Rulemailer
Denmark · www.rulemailer.com · 15 vendors
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Magento — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- Usercentrics GmbH — Technology — Germany
- and 12 more
Services catalogue
2 services in catalogue across 1 category; runs on 15 sub-vendors.
- Email Marketing
- Rulemailer
Insights
Last updated 2026-07-15 · revision 2
15 direct vendors, 191 subvendors
Direct vendors by controlling owner country (sample)
- India: 2
- Denmark: 1
- United States: 9
Subvendors by controlling owner country (sample)
- Argentina: 1
- Australia: 3
- United States: 131
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Rulemailer's migration readiness is assessed as medium-low, primarily due to significant unknowns and potential architectural challenges. A key strength is the presence of a robust "Rule REST API (v2/v3)" and "Webhooks", indicating strong integration capabilities that could facilitate modular migration of services and data. Existing "GDPR-Compliant Data Processing" is also a positive, as it means foundational data privacy practices are in place, which are critical for any data-intensive migration. However, several factors significantly reduce readiness. The internal tech stack includes "WordPress (Elementor)", which typically suggests a more traditional, potentially monolithic architecture rather than a cloud-native or microservices approach, making refactoring for cloud migration more complex. A critical unknown is "Data Residency Requirements: Not specified"; if strict requirements exist, this could severely complicate migration, especially to global cloud providers. There is also no data on financial stability (revenue concentration, growth history), making it impossible to assess the company's capacity to fund a potentially costly migration. The "Vendor Lock-in Risk" is "Unknown", and the contradictory vendor data (0 total vendors vs. 16 services with diverse vendor countries) creates ambiguity regarding the complexity of disentangling from existing service providers. The geographic diversity of service providers, while good for resilience, could add coordination complexity during a migration.
Compliance
7 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
GDPR risk is inherently High for a MarTech/SaaS company like Rule Communication Nordic AB because: (1) The company's core business model is built on processing personal data at scale — email addresses, mobile numbers, behavioral data, IP addresses, geographic locations, and customer profiles — both as a data controller (own customers/users) and as a data processor (on behalf of 3,500+ client companies); (2) As a data processor for thousands of businesses, any compliance gap creates cascading liability across the entire customer base; (3) GDPR fines can reach up to €20M or 4% of global annual turnover; (4) Sweden's supervisory authority (IMY - Integritetsskyddsmyndigheten) has an active enforcement record; (5) The company's privacy policy references the Privacy Shield agreement (which was invalidated by Schrems II in 2020), suggesting the policy may not be fully up to date with current transfer mechanisms (SCCs/adequacy decisions); (6) The company processes data for clients in banking, e-commerce, healthcare-adjacent sectors, and other sensitive industries, amplifying risk. Partial compliance is assessed because the company has published a DPA, privacy policy, and references GDPR compliance, but the outdated Privacy Shield reference and absence of a publicly named DPO raise concerns.
Evidence: https://www.rule.io/rule-personal-data-assistant-agreement/, https://www.rule.io/rule-communication-nordic-ab-policy-for-data-management-and-cookies/, https://www.rule.io/rule-data-processing-agreement/, https://www.rule.se/rule-personuppgiftsbitradesavtal/, https://www.imy.se/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
NIS2 (source) — Assessment Required
NIS2 risk is assessed as Low for the following reasons: (1) Rule Communication Nordic AB has approximately 30+ employees as publicly stated on their About page, which is below the NIS2 medium enterprise threshold of 50 employees; (2) While the company is a digital service provider (SaaS/cloud platform), NIS2 Annex II lists 'digital providers' (online marketplaces, online search engines, social networking platforms) and 'ICT service management' as Important Entities, but the size exemption for micro and small enterprises (fewer than 50 employees AND annual turnover/balance sheet below €10M) typically excludes companies of this size; (3) However, exact annual turnover is not publicly disclosed, creating some uncertainty; (4) If the company exceeds €10M annual turnover (possible given 3,500+ customers), both thresholds must be met for the SME exemption to apply; (5) Sweden has transposed NIS2 via the Cybersäkerhetslag (2024:1226), effective January 2025, with IMY and NCSC-SE as relevant authorities. Assessment Required because turnover data is not publicly available to confirm SME exemption.
Evidence: https://www.rule.io/about-rule/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.msb.se/sv/amnesomraden/informationssakerhet-cybersakerhet-och-sakra-kommunikationer/nis2/, https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/cybersakerhetslag-20241226_sfs-2024-1226/
ISO 27001 (source) — Assessment Required
ISO 27001 risk is Medium because: (1) Rule Communication Nordic AB processes large volumes of personal data and customer data as a SaaS provider, making information security management critically important; (2) No ISO 27001 certification has been found, meaning the company lacks independently verified information security controls; (3) The absence of ISO 27001 is a gap for enterprise procurement, particularly in regulated industries (banking, finance, healthcare) where the company actively markets its services; (4) Risk is Medium rather than High because ISO 27001 is voluntary in the EU (not legally mandated), and GDPR Article 32 security obligations can be met through other means; (5) The company's DPA commits to technical and organizational security measures, but without ISO 27001 certification, these are self-declared; (6) A security breach without ISO 27001 controls could result in significant GDPR fines and reputational damage.
Evidence: https://www.rule.io/rule-personal-data-assistant-agreement/, https://www.iso.org/standard/27001, https://www.rule.se/branscher/rule-for-bank-finanssektorn/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Rule Communication Nordic AB (operating rulemailer.com/rule.io) demonstrates qualitative signals of financial health despite the absence of publicly verified financial figures in this research. The company has been recognized as a Dagens Industri 'Master Gasell' for three consecutive years, an audited award requiring roughly doubled revenue over four years, positive operating results, and organic growth. Combined with a long operating history since 2007, a claimed 3,500+ customer base, and credible Nordic e-commerce logos (A Day's March, Desenio, Hestra, Orrefors, Craft, PriceRunner), this points to a healthy, growing, profitable Nordic SaaS SME. The recurring SaaS subscription model provides predictable cash flow and stickiness, further reinforced by 100+ integrations (Shopify, WooCommerce, Magento, Zapier, Meta, Google) that create switching costs. Product breadth across email, SMS, RCS, and marketing automation increases ARPU and reduces single-product churn risk. However, resilience is capped by structural risks: small headcount (~30) creates key-person dependency, development capacity is outsourced to Vilmate LLC in Kharkiv, Ukraine (exposing the company to war-related operational and cyber risk), and the company competes against much larger, better-funded rivals like Klaviyo, Mailchimp, Voyado, ActiveCampaign, and Braze that could compress pricing. Geographic concentration in the Nordics also limits diversification. Exact revenue, EBIT, and equity figures were not verifiable in this session and would need to be pulled from Bolagsverket/allabolag.se filings.
Key strengths: Recurring SaaS subscription revenue model with predictable cash flow, DI Master Gasell award three consecutive years (audited high-growth recognition), Long operating history since 2007, 3,500+ customers claimed with credible Nordic e-commerce logos, Multi-product platform (email, SMS, RCS, marketing automation) increases ARPU, 100+ integrations create switching costs
Risk factors: Small headcount (~30 employees) creates key-person dependency, Development outsourced to Vilmate LLC in Kharkiv, Ukraine — war-related operational and cyber risk, Highly competitive MarTech space vs. Klaviyo, Mailchimp, Voyado, ActiveCampaign, Braze, Geographic concentration in the Nordics limits diversification, Private ownership with limited financial transparency
Workforce by country
- Sweden: 22
- Ukraine: 9
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.