Report-URI.io
United Kingdom · report-uri.io · 14 vendors
Report URI is a cybersecurity platform that helps website operators deploy and monitor cutting-edge browser security controls. It provides real-time monitoring and reporting on security issues detected by web browsers, protecting against data breaches, hacks, and various client-side attacks like Magecart and cross-site scripting. The platform aids in compliance with standards like PCI DSS and offers threat intelligence.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Fastmail Pty Ltd — Technology — Australia
- HubSpot, Inc. — Technology — United States
- Tealium — Technology — United States
- and 11 more
Services catalogue
2 services in catalogue across 2 categories; runs on 14 sub-vendors.
- CSP Reporting
- Report-URI
Insights
Last updated 2026-08-16 · revision 2
14 direct vendors, 170 subvendors
Direct vendors by controlling owner country (sample)
- United States: 12
- Australia: 1
- Canada: 1
Subvendors by controlling owner country (sample)
- Ireland: 2
- Germany: 4
- Australia: 3
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Report-URI.io exhibits a high degree of migration readiness, largely attributable to its modern and flexible technology stack. The use of a CDN, webhook-based integrations, REST API, and a real-time telemetry pipeline suggests an architecture that is likely distributed and adaptable. The capability to offer "dedicated infrastructure option for Enterprise customers (geographic hosting)" strongly indicates that their platform is designed for portability and can be deployed in various environments, which is a critical enabler for migration. Their deep integration with browser-native reporting standards and HTTP security headers also points to a standards-compliant approach that generally reduces migration friction. The vendor relationship data, while contradictory ("Total Vendors: 0" vs. "Vendor HQ Countries"), suggests a scenario of either minimal direct vendor dependencies or a diverse set of underlying service providers across three countries (United States, Australia, Canada). If "Total Vendors: 0" is interpreted as minimal direct vendor lock-in, this significantly boosts migration readiness. Even if they rely on services from the listed countries, the geographic diversity is a positive. The "Vendor Lock-in Risk: Unknown" prevents a definitive assessment, but the overall picture points to flexibility. A significant factor influencing migration is their adherence to "PCI DSS 4.0 Compliance Suite." While a strength for security, migrating a PCI-compliant system requires meticulous planning and execution to maintain compliance, potentially adding complexity and cost. However, the fact that they already manage this compliance suggests they have the necessary processes and expertise. Data residency requirements are "Not specified," but their ability to offer geographic hosting implies they can address such needs if they arise during a migration. Financial stability data (revenue concentration, growth history) is missing, which prevents an assessment of their capacity to fund a potentially complex migration project. Given the modern, portable tech stack, implied low vendor lock-in, and existing compliance expertise, despite the potential complexity of PCI DSS migration and missing financial data, a migration readiness score of 80 is warranted.
Compliance
6 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is the international standard for Information Security Management Systems (ISMS). It is highly relevant for cybersecurity SaaS providers like Report URI, particularly those serving regulated industries. The homepage lists 'ISO 27001' as one of the compliance standards the platform helps customers address, but no ISO 27001 certificate for Report URI itself is publicly available. The Security & Compliance page lists a 2025 Penetration Test Report and PCI DSS SAQ A AoC, but no ISO 27001 certificate. Risk is Medium because: (1) enterprise customers in banking, healthcare, and government typically require ISO 27001 certification from security vendors; (2) the absence of certification may limit enterprise sales opportunities; (3) the company demonstrates strong security practices (pen testing, minimal data collection, secure architecture) that are consistent with ISO 27001 controls but formal certification has not been evidenced.
Evidence: https://report-uri.com/security-and-compliance, https://report-uri.com/, https://cdn.report-uri.com/pdf/Report URI - 2025 Penetration Test Report.pdf
PCI DSS (source) — Partially Compliant
PCI DSS is highly relevant to Report URI in two distinct ways: (1) As a merchant/service provider processing payment card data for its own subscription payments — Report URI has published a PCI DSS SAQ A AoC (2026), indicating it qualifies as a SAQ A merchant (card data fully outsourced to Stripe, no direct card data handling). This is the lowest-risk PCI DSS merchant category. (2) As a technology solution provider helping customers meet PCI DSS 4.0 requirements 6.4.3 and 11.6.1 (client-side script management and integrity monitoring) — this is a core commercial proposition. Risk is Medium rather than Low because: (1) the SAQ A AoC covers Report URI as a merchant but does not address its status as a PCI DSS service provider to customers; (2) customers using Report URI for PCI DSS compliance may require Report URI to appear on Visa/Mastercard's lists of compliant service providers or provide a full SAQ D/ROC; (3) the distinction between merchant compliance and service provider compliance requires clarification.
