Refiner

France · refiner.io · 11 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 11 sub-vendors.

Insights

Last updated 2026-06-24 · revision 1

11 direct vendors, 202 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Refiner exhibits high migration readiness. The company's internal tech stack is modern and cloud-oriented, heavily utilizing Amazon Web Services (AWS) and offering various SDKs (JavaScript, iOS, Android, React Native, Flutter), REST APIs, and Webhooks, which suggests a distributed and interoperable architecture. This cloud-native approach significantly reduces the technical hurdles associated with migration. Furthermore, their adherence to stringent regulatory compliance frameworks (GDPR, CCPA, HIPAA, SOC 2 Type II) indicates well-defined processes and controls that can facilitate a structured migration, provided these standards are maintained in the new environment. The absence of specified data residency requirements also offers greater flexibility in choosing migration targets. A primary challenge to migration readiness is the lack of financial data (revenue concentration, growth history), which prevents an assessment of the company's ability to fund a potentially significant migration effort. While the use of standard APIs and SDKs mitigates deep technical lock-in, reliance on core business vendors like Stripe (payment processing), Chargebee (subscription billing), and Customer.io (email delivery) could present moderate vendor lock-in risks and complexities during a transition, particularly if alternative solutions are sought.

Compliance

6 in-scope frameworks identified; showing 3.

CCPA — Compliant

Refiner has a dedicated CCPA compliance page and lists CCPA as one of their core compliance frameworks. As a global SaaS provider serving US customers (including California residents), CCPA applicability is confirmed. Risk is Low because: (1) Refiner explicitly acknowledges CCPA and has published compliance documentation; (2) Their data architecture (no user data sent to sub-processors by default, data deletion mechanisms, data ownership principles) supports CCPA compliance; (3) The SOC 2 Type II audit provides overlapping security controls assurance.

Evidence: https://refiner.io/legal/ccpa/, https://refiner.io/security-statement/, https://refiner.io/legal/privacy-policy/

NIS2 (source) — Assessment Required

Refiner is a French SaaS company providing in-app survey software. NIS2 Directive (EU 2022/2555) applies to Essential and Important Entities in the EU. Refiner does not operate in any of the NIS2 Essential Entity sectors (energy, transport, banking, health, water, digital infrastructure, public administration, space). As a digital provider of survey software, it could potentially fall under the 'Digital Providers' category (online marketplaces, online search engines, cloud computing services) if it qualifies as a cloud computing service provider, but in-app survey software is not a core cloud infrastructure service. The size threshold (50+ employees or €10M+ turnover) is unconfirmed — Refiner appears to be a small/micro company based on its bootstrapped, founder-led profile. Risk is Low because the sector does not clearly match NIS2 covered sectors, and the company likely falls below size thresholds. However, a formal assessment is recommended to confirm employee count and revenue.

Evidence: https://refiner.io/about/, https://refiner.io/security-statement/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

HIPAA (source) — Partially Compliant

Refiner explicitly offers HIPAA support and has a dedicated HIPAA compliance page, indicating they serve customers in regulated healthcare environments. As a SaaS survey tool, Refiner can be used by healthcare organizations to collect patient feedback, which may constitute Protected Health Information (PHI). The risk is Medium because: (1) HIPAA compliance for a SaaS vendor depends heavily on customer configuration and use case — Refiner provides the framework but customers must ensure proper implementation; (2) Refiner is not a US-based company, so direct HIPAA enforcement is less likely, but US healthcare customers using Refiner as a Business Associate face compliance obligations; (3) The company acknowledges HIPAA applicability but the full scope of their BAA (Business Associate Agreement) offering and technical safeguards specific to HIPAA are not fully detailed in public documentation. Status is 'Partially Compliant' as they acknowledge and support HIPAA but full independent verification is not publicly available.

Evidence: https://refiner.io/legal/hipaa/, https://refiner.io/security-statement/, https://refiner.io/legal/soc-2/

Financials

Three-year financials

Financial Resilience Score: 5/10

Refiner SAS presents a mixed financial resilience profile. On the positive side, it operates a recurring SaaS subscription model providing predictable MRR/ARR, has a diversified customer base including blue-chip names like Qonto, Razorpay, BPCE, AutoScout24, and OneFootball, and maintains a lean cost structure as a remote-first team based in Europe. Its strong compliance posture (SOC 2 Type II since 2024, GDPR, HIPAA, CCPA) creates a meaningful moat for enterprise sales and reduces churn risk. The bootstrapped, profitable-by-design micro-SaaS approach suggests disciplined financial management. However, significant risks weigh on the assessment. The company has only €1,000 in share capital with no announced external funding, providing a limited capital buffer compared to well-funded competitors like Qualtrics (public), Sprig, and Survicate. It operates in a highly competitive market with multiple better-capitalized players. Key-person risk is elevated due to single founder Moritz Dausinger acting as legal representative, and the small team concentrates operational risk. Customer concentration is likely high (typical for small SaaS), FX risk exists from global sales reported in EUR, and AI disruption could compress pricing power. No public financial data (revenue, EBIT, equity) is available to validate quantitative resilience. The score of 5 reflects qualitative strengths offset by scale limitations and disclosure gaps.

Key strengths: Recurring SaaS subscription revenue model providing predictable MRR/ARR, Diversified blue-chip customer base (Qonto, Razorpay, BPCE, AutoScout24, OneFootball), Lean cost base as remote-first European team, Strong compliance posture (SOC 2 Type II, GDPR, HIPAA, CCPA), Niche focus strategy on SaaS, fintech, edtech, marketplaces, Bootstrapped, profitable-by-design micro-SaaS profile

Risk factors: Very small scale with only €1,000 share capital and no announced external funding, Highly competitive market with better-capitalized competitors (Qualtrics, Sprig, Survicate), Key-person risk concentrated in single founder Moritz Dausinger, Likely high customer concentration in top 10-20 accounts, FX and pricing risk from global sales reported in EUR, AI disruption and commoditization from LLM-driven feedback tools and embedded CDP features

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report