Rapyd
United States · rapyd.cloud · 23 vendors
Resilience scores
- Digital Sovereignty: 57
- Digital Resilience: 5
- Financial Resilience: 4
Technology vendors
- Meta Platforms, Inc. — Technology — United States
- Primer — United States
- Visa Inc. — Financial Services — United States
- and 22 more
Services catalogue
1 service in catalogue across 1 category; runs on 23 sub-vendors.
- Rapyd
Insights
Last updated 2026-08-16 · revision 2
23 direct vendors, 232 subvendors
Direct vendors by controlling owner country (sample)
- United Kingdom: 1
- Denmark: 1
- Switzerland: 1
Subvendors by controlling owner country (sample)
- China: 4
- Netherlands: 3
- Israel: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Rapyd exhibits high migration readiness. A key strength is the adoption of container isolation (per-environment containerization), which significantly enhances workload portability and simplifies migration to cloud-native environments. The internal tech stack includes modern components such as PHP 8.x, LiteSpeed Web Server, MariaDB, KeyDB, and Redis. Furthermore, the company's offering of "Headless WordPress Hosting" indicates a capability and understanding of decoupled architectures, which are generally more cloud-friendly and easier to migrate than monolithic systems. However, a complete assessment is hindered by the lack of information regarding the specific regulatory environment, data residency requirements, and financial stability (which impacts the ability to fund a migration). Vendor lock-in risk is also difficult to precisely assess due to conflicting data; while there is good geographic diversity among implied vendor headquarters (11 countries), the "Total Vendors: 0" data point makes it unclear how many distinct vendors are involved and the complexity of their contracts.
Compliance
8 in-scope frameworks identified; showing 3.
CPRA — Partially Compliant
Rapyd Cloud/Levamo LLC is a US-based company (Florida LLC) that serves California residents. The Privacy Policy explicitly includes an 'Additional Terms for US Citizens' section referencing the California Privacy Rights Act (CPRA) and lists the categories of personal information collected per California Civil Code Section 1798.80. The company states it does not sell personal information and does not engage in profiling for automated decisions (per Colorado Privacy Act). Risk is Medium because: (1) The company has made CCPA/CPRA disclosures; (2) However, no formal CCPA compliance audit has been disclosed; (3) The company's size and revenue thresholds relative to CCPA applicability thresholds are not publicly confirmed; (4) The Privacy Policy was last updated May 26, 2026, indicating active maintenance.
Evidence: https://rapyd.cloud/legal/privacy-policy/, https://levamo.com/legal/privacy-policy/
GDPR (source) — Partially Compliant
Rapyd Cloud (now Levamo LLC) is a US-based cloud hosting provider that explicitly serves EU/EEA customers and processes their personal data. The company has published a comprehensive GDPR-aligned Privacy Policy, a Data Processing Addendum (DPA) incorporating EU Standard Contractual Clauses (SCCs) per Commission Implementing Decision (EU) 2021/914, Controller-to-Processor and Processor-to-Processor transfer documents, a Subprocessors list, and explicit 'Additional Terms for EU Citizens' in its Privacy Policy. These are strong indicators of active GDPR compliance efforts. However, risk remains Medium because: (1) no independent third-party GDPR audit or DPO appointment has been publicly disclosed; (2) the company is US-based and relies on SCCs for cross-border transfers rather than an adequacy decision; (3) the company is small/medium-sized and may lack dedicated compliance resources; (4) the Privacy Policy was last updated May 26, 2026, suggesting active maintenance. The absence of a publicly named Data Protection Officer (DPO) and no evidence of formal GDPR certification (e.g., via an EU supervisory authority) keeps the risk at Medium rather than Low.
Evidence: https://rapyd.cloud/legal/privacy-policy/, https://levamo.com/legal/privacy-policy/, https://levamo.com/legal/data-processing-addendum/, https://levamo.com/legal/controller-to-processor-transfers/, https://levamo.com/legal/processor-to-processor-transfers/, https://levamo.com/legal/subprocessors/
CAN-SPAM Act — Compliant
Rapyd Cloud/Levamo LLC explicitly addresses CAN-SPAM Act and TCPA compliance in its Terms of Service (Section 11 - Communication Services). The company places responsibility on customers for compliance with these laws when using communication services, and its own marketing communications include opt-out mechanisms as described in the Privacy Policy. Risk is Low as the company has documented its obligations and customer responsibilities under these frameworks.
Evidence: https://levamo.com/legal/terms-of-service/, https://levamo.com/legal/privacy-policy/
Financials
Three-year financials
- null:
Financial Resilience Score: 4/10
Rapyd Cloud (now rebranded to Levamo LLC as of May 2026) is a small, privately-held US LLC with no public financial disclosures. As a result, quantitative assessment of financial resilience is not possible. Qualitatively, the company likely benefits from a subscription/recurring-revenue managed hosting model, which typically produces predictable cash flow and healthy gross margins in the hosting industry. Its asset-light model — running on top of hyperscaler clouds and Cloudflare Enterprise CDN — avoids heavy capex requirements. The company has notable strengths in founder pedigree (built by the BuddyBoss team), which provides an in-built customer pipeline, and a niche positioning in high-value 'hard-to-host' WordPress workloads (WooCommerce, BuddyBoss, LMS, membership sites) that command higher price points than generic shared hosting. Reference customers include WPForms, AIOSEO, MonsterInsights, OptinMonster, Duplicator, EDD, BuddyBoss, and The Gottman Institute. However, the company is small (~30+ employees), faces intense competition from much larger and better-capitalized rivals (WP Engine, Kinsta, Cloudways, Rocket.net, Pressable, Pagely), and has concentration risk in the WordPress ecosystem. There is no visible external funding, which suggests financial discipline but also limits the war chest against VC-backed competitors. The recent rebrand from Rapyd Cloud to Levamo introduces short-term SEO/marketing transition risk.
Key strengths: Subscription/recurring-revenue managed hosting model with predictable cash flow, Asset-light infrastructure model on top of hyperscalers and Cloudflare, Founder pedigree and captive customer base from BuddyBoss ecosystem, Niche positioning in high-value dynamic WordPress workloads commanding premium pricing, Notable customer references within the WordPress SaaS ecosystem
Risk factors: Small scale (~30+ employees) limits ability to absorb shocks or price wars, Intense competition from larger, better-capitalized hosting providers (WP Engine, Kinsta, Cloudways), Concentration risk in the WordPress/WooCommerce ecosystem, Brand transition risk from Rapyd Cloud to Levamo rebrand (May 2026), Dependence on third-party infrastructure (Cloudflare, hyperscalers, open-source WordPress), No visible external funding limits war chest versus VC-backed competitors, Brand confusion with the unrelated fintech Rapyd Financial Network
Revenue by geography
- Canada: 0%
- Australia: 0%
- Rest of World: 0%
- United States: 0%
- United Kingdom: 0%
Revenue by product/service
- Agency Hosting: 0%
- BuddyBoss Hosting: 0%
- Enterprise Hosting: 0%
- MemberPress Hosting: 0%
- WooCommerce Hosting: 0%
- Managed WordPress Hosting: 0%
- Headless WordPress Hosting: 0%
- Easy Digital Downloads Hosting: 0%
- LMS Hosting (LearnDash, TutorLMS, LifterLMS): 0%
Workforce by country
- India: 0
- Spain: 0
- Australia: 0
- Philippines: 0
- United States: 0
- Serbia/Croatia: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.