Recurly
United States · recurly.com · 42 vendors
Resilience scores
- Digital Sovereignty: 88
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Anthropic, PBC — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 39 more
Services catalogue
5 services in catalogue across 4 categories; runs on 42 sub-vendors.
- Personal Data Processing
- Payment Processing
- Subscription and Billing
Insights
Last updated 2026-08-02 · revision 3
42 direct vendors, 345 subvendors
Direct vendors by controlling owner country (sample)
- UK: 1
- Greece: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- Czech Republic: 2
- United States: 232
- Sweden: 11
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Recurly exhibits high migration readiness, primarily due to its modern, cloud-native technology stack. The extensive use of AWS, Kubernetes for container orchestration, and Docker for containerization indicates an architecture designed for portability, scalability, and modularity, which are critical enablers for efficient migration. The platform's reliance on RESTful APIs and Webhooks further supports a decoupled architecture, simplifying integration and potential re-platforming efforts. Compliance with PCI-DSS, GDPR, and HIPAA suggests mature processes for data handling and security, which streamlines the complexities often associated with data migration and regulatory adherence. The integration with numerous global payment gateways and other third-party services (e.g., Braze, Vertex) demonstrates an architecture capable of managing external dependencies, a key factor in complex migrations. Potential challenges and unknowns include the "Ruby on Rails (historically core backend framework)," which, depending on its current state and degree of refactoring, could represent a more monolithic component requiring significant effort to migrate or modernize fully. However, the presence of Kubernetes suggests ongoing efforts towards modularization. There is no specified data residency requirement, which, if introduced, could add complexity to future migrations. Financial stability data is also absent, which is important for assessing the company's capacity to fund a significant migration project. The vendor relationship data is contradictory, stating "Total Vendors: 0" while listing "Total Services: 47" from 6 unique countries. This ambiguity makes it difficult to precisely assess vendor lock-in risk, though the geographic diversity of services generally points to a lower risk than a highly concentrated vendor base. The "unknown" vendor lock-in risk is a notable gap in the assessment.
Compliance
9 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 certification is not publicly confirmed by Recurly on its website or trust documentation. However, Recurly's SOC 2 Type II compliance demonstrates a mature information security management program that overlaps significantly with ISO 27001 requirements. The risk is Low because even without ISO 27001 certification, Recurly's SOC 2 Type II and PCI DSS compliance demonstrate robust information security controls. ISO 27001 is not a regulatory requirement for US-based SaaS companies, though it is increasingly expected by enterprise customers, particularly in Europe.
Evidence: https://recurly.com/security/, https://trust.recurly.com/
NIS2 (source) — Assessment Required
Recurly is a US-headquartered company and its primary operations are in the United States. NIS2 Directive (EU) 2022/2555 applies to entities providing services within the EU. Recurly is a digital service provider (online marketplace/cloud computing/search engine adjacent category) and could fall under NIS2 as a 'digital provider' if it meets the size threshold and provides services to EU entities. However, Recurly is not an EU-established entity and NIS2 primarily targets entities established in the EU. The risk is Low because Recurly's core business (subscription billing SaaS) does not fall squarely into NIS2's Essential Entity categories, and as a US company it would only be in scope if it has an EU establishment or designated representative. Enforcement against non-EU entities remains limited.
Evidence: https://recurly.com/security/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
SOX — Assessment Required
SOX applies to publicly traded companies in the United States. Recurly is a privately held company (acquired by Accel-KKR in 2019), so SOX does not directly apply to Recurly itself. However, Recurly's enterprise customers that are publicly traded may require SOX-relevant controls from Recurly as a service provider affecting their financial reporting. Recurly's automated revenue recognition (ASC-606/IFRS-15) product directly supports customers' financial reporting compliance. Risk is Low for Recurly directly, but the company must maintain controls relevant to its customers' SOX compliance.
Evidence: https://recurly.com/product/revenue-recognition/, https://recurly.com/security/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Recurly is a mature, privately held SaaS company backed by Accel-KKR, a well-capitalized technology-focused private equity firm that provides financial staying power and access to follow-on capital. The company operates a sticky, recurring-revenue business model typical of subscription-billing platforms, which generate high gross margins and low churn due to high switching costs, since billing systems sit at the heart of a customer's revenue stack. Recurly has a large blue-chip customer base including Paramount, Twitch, Experian, NerdWallet, Sling TV, and CBS Interactive, indicative of enterprise credibility and multi-year contracts. The company has a long operating history of 15+ years since its founding in 2009, with a mature product across launch, retention, revenue recognition (ASC-606 / IFRS-15), and payments. Its scale of transaction volume ($16B annual run rate) provides meaningful data assets for AI-driven products like Recurly Compass. However, it operates in a highly competitive market with well-funded competitors including Stripe Billing, Chargebee, Zuora, Maxio, Paddle, Adyen, and RevenueCat. Key risks include unknown customer concentration (loss of a large streaming/media customer could be material), typical PE-ownership leverage with undisclosed debt load, transparency gaps due to lack of published financials making creditworthiness assessment difficult, and macro exposure to consumer subscription fatigue affecting Recurly's DTC and streaming customers.
Key strengths: Backed by Accel-KKR private equity firm providing capital access, Sticky recurring-revenue SaaS business model with high switching costs, Blue-chip enterprise customer base (Paramount, Twitch, Experian, CBS Interactive), 15+ years operating history with mature product suite, $16B annual transaction run rate with 100M+ active subscribers, 77M+ subscription renewal events and 140+ currencies supported
Risk factors: Highly competitive market with well-funded rivals (Stripe, Adyen, Zuora, Chargebee), Unknown customer concentration risk with large media/streaming clients, PE ownership typically implies undisclosed leverage/debt load, Transparency gap due to lack of published audited financials, Macro exposure to consumer subscription fatigue and cost-cutting cycles
Revenue by geography
- North America: 80%
- EMEA and Other International: 20%
Revenue by product/service
- Core Subscription Billing Platform: 70%
- Recurly for Shopify / Commerce: 10%
- Recurly Engage: 8%
- Recurly RevRec: 7%
- Recurly Compass (AI): 5%
Workforce by country
- United States: 375
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.