Referral Rock
United States · referralrock.com · 12 vendors
Resilience scores
- Digital Sovereignty: 58
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Anthropic, PBC — Technology — United States
- Demandware — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 9 more
Services catalogue
1 service in catalogue across 1 category; runs on 12 sub-vendors.
- Referral Rock
Insights
Last updated 2026-08-02 · revision 2
12 direct vendors, 230 subvendors
Direct vendors by controlling owner country (sample)
- Singapore: 1
- Canada: 1
- Denmark: 1
Subvendors by controlling owner country (sample)
- China: 5
- Norway: 6
- United States: 164
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Referral Rock exhibits medium to high migration readiness, largely attributable to its foundational use of Microsoft Azure, indicating a cloud-native or cloud-first approach. The tech stack includes modern elements like REST APIs and JavaScript, suggesting an architecture that is likely modular and adaptable. A significant advantage for migration is the absence of specified data residency requirements, offering flexibility in choosing new infrastructure locations. The existing compliance with GDPR & CCPA also means the company has established processes for handling sensitive data, which is crucial for any migration. However, several factors temper the readiness score. There is no explicit mention of advanced cloud-native practices such as containerization or microservices, which would further enhance migration agility. Financial stability data is unavailable, making it difficult to assess the company's capacity to fund a significant migration effort. Critically, while vendor geographic diversity is good, the 'Total Vendors: 0' data point is contradictory to the presence of vendor countries and services; assuming there are vendors, the 'Vendor Lock-in Risk' is unknown, which is a key determinant of migration complexity. High vendor lock-in could significantly impede migration efforts.
Compliance
9 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
Referral Rock is a US-based SaaS company (Alexandria, VA) that explicitly acknowledges GDPR applicability and has published a dedicated GDPR compliance page, a Data Processing Agreement (DPA), and privacy rights mechanisms (right to deletion, portability, modification). The company processes personal data of EU/EEA residents through its global customer base and referral programs. Risk is Medium rather than Low because: (1) compliance is self-declared without evidence of independent third-party GDPR audit or DPO appointment; (2) the privacy policy was last updated January 2024, and the security page was last updated March 2021, suggesting potential gaps in keeping pace with evolving GDPR guidance; (3) the company acknowledges international data transfers to the United States without explicitly referencing Standard Contractual Clauses (SCCs) or other GDPR-compliant transfer mechanisms post-Schrems II; (4) no EU representative appointment is publicly documented. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://referralrock.com/gdpr/, https://referralrock.com/privacy/, https://referralrock.com/dpa/, https://referralrock.com/security/
ISO 27001 (source) — Partially Compliant
Similar to SOC 2, Referral Rock's privacy policy claims ISO/IEC 27001 certification 'through our third-party systems,' specifically Microsoft Azure (ISO/IEC 27001 certified). This represents inherited compliance from infrastructure providers rather than a direct ISO 27001 certification of Referral Rock Inc. as an organization. Risk is Medium because: (1) ISO 27001 certification of a cloud provider (Azure) does not extend to the tenant organization (Referral Rock); (2) enterprise and regulated-industry customers increasingly require direct ISO 27001 certification from SaaS vendors; (3) the security page describes an Information Security Management System (ISMS)-like program (security policies, access controls, annual training, incident response) but no certification body or certificate number is referenced; (4) no ISO 27001 certificate from an accredited certification body (e.g., BSI, Bureau Veritas, DNV) is publicly documented for Referral Rock.
Evidence: https://referralrock.com/privacy/, https://referralrock.com/security/, https://www.microsoft.com/en-us/TrustCenter/Compliance/ISO-IEC-27001
SOC 2 (source) — Partially Compliant
Referral Rock's privacy policy explicitly states 'Referral Rock is ISO/IEC 27001 and SOC II Type 2 Certified through our third-party systems,' specifically referencing Microsoft Azure (SOC 1/SSAE16, SOC 2/AT Section 101), SparkPost (SSAE-16 SOC II Type 2), and SendGrid (SOC2 Type 2). However, this language indicates that SOC 2 compliance is achieved through the certifications of third-party infrastructure providers rather than through a direct SOC 2 Type 2 audit of Referral Rock itself as an organization. Risk is Medium because: (1) reliance solely on sub-processor certifications does not constitute a SOC 2 Type 2 report for Referral Rock as the service organization; (2) enterprise customers and prospects may require a direct SOC 2 Type 2 report from Referral Rock; (3) the privacy policy language is ambiguous and could mislead customers about the scope of certification; (4) no direct SOC 2 report or audit letter from a licensed CPA firm is publicly referenced for Referral Rock itself.
Evidence: https://referralrock.com/privacy/, https://referralrock.com/security/, https://www.microsoft.com/en-us/trustcenter/compliance/soc, https://www.microsoft.com/en-us/TrustCenter/Compliance/ISO-IEC-27001
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Referral Rock is a bootstrapped, privately held US SaaS company that has operated independently for over 10 years without any outside funding. The founder has publicly emphasized profitability and self-sufficiency since 2015, which typically implies conservative burn and positive cash flow. The company has built a recurring SaaS revenue model with monthly and 6-month+ commitments, serves 1,000+ paying customers across diversified industries (home services, professional services, healthcare, financial services, e-commerce, SaaS, franchises, multi-location brands), and has notable enterprise logos including TripAdvisor, Penguin Random House, Culligan Water, Mitel, ActiveCampaign, Material Bank, Grover, and Flink. However, the resilience score is moderated by significant unknowns: no public financials (revenue, EBIT, equity) are disclosed, making external verification of financial health impossible. As a small bootstrapped company, it has less balance-sheet cushion than better-funded competitors like ReferralCandy, Friendbuy, Impact.com, PartnerStack, and Everflow. The referral/affiliate SaaS category is crowded and increasingly consolidated by larger partner-marketing suites. Key-person dependency on founder Josh Ho and SMB customer concentration (typically higher churn) further limit resilience. The company appears stable and likely profitable, but the lack of transparency and small scale warrant a mid-range score.
Key strengths: Bootstrapped with no outside funding or disclosed debt, 10+ years of continuous operation since 2015, 1,000+ paying customers with diversified industry base, Recurring SaaS revenue model with 6-month+ commitments, Marquee enterprise logos (TripAdvisor, Penguin Random House, Culligan, Mitel), Product breadth across referral, affiliate, and ambassador programs, 50+ integrations reducing single-platform dependency, Founder publicly emphasizes profitability and self-sufficiency
Risk factors: No public financial disclosures (revenue, EBIT, equity all undisclosed), Small bootstrapped scale with limited balance-sheet cushion vs. VC-funded competitors, Crowded competitive category with larger partner-marketing suites encroaching, Key-person dependency on founder Josh Ho, SMB customer concentration typically carries higher churn, External stakeholders cannot independently verify financial health
Workforce by country
- United States: 35
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.