Riot Games, Inc.

United States · www.riotgames.com · 47 vendors

Riot Games, Inc. is an American video game developer, publisher, and esports tournament organizer. The company is best known for developing popular online multiplayer games such as League of Legends and Valorant. They also expand their intellectual properties into multimedia projects, including the Emmy-winning animated series Arcane.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 47 sub-vendors.

Insights

Last updated 2026-03-12 · revision 1

47 direct vendors, 363 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Riot Games exhibits a very high level of migration readiness. Their extensive use of cloud-native technologies such as AWS, GCP, Kubernetes, Docker, and a robust CI/CD pipeline (Jenkins, Spinnaker) demonstrates a modern, agile, and highly portable infrastructure. The adoption of Infrastructure as Code (Terraform) further streamlines potential migrations. Their existing multi-cloud strategy and experience with distributed systems at a global scale indicate a strong capability to adapt and move workloads. The geographic diversity of their vendor base, while the exact number of vendors and lock-in risk are unknown, suggests a degree of flexibility in their external dependencies. The primary unknowns are specific regulatory and data residency requirements, and the financial capacity to fund a large migration, which prevent a perfect score.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

Riot Games has global operations including EU/EEA presence (Ireland office) and processes personal data of EU/EEA residents through their games and services. They have implemented comprehensive privacy policies, appointed a Data Protection Officer (dpo@riotgames.com), and have joint controllers arrangement with Riot Games Ltd. (Ireland) for EU operations. Medium risk due to the complexity of global gaming operations and large user base, but strong compliance framework is in place.

Evidence: https://www.riotgames.com/en/privacy-notice

SOC 2 (source) — Assessment Required

As a cloud-based gaming service provider processing customer data globally, Riot Games would benefit from SOC2 compliance to demonstrate security controls. However, no public evidence of SOC2 certification was found. Medium risk because gaming companies handling personal data and providing cloud services typically pursue SOC2 for customer assurance, but it's not legally mandated.

ISO 27001 (source) — Assessment Required

Given Riot Games' global operations, large user base, and handling of personal data, ISO 27001 certification would be expected for information security management. However, no public evidence of ISO 27001 certification was found. Medium risk because while not legally required, it's considered best practice for companies of this size and scope.

Financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report