO 27001, SOC 2, PCI-DSS, HIPAA, 18+ years of continuous organic, self-funded growth, 96.8% customer satisfaction across 7,188 verified reviews

Risk factors: Zero public financial transparency limits counterparty due diligence, Intense competition from GoDaddy, OVHcloud, Hostinger, IONOS, AWS Lightsail, Cloudflare and hyperscalers, Capex-heavy business requiring ongoing data center hardware refresh and connectivity investment, Sensitivity to European electricity prices post-2022, Multi-currency exposure (EUR, CHF, GBP, CAD, USD) appears unhedged, SMB/prosumer segment concentration with structurally higher churn during downturns, Key-person / founder risk given long-standing unchanged shareholder base, Cybersecurity liability exposure (blocked 144M web attacks and 2,800 DDoS attacks in 2024)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report