Resend Labs, Inc.

United States · owned by Independent (United States) · resend.com · 31 vendors

Resend is an email API and platform for developers, enabling them to build, test, and send transactional and marketing emails at scale. The company focuses on providing a strong developer experience, ensuring email deliverability, and offering features like React-based email templating.

Resilience scores

Technology vendors

Services catalogue

5 services in catalogue across 2 categories; runs on 31 sub-vendors.

Insights

Last updated 2026-07-02 · revision 7

31 direct vendors, 303 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Resend Labs exhibits high migration readiness, primarily driven by its modern and cloud-native technology stack. The use of Amazon Web Services (AWS) as the primary hosting provider, coupled with infrastructure-as-code tools like AWS CDK and Terraform, enables agile and efficient infrastructure management, making potential migrations to different AWS regions or even other cloud providers more feasible. Their internal tech stack, including TypeScript, Golang, PostgreSQL, and Apache Kafka, consists of widely adopted and portable technologies. The company's strong financial position, evidenced by a recent Series A funding round, provides the necessary resources to fund and execute a significant migration effort if required. From a regulatory perspective, existing compliance with GDPR and SOC 2 Type II, along with certification under the EU-U.S. Data Privacy Framework (DPF) and UK Extension, provides a solid foundation for maintaining compliance during and after a migration. However, data residency requirements, with primary storage in the United States and all subprocessors being US-based, could introduce complexity for customers with strict data localization needs if a migration involves moving data outside the US. The 'Vendor Lock-in Risk' is explicitly 'Unknown', and the contradictory 'Total Vendors: 0' alongside 'Total Services: 46' makes it difficult to fully assess vendor-specific lock-in. While there's an inherent platform dependency on AWS, the use of open standards and IaC mitigates this to some extent. The absence of ISO 27001 certification could also be a minor hurdle for certain enterprise migration requirements. Overall, the modern architecture and operational practices position Resend Labs well for future migrations.

Compliance

6 in-scope frameworks identified; showing 3.

CCPA — Compliant

Resend is headquartered in San Francisco, California, making CCPA directly applicable. The company has explicitly addressed CCPA obligations in its DPA (Section 2.5), confirming its role as a 'service provider' under CCPA, committing not to sell personal information, and restricting use of personal data to service provision purposes. Risk is Low because: (1) CCPA compliance is explicitly documented in the DPA; (2) Resend's role as a service provider (not a business selling data) limits CCPA exposure; (3) the company has implemented appropriate contractual and technical controls.

Evidence: https://resend.com/legal/dpa, https://resend.com/legal/privacy-policy

ISO 27001 (source) — Assessment Required

No evidence of ISO 27001 certification was found for Resend Labs, Inc. (Plus Five Five, Inc.). However, the risk is Low because: (1) Resend has achieved SOC 2 Type II, which covers overlapping information security management controls; (2) Resend's DPA Exhibit C notes that their infrastructure providers (cloud hosting) are audited for ISO 27001 compliance; (3) ISO 27001 is not legally mandated for email service providers in the US; (4) Resend's security program documentation demonstrates mature security governance practices consistent with ISO 27001 principles. The absence of ISO 27001 certification is a gap for enterprise customers requiring it, but does not represent a regulatory compliance failure.

Evidence: https://resend.com/security, https://resend.com/security/soc-2, https://resend.com/legal/dpa

GDPR (source) — Compliant

Resend explicitly self-declares GDPR compliance and has invested over 12 months in compliance efforts. They operate as a data processor under Article 28 GDPR, serving a global customer base that includes EU/EEA residents and businesses. Risk is Medium rather than Low because: (1) Resend is a US-based company storing data primarily in the United States, meaning cross-border data transfers are inherent to their model; (2) self-audited GDPR compliance (not independently certified) introduces residual risk; (3) as an email infrastructure provider, they process large volumes of personal data (email addresses, message content, IP addresses, tracking data) on behalf of customers, amplifying the potential impact of any compliance gap; (4) enforcement by EU supervisory authorities against US-based processors has increased. Mitigating factors include: published DPA with EU SCCs, EU-U.S. Data Privacy Framework certification, Vanta-monitored controls, and a published subprocessor list.

Evidence: https://resend.com/security/gdpr, https://resend.com/legal/dpa, https://resend.com/legal/subprocessors, https://www.dataprivacyframework.gov/

Financials

Three-year financials

Financial Resilience Score: 6/10

Resend Labs is a private, venture-backed developer-tools startup that does not disclose revenue, operating income, or equity. Assessment relies on qualitative signals rather than audited financials. The company has raised approximately US $24 million cumulatively (seed $3M in 2023, Series A $18M in Dec 2024 led by Andreessen Horowitz, and an additional $3M in Oct 2025), providing reasonable but not extensive capital runway for a ~43-person team in an infrastructure-heavy business. Strengths supporting resilience include top-tier VC backing (a16z, Y Combinator, SV Angel), a marquee angel roster (founders/execs from Vercel, Figma, Sentry, Supabase, PostHog, WorkOS, Mailchimp), explosive user growth (6k waitlist in early 2023 to 3M users by June 2026), a product-led growth engine anchored by the React Email open-source library (300k+ weekly npm downloads), enterprise-ready compliance (SOC 2 Type II, GDPR), marquee logos (Warner Brothers, Decathlon, Vercel, Raycast, Supabase), and cash strength sufficient to complete two acquisitions (Mergent Apr 2025, Briefer Aug 2025). Key risks include the absence of any public financial data (revenue scale, gross margin, burn, and runway cannot be verified), intense competition from entrenched incumbents (SendGrid/Twilio, Postmark, Mailgun/Sinch, Amazon SES, Loops, Mailtrap), deliverability/blocklisting incidents that have occurred multiple times (Jan/Feb 2024, Nov 2025, Feb 2026) posing existential/reputational risk, heavy concentration on a single core product line, and a moving regulatory target with tightening bulk-sender rules from Gmail, Yahoo, and Microsoft.

Key strengths: ~US $24M cumulative equity funding raised (seed 2023, $18M Series A 2024, $3M 2025), Top-tier VC backing led by Andreessen Horowitz and Y Combinator, Strong angel roster from Vercel, Figma, Sentry, Supabase, PostHog, Mailchimp, WorkOS, Explosive user growth: 100k (Apr 2024) to 3M (Jun 2026), React Email open-source funnel with 300k+ weekly npm downloads, SOC 2 Type II and GDPR compliance achieved, Marquee customers including Warner Brothers, Decathlon, Vercel, Raycast, Supabase, Two acquisitions completed in 2025 (Mergent, Briefer) indicating cash strength, Named to Redpoint InfraRed 100 (Jun 2024)

Risk factors: No public financials — revenue, EBIT, equity, burn, and runway unknown, Intense competition from SendGrid/Twilio, Postmark, Mailgun, Amazon SES, Repeated deliverability/outage incidents (Jan 2024, Feb 2024, Nov 2025, Feb 2026), Heavy product concentration on transactional/marketing email API, Regulatory/deliverability moving target (Gmail, Yahoo, Microsoft bulk-sender rules), Small headcount (~43) supporting infrastructure-heavy business, Series A vintage Dec 2024 — runway dependent on undisclosed revenue traction

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report