punkt.de GmbH

Germany · www.punkt.de · 9 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 9 sub-vendors.

Insights

Last updated 2026-08-15 · revision 2

9 direct vendors, 84 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

punkt.de GmbH exhibits strong migration readiness, largely driven by its extensive adoption of open-source technologies and modern development practices. The company's reliance on open-source solutions (TYPO3, Neos, Sylius, Elastic, Keycloak, Matomo, Nextcloud, n8n, Mautic, Akeneo) minimizes proprietary vendor lock-in, making their applications highly portable across different environments. Their internal tech stack and product offerings highlight expertise in DevOps, Infrastructure as Code (IaC), and CI/CD pipelines, which are foundational for efficient and automated cloud migrations. The technologies used (PHP, JavaScript, React, NGINX, MySQL, PostgreSQL, Redis, Elasticsearch) are widely supported in public cloud environments. Furthermore, their demonstrated awareness of GDPR and data residency (with data centers in Germany, Finland, Switzerland) provides a solid basis for planning compliant cloud deployments. Key challenges for migration readiness include the potential complexity of migrating their *own* 'proServer Managed Hosting' infrastructure, which is built on FreeBSD and ZFS. While robust, these are less common in mainstream public cloud offerings compared to Linux, potentially requiring significant re-platforming efforts if they were to migrate this specific product. A major unknown is the lack of financial data (revenue, growth history), which makes it impossible to assess the company's financial capacity to fund a large-scale migration project. While client data residency is addressed, specific 'Data Residency Requirements' for their own internal operations are not specified. The 'Vendor Lock-in Risk' for their own vendors is also unknown, though their open-source focus mitigates much of this risk at the software level.

Compliance

8 in-scope frameworks identified; showing 3.

EU AI Act (source) — Assessment Required

The EU AI Act entered into force in August 2024 with phased implementation through 2027. punkt.de GmbH explicitly offers 'KI & RAG' (AI and Retrieval-Augmented Generation) specialist consulting services and workflow automation using AI-powered processes. As a developer and deployer of AI systems for clients, punkt.de may be subject to AI Act obligations depending on the risk classification of AI systems it develops or deploys. Risk is Low currently because: (a) most web agency AI implementations (content recommendations, chatbots, RAG systems) are likely to fall in the 'minimal risk' or 'limited risk' categories; (b) the AI Act's main obligations for high-risk AI systems are phased in from 2025-2027; (c) the company's AI services appear to be general-purpose tools rather than high-risk AI systems (e.g., biometric identification, critical infrastructure). However, assessment is required as AI Act obligations evolve.

Evidence: https://punkt.de/de/consulting/specialists/spezialist-ki-rag.html, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689

Telemediengesetz — Partially Compliant

The TTDSG (effective December 2021) governs cookie consent and electronic communications privacy in Germany, implementing the ePrivacy Directive. punkt.de GmbH operates a public website and uses tracking technologies (self-hosted Matomo, rek.ai for page recommendations). The company provides a Matomo opt-out mechanism on its privacy policy page, which is a positive compliance indicator. However, the use of rek.ai (an AI recommendation service that collects browser information and visited pages) requires proper consent management. Risk is Low because: (a) the company uses privacy-friendly Matomo rather than Google Analytics; (b) an opt-out mechanism is provided; (c) no cross-border data transfers are involved; (d) the company is not a telecommunications provider subject to the full scope of TTDSG.

Evidence: https://punkt.de/de/f/datenschutzerklaerung.html, https://punkt.de/de/digitale-loesungen/web-tracking-und-analyse-ohne-google-mit-matomo.html

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA for service organisations that store, process, or transmit customer data in the cloud. While not legally mandated in Germany or the EU, SOC 2 reports are increasingly requested by enterprise clients (particularly US-headquartered multinationals) as evidence of security controls. punkt.de GmbH provides managed hosting, infrastructure, and cloud services to enterprise clients including Siemens, Deutsche Post, and LeasePlan — organisations that may contractually require SOC 2 or equivalent assurance. No SOC 2 report has been found in public sources. Risk is Medium because: (a) the absence of SOC 2 may create a competitive disadvantage or contractual gap with enterprise clients; (b) the company's hosting services make it a relevant candidate for SOC 2 Type II; (c) however, SOC 2 is not legally required in Germany and many European companies use ISO 27001 as an equivalent. The company has not publicly disclosed ISO 27001 certification either, which compounds the gap.

Evidence: https://punkt.de/de/ueber-uns/awards-zertifikate.html, https://punkt.de/de/digitale-loesungen/hosting.html

Financials

Three-year financials

Financial Resilience Score: 7/10

punkt.de GmbH demonstrates solid financial resilience for a small German IT services company. With nearly 30 years of continuous operation since 1996, the company has proven its ability to weather multiple economic cycles and technology transitions, which strongly signals a stable, cash-generative operating model and low bankruptcy risk. The business model combines project-based consulting and custom development with recurring revenue from its proServer hosting infrastructure (over 1,024 proServers by 2023), providing subscription-like income that cushions project-business volatility. The company's blue-chip client base including Deutsche Post, Siemens, CompuGroup Medical, and S-Kreditpartner reduces receivables default risk and provides revenue stability. Strong ecosystem positioning as TYPO3 Gold Member and Neos Gold Partner generates steady referral projects. However, the small size (~40 FTEs) creates key-person risk and limits ability to absorb large project losses. Technology concentration in the TYPO3/Neos ecosystems poses a strategic risk if these platforms decline relative to global competitors. Rising German developer wages create margin pressure. No indication of private-equity backing suggests self-funded, organic growth with low leverage but limited scaling pace. Actual financial figures are not publicly disclosed due to small-GmbH exemptions under HGB.

Key strengths: Nearly 30 years of operating history since 1996, Diversified revenue mix: consulting + custom development + recurring hosting income, Blue-chip client base (Deutsche Post, Siemens, CGM, S-Kreditpartner), TYPO3 Gold Member and Neos Gold Partner ecosystem positioning, Recurring revenue from proServer hosting (1,024+ servers by 2023), Two locations diversifying regional client base (Karlsruhe + Frankfurt), Likely low leverage due to organic, self-funded growth

Risk factors: Small size (~40 FTEs) creates key-person risk, Limited ability to absorb large project losses, Technology concentration in TYPO3/Neos ecosystems, Rising German developer wages creating margin pressure, Dependence on German mid-market IT budget cycle, Limited financial disclosure reduces transparency with stakeholders, No private-equity backing limits pace of scaling

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report