Raygun

New Zealand · raygun.com · 12 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 2 categories; runs on 12 sub-vendors.

Insights

Last updated 2026-08-03 · revision 2

12 direct vendors, 206 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Raygun exhibits high migration readiness, primarily driven by a robust technical foundation. Their extensive use of Amazon Web Services (AWS) signifies strong cloud adoption and experience. The company's support for a diverse and modern technology stack, including .NET Core, Node.js, Python, Java, Go, various front-end frameworks, mobile SDKs, and AI integration, indicates a high capability for transitioning to cloud-native, containerized, and microservices architectures. The utilization of a REST API further enhances interoperability. The 'Total Vendors: 0' data point, if interpreted as minimal reliance on external critical vendors, could suggest low vendor lock-in, which is a significant advantage for migration flexibility. However, critical information regarding regulatory environment, data residency requirements, and financial stability (ability to fund a migration) is missing, which introduces some uncertainty. The 'Vendor Lock-in Risk' is explicitly unknown, making a definitive assessment of vendor-related migration challenges difficult.

Compliance

7 in-scope frameworks identified; showing 3.

CCPA — Compliant

Raygun explicitly claims CCPA compliance on its homepage ('We adhere to the most stringent security requirements and are HIPAA, GDPR, CCPA, and PCI compliant'). CCPA applies to for-profit businesses that collect personal information of California residents and meet one of three thresholds: annual gross revenue >$25M, buy/sell/receive/share personal information of 100,000+ consumers/households annually, or derive 50%+ of annual revenue from selling personal information. Given Raygun's global scale (100,000+ developers across 120+ countries), CCPA applicability is highly likely. Risk is Low given explicit compliance claim and GDPR-aligned data controls that substantially satisfy CCPA requirements.

Evidence: https://raygun.com, https://raygun.com/privacy, https://raygun.com/security

HIPAA (source) — Compliant

Raygun explicitly claims HIPAA compliance on its security page and states willingness to sign a Business Associate Agreement (BAA) with healthcare customers. HIPAA applies to Raygun when it processes electronically Protected Health Information (e-PHI) on behalf of Covered Entities or Business Associates in the US healthcare sector. Raygun's self-attestation of HIPAA compliance and BAA availability reduces risk for healthcare customers. Risk is Low for customers who execute a BAA with Raygun, as the contractual and technical safeguards are in place. Residual risk exists because no independent HIPAA audit or third-party attestation report is publicly available.

Evidence: https://raygun.com/security, https://raygun.com/about/contact

PCI DSS (source) — Assessment Required

Raygun claims PCI compliance on its homepage. PCI DSS applies to entities that store, process, or transmit cardholder data. As an application monitoring platform, Raygun could potentially capture payment card data within error reports or session traces if customers' applications process payments and do not properly filter sensitive data before transmission. Raygun provides data filtering tools to prevent this. The risk is Medium because while Raygun claims PCI compliance, the specific PCI DSS level, SAQ type, or QSA attestation is not publicly disclosed, making independent verification impossible.

Evidence: https://raygun.com, https://raygun.com/security, https://raygun.com/industry/ecommerce

Financials

Three-year financials

Financial Resilience Score: 6/10

Raygun Limited is a private New Zealand-based SaaS company with limited public financial disclosure. As an unlisted private company that likely does not meet the 'large' threshold under the NZ Companies Act, it is not required to file publicly available audited financial statements. The company has demonstrated durability through a long operating history since 2007 and a successful pivot from .NET developer components (as Mindscape) to a SaaS APM/crash reporting/RUM platform. The recurring SaaS revenue model provides predictable revenue with typically high gross margins, and blue-chip customer references such as Microsoft, Coca-Cola, HBO, and Domino's suggest enterprise segment penetration with higher ACVs and lower churn. The absence of publicly reported distress and the fact that no priced round beyond the 2014 Series A (~NZ$4.2M) has been disclosed suggests the company may be self-funded and cash-flow positive, though this cannot be verified. However, resilience is meaningfully constrained by intense competition from far larger, well-capitalised observability vendors (Datadog, New Relic, Dynatrace, Sentry, Splunk, Grafana), consolidation risk in the observability space, and limited disclosed capital that may hinder aggressive investment relative to competitors. FX exposure (NZD cost base vs. USD revenue) is generally favourable but adds volatility. Overall, the company appears operationally resilient for a niche player but faces structural headwinds.

Key strengths: Recurring SaaS subscription revenue model with high gross margins, Blue-chip enterprise customer references (Microsoft, Coca-Cola, HBO, Domino's), Long operating history since 2007 with no reports of distress, Product breadth across crash reporting, RUM, and APM enables cross-sell, Recent AI Error Resolution product extension aligns with topical adjacency, Likely self-funded/profitable given no priced round since 2014, Favourable FX exposure (NZD cost base, USD revenue)

Risk factors: Intense competition from larger, better-capitalised observability vendors (Datadog, New Relic, Dynatrace, Sentry, Splunk, Grafana), Consolidation risk in observability sector squeezing niche vendors, Limited disclosed capital raises since 2014 Series A may constrain investment, R&D scale disadvantage vs. large competitors, Private-company opacity limits external stakeholder visibility, FX volatility between NZD costs and USD revenue, Small-country base with limited domestic market

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report