rami.io GmbH
Germany · pretix.eu · 10 vendors
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Atlassian Corporation Plc — Technology — Australia
- Google LLC — Technology — United States
- HubSpot, Inc. — Technology — United States
- and 8 more
Services catalogue
4 services in catalogue across 3 categories; runs on 10 sub-vendors.
- Custom Email Hosting
- Pretix
- Email Service
Insights
Last updated 2026-08-02 · revision 1
10 direct vendors, 163 subvendors
Direct vendors by controlling owner country (sample)
- United States: 7
- Germany: 2
- Australia: 1
Subvendors by controlling owner country (sample)
- Ireland: 1
- Ukraine: 1
- Denmark: 3
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
rami.io GmbH exhibits a high degree of migration readiness primarily due to its modern, portable, and open-source technology stack. The use of Python, Django, PostgreSQL, Redis, and Celery, along with a well-defined REST API, suggests an architecture that is highly adaptable to cloud environments. The open-source nature of their core products and technologies significantly reduces software-level vendor lock-in, providing substantial flexibility for platform choices during migration. The presence of infrastructure components like Patroni (for PostgreSQL HA), HAProxy, and etcd indicates a team capable of managing complex, distributed systems, which is beneficial for cloud-native adoption. Existing strong compliance frameworks (GDPR, ISO 27001, PCI DSS) demonstrate mature processes that can be adapted to a new cloud environment. However, certain factors present challenges. While the company adheres to stringent regulatory requirements, maintaining these compliances during and after migration will require careful planning and execution, potentially increasing complexity and cost. Although not explicitly stated, the company's sole operational presence in Germany strongly implies data residency requirements within Germany or the EU, which could limit the choice of cloud regions and providers. The lack of information regarding financial stability (revenue concentration, growth history) makes it difficult to assess the company's capacity to fund a potentially significant migration effort. Additionally, while vendor geographic diversity is present, the specific vendor lock-in risk remains unknown, which could impact the ease of transitioning away from existing service providers. The absence of explicit mention of containerization (e.g., Docker, Kubernetes) or a microservices architecture, while compatible with their stack, means these may be new adoption efforts during migration.
Compliance
8 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Compliant
The company has publicly confirmed ISO/IEC 27001 certification with a downloadable certificate, validated through external audits on a regular basis. This is the gold standard for information security management and demonstrates a mature, audited ISMS. Risk is Low because: (1) certification is confirmed and publicly evidenced; (2) external audits are conducted regularly; (3) the ISMS covers the company's hosting and software development operations; (4) the company has an appointed Information Security Officer (Jochen Siebert, publicly named). The main residual risk is ensuring continuous compliance between audit cycles, but the company's transparent security disclosure page and active vulnerability management program indicate ongoing security diligence.
Evidence: https://pretix.eu/about/en/security, https://static.pretix.cloud/static/pretixeu/cert/z_eng_isms_26.75e712f50605.pdf, https://pretix.eu/about/en/company, https://cdn.pretix.cloud/1/pub/_global/PCI%20DSS-v4.0.1_CERTIFICATE_pretix_gmbh_10_31_2025_en.pdf
ISAE 3000 (source) — Assessment Required
ISAE 3000 is an international assurance standard used for non-financial assurance engagements, often applied in the context of data protection, sustainability, or IT controls reporting. It is not a mandatory regulatory requirement for a ticketing SaaS company. Risk is Low because: (1) ISAE 3000 is voluntary and not mandated by any regulation applicable to pretix GmbH's industry; (2) the company's ISO 27001 certification and PCI DSS compliance provide robust third-party assurance without requiring ISAE 3000; (3) no customer or regulatory requirement for ISAE 3000 reporting has been identified. The framework is more commonly used by financial service providers or companies seeking to provide formal assurance reports to stakeholders.
Evidence: https://pretix.eu/about/en/security
SOC 2 (source) — Assessment Required
SOC 2 is a voluntary framework developed by the AICPA for service organizations that store, process, or transmit customer data in the cloud. pretix GmbH is a cloud SaaS provider processing personal data for 3,000+ customers, making SOC 2 highly relevant from a customer trust and enterprise sales perspective. Risk is Medium because: (1) the company has not publicly disclosed a SOC 2 report; (2) enterprise customers (particularly US-based or large EU enterprises) increasingly require SOC 2 Type II reports as a vendor due diligence requirement; (3) absence of SOC 2 may limit the company's ability to win enterprise contracts; (4) however, the company's ISO 27001 certification provides a comparable (and in the EU, often preferred) alternative assurance framework. The business risk of not having SOC 2 is real but partially mitigated by ISO 27001.
Evidence: https://pretix.eu/about/en/security, https://static.pretix.cloud/static/pretixeu/cert/z_eng_isms_26.75e712f50605.pdf
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
rami.io GmbH (renamed pretix GmbH in 2025) is a bootstrapped, owner-led German SaaS ticketing company that has grown organically without external investors or creditors. This financial independence is a strength, as management is not subject to VC dilution pressure or debt covenants, and the company has funded growth via customer revenue for over a decade. The business model benefits from recurring SaaS revenue, a diversified customer base of >3,000 organizations across multiple event verticals (conferences, trade fairs, museums, zoos, festivals), and a compliance edge (ISO 27001, GDPR, PEPPOL) that supports enterprise and public-sector sales. However, resilience is constrained by the company's small scale (~31 employees), key-person risk around founder Raphael Michel, and cyclical exposure to the discretionary events industry — as demonstrated during COVID-19, when in-person ticketing collapsed and the company had to pivot with the Venueless product to survive. There is no external capital buffer for shocks or aggressive expansion, and the company competes against much larger players like Eventbrite, Ticketmaster, and Cvent. Financial transparency is limited as a small GmbH, with no publicly verifiable revenue, EBIT, or equity figures available in this session, which itself is a resilience concern for counterparties assessing credit or contract risk.
Key strengths: Bootstrapped with no external investors or creditors, Recurring SaaS revenue model, Diversified customer base of >3,000 organizations across multiple verticals, Open-source community driving inbound leads, ISO 27001, GDPR, and PEPPOL compliance edge for EU enterprise/public-sector sales, Organic headcount growth from 1 to 31 over ~11 years, Successful COVID-era pivot with Venueless product
Risk factors: Small scale (~31 employees) limits operational resilience, Key-person risk around founder/CEO Raphael Michel, Cyclical exposure to discretionary events industry (COVID-type shocks), Competitive pressure from Eventbrite, Ticketmaster, Cvent, Weezevent, No external capital buffer for shocks or M&A, Limited financial disclosure as small GmbH, Ongoing regulatory compliance workload (KassenSichV, DSGVO)
Workforce by country
- Germany: 31
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.