Portland Labs
United States · www.concretecms.com · 24 vendors
Resilience scores
- Digital Sovereignty: 83
- Digital Resilience: 5
- Financial Resilience: 6
Technology vendors
- HubSpot, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- Vultr — Technology — United States
- and 22 more
Services catalogue
1 service in catalogue across 1 category; runs on 24 sub-vendors.
- Concrete CMS
Insights
Last updated 2026-06-02 · revision 2
24 direct vendors, 270 subvendors
Direct vendors by controlling owner country (sample)
- United States: 20
- Sweden: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- Finland: 1
- United Kingdom: 6
- Germany: 6
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
A major advantage for migration readiness is the open-source nature of their flagship product, Concrete CMS, licensed under MIT. This significantly reduces software vendor lock-in and provides flexibility for migration. The company's familiarity with stringent compliance standards (ISO 27001, SOC 2, HIPAA) is a strong asset, as it means they have established processes that can be adapted to maintain compliance in a new environment. The use of GitLab CI/CD indicates a mature approach to deployments, which facilitates automated migration processes. However, the internal tech stack, primarily PHP and MySQL, while robust, does not explicitly mention cloud-native architectures, containerization (e.g., Docker, Kubernetes), or microservices, which could necessitate significant re-architecting during a migration to modern cloud platforms. The absence of data on financial stability (revenue, growth) makes it impossible to assess the company's capacity to fund a potentially costly migration effort. Data residency requirements are not specified, which could introduce unforeseen complexities if specific geographic data storage is mandated. The 'Total Vendors: 0' is ambiguous; if they rely on specific infrastructure for their managed hosting services, this could introduce infrastructure-level vendor lock-in, despite the open-source nature of their software. The score of 65 indicates a medium-high migration readiness. The open-source core product is a substantial enabler, providing significant flexibility. This, combined with their strong compliance posture and CI/CD practices, positions them well. However, the traditional aspects of their tech stack, the unknown financial capacity, and unspecified data residency requirements present notable challenges that prevent a higher score.
Compliance
5 in-scope frameworks identified; showing 3.
SOC 2 (source) — Compliant
Portland Labs is SOC 2 Type 2 compliant with regular audits. As a cloud services provider, SOC 2 compliance is critical for customer trust and regulatory requirements. Risk is low due to demonstrated compliance with Type 2 reporting (operational effectiveness over time).
Evidence: https://www.concretecms.com/about/legal/hosting-compliance
ISO 27001 (source) — Compliant
Portland Labs is ISO 27001 certified, demonstrating a robust information security management system. This significantly reduces security-related compliance risks and provides a strong foundation for other regulatory requirements.
Evidence: https://www.concretecms.com/about/legal/hosting-compliance, https://www.concretecms.com/about/legal/privacy-policy
GDPR (source) — Assessment Required
Portland Labs processes personal data through their website, hosting services, and customer interactions. While they are US-based, they likely process EU resident data through their global customer base and website visitors. Their privacy policy mentions EU-US Privacy Shield compliance, indicating EU data processing. Risk is medium due to potential fines up to 4% of annual turnover, but company appears to have some privacy controls in place.
Evidence: https://www.concretecms.com/about/legal/privacy-policy
Financials
Three-year financials
- null:
Financial Resilience Score: 6/10
PortlandLabs demonstrates qualitative financial resilience through its long operating history since 2008, marquee enterprise and government customers (U.S. Army, BASF, Home Depot, ITV, Safran, GlobalSign), and a recurring-revenue business model based on managed hosting subscriptions and enterprise SLAs. The company appears to be bootstrapped or founder-funded with no public evidence of significant debt or venture funding rounds, suggesting capital discipline and self-sustaining operations. The open-source flywheel of Concrete CMS lowers customer acquisition costs by funneling community users into commercial hosting and services tiers. However, the company faces meaningful risks that limit its resilience score. It operates in an extremely competitive CMS market dominated by WordPress (>40% market share), Drupal, Adobe Experience Manager, Sitecore, Contentful, Webflow, Wix, and Squarespace. As a small private firm with an estimated 10-50 FTEs, it has limited ability to outspend competitors on R&D or marketing. Customer concentration risk is significant, as government/military customers like the U.S. Army may represent a substantial share of enterprise revenue. Additionally, the PHP-based technology stack faces pressure from JavaScript/Node-based headless CMS architectures that are gaining momentum. The complete absence of public financial disclosures also limits external due diligence.
Key strengths: Long operating history since 2008 (~17 years), Recurring revenue from managed hosting subscriptions and enterprise SLAs, Marquee enterprise and government customers (U.S. Army, BASF, Home Depot, ITV, Safran, GlobalSign), Open-source flywheel lowers customer acquisition costs, Capital-light business model with no visible debt or VC funding, ISO 27001, SOC 2, and HIPAA-compliant hosting capabilities
Risk factors: Intense competition from WordPress (>40% market share), Drupal, Adobe, Sitecore, and headless CMS players, Customer concentration risk with large government/enterprise accounts, Small scale (estimated 10-50 FTEs) limits R&D and marketing spend, PHP-based technology stack faces pressure from JavaScript/Node headless CMS architectures, No audited financials limits creditor/partner due diligence, Small market share relative to dominant CMS competitors
Revenue by geography
- Japan: 0%
- United States: 0%
- Western Europe: 0%
Revenue by product/service
- Managed Hosting (SaaS Subscriptions): 0%
- Professional Services / Custom Development: 0%
- Marketplace (Themes, Add-ons, Integrations): 0%
Workforce by country
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.