Rocket.net
United States · rocket.net · 17 vendors
Resilience scores
- Digital Sovereignty: 53
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Anthropic, PBC — Technology — United States
- HubSpot, Inc. — Technology — United States
- WP Rocket — Technology — France
- and 14 more
Services catalogue
2 services in catalogue across 2 categories; runs on 17 sub-vendors.
- Managed WordPress Hosting
- Rocket.net
Insights
Last updated 2026-08-11 · revision 3
17 direct vendors, 254 subvendors
Direct vendors by controlling owner country (sample)
- Switzerland: 1
- Japan: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Bangladesh: 2
- Norway: 7
- Switzerland: 2
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Rocket.net exhibits high migration readiness, largely driven by its modern and highly programmable infrastructure. A key strength is the implementation of 'AI Hosting' with an 'official Model Context Protocol (MCP) server.' This protocol enables IDEs and AI agents to provision sites, manage domains, deploy content, and control the entire platform without manual logins, indicating a highly automated and API-driven environment. Such programmability significantly reduces the complexity and effort typically associated with migrations. The internal tech stack is modern, including Cloudflare Enterprise, NVMe SSD, Redis, and support for up-to-date PHP versions, which aligns well with contemporary cloud environments. The company's specialization in WordPress hosting also means its systems are optimized for this platform, potentially simplifying migrations within the WordPress ecosystem. However, several critical data points are missing: 'Data Residency Requirements' are not specified, which could introduce significant legal and technical challenges during migration. Information on the 'Regulatory Environment' is also absent, making it difficult to assess compliance requirements for a potential migration. Financial stability, and thus the ability to fund a large-scale migration, is unknown due to missing revenue data. The 'Vendor Lock-in Risk' is stated as 'Unknown,' and the conflicting 'Total Vendors: 0' versus 'Total Services: 38' makes it difficult to accurately assess the number of distinct vendors and the associated lock-in. While the MCP offers high flexibility, the proprietary 'Mission Control' panel could represent some platform-specific lock-in if its unique features are heavily utilized and not easily transferable to other environments. The extent of containerization or microservices adoption is not explicitly detailed, though the modern architecture suggests a predisposition towards such approaches.
Compliance
7 in-scope frameworks identified; showing 3.
PCI DSS (source) — Assessment Required
Rocket.net processes payments from customers for hosting subscriptions and accepts credit card information (explicitly mentioned in the Privacy Policy as data collected). PCI DSS applies to any organization that stores, processes, or transmits cardholder data. The risk is Medium because: (1) The company collects credit card information for billing; (2) No PCI DSS compliance attestation, SAQ, or QSA report is publicly disclosed; (3) If payment processing is fully outsourced to a PCI-compliant payment processor (e.g., Stripe, Braintree), Rocket.net's scope may be significantly reduced; (4) The Terms of Service references credit card fraud as a prohibited activity, suggesting awareness of payment security obligations. Without knowing the payment processing architecture, full compliance status cannot be determined.
Evidence: https://rocket.net/privacy-policy/, https://rocket.net/terms-of-service/, https://rocket.net/pricing/
CPRA — Partially Compliant
Rocket.net's Privacy Policy explicitly references CCPA (California SB 220) compliance, stating it is against company policy to sell personal information without consent. As a US-based company serving California residents, CCPA/CPRA applicability depends on revenue and data volume thresholds. The company acknowledges the law but the Privacy Policy does not include a dedicated 'Do Not Sell or Share My Personal Information' link, detailed CCPA-specific rights disclosures, or a CPRA-updated privacy notice. Risk is Medium because the company acknowledges CCPA but the compliance implementation appears incomplete relative to current CPRA requirements (effective January 2023).
Evidence: https://rocket.net/privacy-policy/, https://rocket.net/terms-of-service/
GDPR (source) — Partially Compliant
Rocket.net (onRocket.com, LLC) is a US-based managed WordPress hosting provider that explicitly acknowledges GDPR applicability in its Privacy Policy and Terms of Service. The company serves EU/EEA customers globally, processes personal data of EU residents, and references GDPR data subject rights (access, rectification, erasure, portability, objection). However, several compliance gaps exist: (1) The Privacy Policy references the now-invalidated EU-US Privacy Shield as a transfer mechanism alongside Standard Contractual Clauses (SCCs), which is outdated and potentially non-compliant; (2) No Data Processing Agreement (DPA) is publicly available for customers; (3) No appointed EU Data Protection Representative is publicly identified despite being required under GDPR Art. 27 for non-EU controllers targeting EU residents; (4) The Privacy Policy effective date is May 2020 and has not been visibly updated to reflect post-Schrems II transfer mechanism requirements. Risk is Medium rather than High because the company does demonstrate awareness of GDPR, enumerates data subject rights, mentions SCCs, and has a named DPO contact address, but the gaps in transfer mechanism documentation and lack of a public DPA are notable deficiencies.
Evidence: https://rocket.net/privacy-policy/, https://rocket.net/terms-of-service/, https://rocket.net/cookie-policy
Financials
Three-year financials
- 2025:
- 2024:
- 2023:
Financial Resilience Score: 6/10
Rocket.net is a privately held, founder-led managed WordPress hosting company that does not disclose audited or summary financial statements. As such, financial resilience cannot be quantitatively verified. However, structurally, the business model is attractive: recurring subscription SaaS revenue with typically high gross margins in the hosting sector, a fully remote workforce keeping fixed costs low, and a virtualized platform built on Cloudflare Enterprise that avoids heavy datacenter capex. The company has marquee reference customers (Mediavine, Ziff Davis, Atarim, AIOSEO) and strong founder domain expertise (Ben Gabler, ex-StackPath and GoDaddy). It has differentiated positioning via Cloudflare Enterprise delivery and bundled premium tools (WP Rocket, Object Cache Pro/Relay, WP Umbrella), plus an early mover position in AI-native hosting with MCP server support launched in 2026. Key risks include small scale relative to well-capitalized competitors (WP Engine, Kinsta), ~100% revenue concentration in the WordPress ecosystem (which faces pressure from Webflow, Framer, Wix, Shopify and AI site-builders), heavy dependence on the Cloudflare relationship, and reliance on aggressive promotional pricing ($1 intro offers) that could pressure unit economics if churn is elevated. The unknown capital structure — likely bootstrapped or lightly funded — is a strength for control but a risk if well-funded competitors accelerate. Overall, a moderate resilience score reflects an attractive model offset by opacity and scale disadvantages.
Key strengths: Recurring-revenue SaaS model with predictable, sticky cash flow, Differentiated product using Cloudflare Enterprise delivery layer, Marquee reference customers including Mediavine and Ziff Davis, Founder domain expertise (Ben Gabler, 20+ years hosting experience), Low fixed-cost overhead via fully remote workforce, Early mover on AI-native hosting (MCP server, LLM integrations), Bundled premium tools (WP Rocket, Object Cache Pro/Relay, WP Umbrella) at no extra cost
Risk factors: No public financial disclosure — resilience cannot be externally verified, Small scale relative to WP Engine (~$400M+ revenue) and Kinsta, ~100% revenue concentration in WordPress ecosystem, Heavy dependence on Cloudflare Enterprise relationship, Reliance on aggressive promotional pricing ($1 intro offers), Unknown capital structure — likely bootstrapped or lightly funded, Competitive pressure from Webflow, Framer, Wix, Shopify and AI site-builders
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.