PubWorks

United States · www.pubworks.com · 8 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 8 sub-vendors.

Insights

Last updated 2026-09-12 · revision 1

8 direct vendors, 95 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

PubWorks' migration readiness is assessed as medium (50). A significant advantage is the reported 'Total Vendors: 0'. If accurate, this eliminates external vendor lock-in, which is often a major barrier to migration due to contract complexities and dependency management. However, this implies that all 17 listed services are managed internally. The complexity of migrating these internal systems is a major unknown due to the complete lack of data on the 'Internal Tech Stack' and 'Key Technologies' (e.g., cloud-native vs. legacy, containerization, microservices). This absence of architectural insight makes it challenging to estimate migration effort and cost. Furthermore, 'Data Residency Requirements' are 'Not specified', and the 'Regulatory Environment' is unknown, both of which could introduce significant hurdles during a migration. The lack of data on 'Revenue Concentration by Product/Geography' and 'Growth History' also prevents an assessment of PubWorks' financial capacity to fund a potentially large-scale migration project. While the absence of external vendor dependencies is a strong positive, the numerous unknowns regarding internal systems, compliance, and financial capacity temper the overall readiness score.

Compliance

9 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

As a software provider handling government data, implementing an Information Security Management System (ISMS) based on ISO 27001 would be a best practice. Some clients, particularly larger ones or those with international ties, may require it.

While ISO 27001 is a globally recognized information security standard, SOC 2 is more commonly requested by North American customers. The risk of not having this specific certification is likely low for PubWorks' current market.

PSAB 3150 — Compliant

PubWorks, in partnership with MuniSoft, explicitly offers a PSAB 3150 compliant asset registry and management solution to its Canadian municipal clients.

Non-compliance would make the product unsuitable for its target market of Canadian municipalities, leading to significant loss of business. The risk of this is medium, assuming their partnership with MuniSoft ensures continued compliance.

Evidence: https://gworks-showcase.webflow.io/products/pubworks, https://umaas.ca/wp-content/uploads/News-Events/Munisoft-PW-PO-Asset-Management.pdf, https://geospatialworld.net/news/gworks-govtech-expansion-continues-with-the-acquisition-of-softline-data-and-pubworks/

Section 508 — Assessment Required

PubWorks provides software to US public sector entities, including local and potentially federal government agencies. Section 508 of the Rehabilitation Act requires that technology procured by federal agencies be accessible to people with disabilities.

Failure to comply with Section 508 could result in losing US federal and state government contracts, a key market for PubWorks. The risk is medium as there is no public evidence of their accessibility posture.

Evidence: https://www.wcag.com/compliance/section-508/, https://brailleworks.com/section-508-compliance/, https://group107.com/blog/section-508-compliance-requirements/, https://groundworks.io/accessibility

Financials

Financial Resilience Score: 6/10

PubWorks appears to be a small, privately held U.S.-based GovTech software vendor associated with Tracker Software Corporation in Colorado. As a private company not registered with the SEC, no audited financial statements are publicly available, making a precise quantitative resilience assessment impossible. However, the business model provides qualitative indicators of moderate-to-good resilience: government-focused SaaS/maintenance-fee software typically generates sticky, multi-year recurring revenue, and municipal customers rarely switch operational systems once implemented due to high switching costs and procurement inertia. The company operates in a niche vertical (public works software for small-to-mid-sized municipalities), which reduces direct competition versus horizontal ERP vendors. Demand from local-government IT budgets for compliance and asset-management tends to be relatively insulated from consumer economic cycles, providing some countercyclical stability. However, the small scale of the company creates meaningful risks around competitive positioning against much larger GovTech platforms like Tyler Technologies, Cartegraph/OpenGov, Cityworks/Trimble, and Brightly/Siemens. Key concerns include reliance on U.S. municipal budgets which can tighten during recessions or when federal transfers decline, limited capital access as a likely bootstrapped or lightly funded private company, and disclosure opacity that prevents outside stakeholders from readily assessing liquidity or leverage. Without access to primary financial data, this score reflects the balanced qualitative profile of a niche recurring-revenue business against the risks of small scale and limited capital resources.

Key strengths: Recurring revenue profile from government-focused SaaS/maintenance fees, Sticky customer base with high switching costs among municipal clients, Niche focus on public works vertical reduces direct competition, Countercyclical demand from local-government IT budgets

Risk factors: Small scale versus larger GovTech competitors (Tyler Technologies, OpenGov, Trimble, Siemens), Concentration in U.S. municipal budgets vulnerable to recessions and federal transfer declines, Limited capital access as a private, likely bootstrapped company, Disclosure opacity prevents assessment of liquidity or leverage, No public financial statements available for external verification

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report