Procore Technologies
United States · www.procore.com · 39 vendors
Procore Technologies, Inc. provides a cloud-based construction management software platform that connects all stakeholders throughout the construction lifecycle. It offers solutions for preconstruction, project management, workforce management, and financial management. The platform aims to help teams build with efficiency, predictability, and safety.
Resilience scores
- Digital Sovereignty: 85
- Digital Resilience: 9
Technology vendors
- Adobe Inc. — Technology — United States
- Anthropic, PBC — Technology — United States
- Skilljar — United States
- and 37 more
Services catalogue
3 services in catalogue across 2 categories; runs on 39 sub-vendors.
- Construction Management
- Datagrid AI
- Procore
Insights
Last updated 2026-09-13 · revision 3
39 direct vendors, 294 subvendors
Direct vendors by controlling owner country (sample)
- Singapore: 1
- France: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- France: 9
- Brazil: 1
- Italy: 1
Migration Readiness: 10/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Procore Technologies exhibits exceptionally high migration readiness. Their tech stack is inherently cloud-native, built on AWS with extensive use of containerization (Kubernetes, Docker) and a microservices architecture. This modular and decoupled design significantly reduces the complexity and risk associated with migrating applications. The adoption of infrastructure as code with Terraform, along with modern API standards (RESTful, GraphQL, gRPC), ensures portability and ease of integration. Their strong regulatory compliance posture (FedRAMP, SOC, ISO) means they have established processes and controls that would facilitate meeting compliance requirements in a new environment. While specific data on data residency requirements and financial stability for funding a migration is not provided, their advanced technological foundation suggests they are well-positioned for any strategic migration, whether it's optimizing within AWS or considering a multi-cloud approach. The diverse vendor landscape, with services from vendors in 6 unique countries, suggests a flexible ecosystem that is less prone to severe vendor lock-in, despite the 'Total Vendors: 0' data point being contradictory to the listed internal tech stack and vendor diversity information.
Compliance
11 in-scope frameworks identified; showing 3.
CPRA — Compliant
Procore is headquartered in Carpinteria, California, USA, making CCPA/CPRA directly applicable as a California-based business that processes personal information of California residents at significant scale. Risk is Low because Procore has publicly demonstrated compliance: a dedicated 'Do Not Sell Personal Information' page, a comprehensive Privacy Notice, and cookie management mechanisms are all publicly visible. As a large enterprise SaaS company, Procore has the resources and legal infrastructure to maintain CCPA/CPRA compliance.
Evidence: https://www.procore.com/legal/california-consumer-rights, https://www.procore.com/legal/privacy, https://www.procore.com
ISAE 3000 (source) — Assessment Required
ISAE 3000 is the international standard for assurance engagements other than audits or reviews of historical financial information. It is the international equivalent framework underpinning SOC 2-type reports outside the US (e.g., used in Europe and other jurisdictions). Given Procore's EU operations and European customer base, some European customers or regulators may request ISAE 3000-based assurance reports (such as ISAE 3402 for service organizations). Procore's existing SOC 2 Type 2 (SSAE 18) and ISO 27001 certifications provide substantial equivalent assurance, but a formal ISAE 3000 report has not been publicly confirmed. Risk is Low because the existing SOC 2 and ISO 27001 certifications largely satisfy the same assurance needs, and ISAE 3000 is not a mandatory regulatory requirement for Procore's industry.
Evidence: https://trust.procore.com, https://www.procore.com/trust-and-security
FedRAMP — Compliant
Procore has achieved FedRAMP Class C (Moderate) certification for its Procore for Government product, which is a significant and rigorous US federal government cloud security authorization. This is a voluntary but highly demanding certification that demonstrates a mature security posture. Risk is Low for the Government product line. For the commercial product, FedRAMP does not apply, but the security controls implemented for FedRAMP compliance benefit the overall platform security posture.
Evidence: https://trust.procore.com, https://www.procore.com/trust-and-security, https://www.procore.com/government
Financials
Three-year financials
- 2025: revenue USD 1.32B, EBIT USD -124M, equity USD 1.26B
- 2024: revenue USD 1.15B, EBIT USD -136M, equity USD 1.29B
- 2023: revenue USD 950M, EBIT USD -216M, equity USD 1.16B
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.