RecMan

Norway · www.recman.no · 19 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 19 sub-vendors.

Insights

Last updated 2026-08-02 · revision 1

19 direct vendors, 238 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

RecMan demonstrates very high migration readiness, primarily driven by its modern and flexible technology stack. The company's infrastructure is built on Amazon Web Services (AWS) and utilizes containerization (Docker/container workloads), which are hallmarks of cloud-native architecture, enabling high portability and ease of deployment across different cloud environments or regions. A significant strength is the 'RecMan Open API,' which is fully documented and provides SDK examples in numerous programming languages. This greatly reduces potential vendor lock-in related to data and integration, allowing for seamless data import, export, and updates during a migration. The existing integrations with Microsoft Azure Active Directory and Google Workspace for SSO further simplify user management and authentication aspects of a migration. RecMan's adherence to high compliance standards (ISO 27001, SOC 2 Type 1, PCI DSS, and GDPR compliance tools) indicates mature processes that can facilitate migration to other compliant platforms. The main challenges or unknowns for migration readiness include the unspecified 'Data Residency Requirements,' which could introduce constraints on target environments, and the 'Vendor Lock-in Risk' which is currently unknown. While 'Total Services: 18' might suggest numerous dependencies, the presence of a robust Open API significantly mitigates potential integration complexities. The lack of financial stability data also means the ability to fund a large-scale migration cannot be assessed. However, from a purely technical and architectural standpoint, RecMan is exceptionally well-prepared for migration.

Compliance

7 in-scope frameworks identified; showing 3.

Norwegian Personal Data Act — Compliant

Norway's Personal Data Act (Personopplysningsloven, last amended 2018) implements GDPR into Norwegian law via the EEA Agreement. As a Norwegian company, RecMan is directly subject to this act and supervised by the Norwegian Data Protection Authority (Datatilsynet). Risk is Low because RecMan's demonstrated GDPR compliance (ISO 27001, SOC 2, GDPR Admin module, EEA-only infrastructure, privacy policy) directly satisfies the requirements of the Norwegian Personal Data Act, which mirrors GDPR substantively.

Evidence: https://www.recman.io/privacy-and-terms/privacy, https://www.recman.io/public/documents/pdf/hosting_and_security_overview.pdf, https://lovdata.no/dokument/NL/lov/2018-06-15-38

ISO 27001 (source) — Compliant

RecMan holds a current ISO 27001:2022 certification (certificate dated 2025-09-23) and has maintained ISO 27001 certification for five consecutive years, demonstrating sustained commitment to information security management. ISO 27001 is directly applicable to RecMan as a SaaS provider handling sensitive HR, candidate, payroll, and business data. Risk is Low because the certification is current, independently audited, and publicly disclosed. The five-year track record of continuous certification significantly reduces the risk of lapsed or inadequate information security management.

Evidence: https://www.recman.io/privacy-and-terms/documentation, https://www.recman.io/public/documents/pdf/recman_iso_27001_2023_certificate.pdf, https://www.recman.io/public/documents/pdf/hosting_and_security_overview.pdf, https://www.recman.io/public/documents/pdf/information_security_policy.pdf

ISAE 3000 (source) — Assessment Required

ISAE 3000 (Revised) is the international standard for assurance engagements other than audits or reviews of historical financial information. It is commonly used as the framework for SOC 2 reports issued outside the US (where SSAE 18 applies domestically). RecMan's SOC 2 Type 1 report (2024) may have been issued under ISAE 3000 given that the auditor (Boulay) is a US-based firm, but this is not explicitly confirmed. Risk is Low because RecMan has already completed a SOC 2 Type 1 assessment providing equivalent assurance, and ISAE 3000 is not a mandatory regulatory requirement for RecMan's industry. The primary gap is the absence of explicit confirmation of the assurance standard used.

Evidence: https://www.recman.io/privacy-and-terms/documentation, https://www.recman.io/public/documents/pdf/soc_2_type_1_report.pdf

Financials

Financial Resilience Score: 6/10

RecMan AS demonstrates qualitative strengths that support a moderate financial resilience assessment, though specific financial figures could not be retrieved to enable a quantitative evaluation. The company benefits from a blue-chip customer base including Randstad, Experis/ManpowerGroup, Kelly Services, Barona, Jobzone, and OnePartnerGroup, which typically translates into sticky, multi-year SaaS revenue streams. Its vertical focus on staffing and recruitment with an integrated feature set (ATS + CRM + time tracking + payroll/invoicing + Employee App) creates high switching costs for customers, supporting revenue predictability. The Nordic-first strategy with expansion into broader Europe, supported by localization into 7 languages, diversifies geographic exposure. The recurring subscription revenue model typical of SaaS supports predictable cash flow, and 200+ integrations plus a BI/data-warehouse add-on indicate an increasingly platform-oriented offering that enhances customer retention. However, risks include operating in a crowded competitive category (Bullhorn, Teamtailor, Jobylon, etc.) with pricing pressure, sector concentration in staffing making the business sensitive to macroeconomic cycles affecting temporary-worker demand, and multi-currency FX exposure. As a private Norwegian AS, capital structure and any debt covenants are not visible without accessing filed accounts. Small-to-mid-sized SaaS firms often show low or negative EBIT while investing in growth, which cannot be verified from available information.

Key strengths: Blue-chip customer base including Randstad, Experis, Kelly Services, and Barona, Integrated ATS + CRM + workforce management platform creates high switching costs, Nordic + broader-European footprint with 7-language localization, Recurring SaaS subscription revenue model supports predictable cash flow, 200+ integrations and BI add-on strengthen platform stickiness, GDPR compliant with ISO-standard security

Risk factors: Crowded competitive category (Bullhorn, Teamtailor, Jobylon, Intelliplan) with pricing pressure, Sector concentration in staffing sensitive to macroeconomic cycles, Multi-currency FX exposure (USD, EUR, NOK, SEK, DKK, COP, GBP), Capital structure and debt covenants not publicly visible, Small-to-mid SaaS firms often show low or negative EBIT during growth phases

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report