Resiliate

Denmark · owned by Celanin ApS (Denmark) · resiliate.io · 13 vendors

Resiliate is an automated tech vendor due diligence platform focused on analysing digital sovereignty and resilience of companies and technology vendors. It helps organisations assess and build digital resilience by evaluating the sovereignty and risk posture of their technology supply chain. The platform targets enterprises seeking to understand and manage their exposure to digital dependencies.

Resilience scores

Disruption prediction

Resiliate has an estimated 99% probability of disruption in the next 6 months.

6 of Resiliate's 13 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 13 sub-vendors.

Insights

Last updated 2026-09-13 · revision 3

13 direct vendors, 266 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Resiliate's migration readiness is severely hampered by a high vendor lock-in risk, explicitly noted due to its reliance on only two vendors. This concentration of services with a limited number of providers suggests that disentangling and migrating away from these critical dependencies would be a complex, costly, and time-consuming endeavor. The assessment is further challenged by the absence of crucial data regarding Resiliate's internal tech stack (e.g., cloud-nativity, containerization, microservices adoption), which is fundamental for determining migration complexity. Additionally, the lack of information on regulatory environment, data residency requirements, and financial stability (to fund a migration) introduces significant unknowns and potential hurdles. Without clarity on these factors, particularly the high vendor lock-in, the company faces substantial challenges in any potential migration effort.

Compliance

9 in-scope frameworks identified; showing 3.

EU AI Act (source) — Assessment Required

The company's privacy policy states its service 'relies heavily on American AI and cloud service providers' and uses AI for analytics and product improvement, bringing it in scope as a deployer or provider of AI systems in the EU.

The risk depends on the classification of the AI systems used. If any are deemed 'high-risk,' non-compliance carries significant fines. Even for lower-risk systems, transparency failures can damage reputation.

Evidence: https://resiliate.io/privacy, https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai, https://www.slaughterandmay.com/insights/new-insights/the-eu-ai-act-challenges-and-questions-for-ai-providers-as-the-act-starts-to-bite/, https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dtime%2Bin%2BDenmark&q=EhAqBdAUBhsnCvd_qcYjqMRjGIODldUGIjDKJmydJYRjBzJCMY8TRQ4m3FJezp4iyTY61YmKz2nf9u7LXYqPDG5oHcn7Won-478yAnJSWgFD, https://about.citiprogram.org/blog/an-overview-of-the-eu-ai-act-what-you-need-to-know/, https://www.dpo-consulting.com/blog/eu-ai-act

SOC 2 (source) — Assessment Required

This assurance framework is critical for any company providing technology services, especially to US customers. Given Resiliate uses US-based cloud and AI providers, demonstrating SOC 2 compliance is a key market expectation.

Without a SOC 2 report, Resiliate may be unable to sell to US companies or any large enterprise that requires assurance over a vendor's controls related to security, availability, and confidentiality.

Evidence: https://resiliate.io/privacy

CER — Assessment Required

As a provider of cybersecurity services, Resiliate could be considered part of the 'digital infrastructure' sector. EU member states must identify critical entities by July 2026; applicability depends on this designation.

The primary risk is being designated as a 'critical entity' by a member state, which would impose new obligations for physical security and resilience, potentially requiring significant investment.

Evidence: https://www.critical-entities-resilience-directive.com/, https://www.pwc.com/ee/en/services/advisory-services/crisis-management/critical-entities-resilience-directive.html, https://www.dpo-consulting.com/blog/eu-ai-act, https://www.dlapiper.com/en/insights/topics/cer-critical-entities-resilience-directive, https://www.bsigroup.com/en-US/insights-and-media/insights/blogs/what-is-the-eu-critical-entities-resilience-directive-cer/, https://www.sabd.dk/l/en-tre-nye-love-traeder-i-kraft-danmark-styrker-beredskabet-og-sikkerheden-i-kritisk-infrastruktur/

Financials

Three-year financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report