Evidence: https://report-uri.com/security-and-compliance, https://cdn.report-uri.com/pdf/Report URI - PCI DSS SAQ A 2026.pdf, https://report-uri.com/solutions/pci-dss-compliance, https://report-uri.com/pci-dss
GDPR (source) — Partially Compliant
Report URI Ltd is a UK-registered company (post-Brexit, subject to UK GDPR via the Data Protection Act 2018) that explicitly acknowledges both UK GDPR and EU GDPR applicability in its Privacy Policy. The company processes personal data of EU/EEA residents (customers across the EU) and has executed Standard Contractual Clauses (SCCs) with third-party processors for cross-border data transfers. The company demonstrates strong privacy-by-design principles (minimal data collection, essential-only cookies, no cookie consent banner needed, password hashing, IP address discarding). However, the status is 'Partially Compliant' rather than 'Compliant' because: (1) no formal DPO appointment is publicly disclosed; (2) the company acknowledges that customers acting as Controllers using Report URI as a Processor must separately execute a Data Processing Agreement (DPA), meaning compliance depends partly on customer action; (3) some third-party processors (Cloudflare, DigitalOcean, Sendgrid, HubSpot, Microsoft Azure) operate outside the UK/EEA, relying on SCCs and a Transfer Impact Assessment. Risk is Medium rather than High because the company processes very limited personal data (primarily email addresses), has demonstrated proactive GDPR awareness, and the ICO (UK regulator) is the primary supervisory authority. Fines under UK GDPR are capped at £17.5M or 4% of global annual turnover.
Evidence: https://report-uri.com/privacy-policy, https://report-uri.com/security-and-compliance, https://cdn.report-uri.com/pdf/Report URI - Data Protection (1v04).pdf, https://cdn.report-uri.com/pdf/Report URI - Data Protection Analysis (1v5R).pdf, https://ico.org.uk/make-a-complaint/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Report URI Ltd. is a UK-based private SaaS company operating in the client-side web security space with a recurring subscription revenue model and a blue-chip customer base including Monzo, NatWest, RBS, Tesco Bank, Square, Okta, Pfizer, Emirates, and NHS England. The business benefits from an inherently high-gross-margin architecture (browser-native CSP reporting rather than agents/proxies) and a significant regulatory tailwind from PCI DSS 4.0 requirements 6.4.3 and 11.6.1 (effective 31 March 2025), which mandate client-side script inventory and integrity monitoring for card-accepting websites. Operating metrics are strong: 42,000+ websites monitored, 700M+ browser events processed daily, and 1,000+ high-traffic paying websites. However, financial resilience cannot be fully assessed because Report URI Ltd. almost certainly files under UK small/micro-entity exemptions, meaning revenue, EBIT, and detailed P&L are not publicly disclosed. The company faces competitive pressure from well-funded vendors including Akamai, Human Security (PerimeterX), Jscrambler, c/side, Feroot, and Cloudflare, all of which can bundle client-side security into broader platforms. Key-person risk around the founder and a small team, along with dependency on CSP and browser-native reporting standards, add further risk. The 2024 governance step-up (appointment of Paul Oggelsby as Chair, plus senior hires in engineering, sales, and marketing) suggests operational maturation but does not substitute for transparent financial disclosure.
Key strengths: Recurring SaaS subscription revenue model with tiered pricing ($54.99–$274.99/month plus Enterprise), Blue-chip enterprise customer base across UK, US, EU, Australia, and Middle East, PCI DSS 4.0 regulatory tailwind (mandatory client-side script monitoring from March 2025), High-margin architecture using browser-native CSP reporting (low marginal cost per customer), Founder-led with recognised industry credibility (Scott Helme, Troy Hunt as investor), Governance maturation in 2024 with Board Chair appointment and senior hires, 10-year operating history with progressive product diversification (CSP, DMARC, Threat Intelligence)
Risk factors: Financial opacity — no public disclosure of revenue, margin, or profitability under UK small/micro-entity exemptions, Key-person risk from small, founder-led team, Competitive pressure from larger vendors (Akamai, Human Security, Jscrambler, Cloudflare, c/side, Feroot), Standards-dependence on CSP and browser-native reporting APIs, Product concentration weighted toward CSP-driven use cases despite diversification efforts, Limited external visibility into cash runway and credit profile
Revenue by geography
- Australia: 0%
- Middle East: 0%
- United States: 0%
- United Kingdom: 0%
- Continental Europe: 0%
Revenue by product/service
- CSP Violation Reporting (core): 0%
- Email Security (DMARC, MTA-STS/SMTP TLS): 0%
- Adjacent Security Reporting (HPKP, Certificate Transparency, COOP/COEP, NEL): 0%
- Active Enforcement Suite (Script Watch, Data Watch, Frame Watch, Policy Watch, Threat Intelligence): 0%
Workforce by country
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.