Safewhere A/S
Denmark · owned by Gaia HoldCo A/S (Denmark) · safewhere.com · 19 vendors
Safewhere A/S is a Danish software provider specializing in Identity and Access Management (IAM) and Identity as a Service (IDaaS). The company offers cloud-based and on-premises solutions for single sign-on, multi-factor authentication, monitoring, and access governance, enabling organizations to securely connect users to applications. Safewhere has been selected as the national standard for inter-government federation in Denmark and serves both public and private sector clients.
Resilience scores
- Digital Sovereignty: 32
- Digital Resilience: 7
- Financial Resilience: 5
Technology vendors
- Centric — Technology — Netherlands
- Meta Platforms, Inc. — Technology — United States
- Rain-Task Limited — Technology — United Kingdom
- and 18 more
Services catalogue
1 service in catalogue across 1 category; runs on 19 sub-vendors.
- Identify
Insights
Last updated 2026-09-13 · revision 2
19 direct vendors, 162 subvendors
Direct vendors by controlling owner country (sample)
- Netherlands: 2
- United States: 5
- United Kingdom: 6
Subvendors by controlling owner country (sample)
- Denmark: 3
- Sweden: 6
- UK: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Safewhere A/S exhibits high migration readiness, scoring 80. A primary strength is their core product offering, 'Safewhere Identify,' which is an Identity as a Service (IDaaS) platform. This strongly indicates a cloud-native architecture and existing operational experience within a cloud environment, making further migration or cloud optimization highly feasible. The platform's support for open standards such as SAML 2.0, OAuth 2.0, and OpenID Connect further reduces vendor lock-in at the application level and facilitates integration with diverse systems. Their data residency requirement for Microsoft Azure data centers in the EU is clearly defined, simplifying migration planning by providing a known and compliant target environment. The positive revenue growth from 2021 to 2022 suggests financial stability and the capacity to fund migration initiatives. Furthermore, their existing strong regulatory compliance (GDPR, ISO 27001, NemLog-in3) means robust processes are already in place, providing a clear framework for ensuring any migration remains compliant. While the data states 'Total Vendors: 0', implying minimal direct vendor lock-in, the reliance on Microsoft Azure for data centers represents a form of vendor dependency. However, the geographic diversity of 'Vendor HQ Countries' for the '17 services' (7 unique countries) suggests a diversified ecosystem, mitigating broader vendor lock-in concerns. The specific internal architecture details (e.g., extensive containerization or microservices adoption beyond the IDaaS offering) are not explicitly stated, which is a minor area of unknown, but the IDaaS nature strongly implies modern architectural practices.
Compliance
7 in-scope frameworks identified; showing 3.
Danish Act on Data Security — Assessment Required
Denmark's Data Protection Act (Databeskyttelsesloven, Act No. 502 of 23 May 2018) supplements GDPR with national specifications, including stricter rules for processing sensitive personal data, criminal liability provisions, and specific rules for public authorities. As Safewhere processes identity data for Danish public sector entities (municipalities), compliance with the Danish Data Protection Act is mandatory alongside GDPR. Datatilsynet actively enforces both GDPR and the national act. Risk is Medium because violations can result in criminal prosecution in addition to GDPR administrative fines.
Evidence: https://www.datatilsynet.dk/english, https://www.retsinformation.dk/eli/lta/2018/502, https://safewhere.com
ISAE 3000 (source) — Assessment Required
ISAE 3000 is relevant for companies that provide assurance reports to third parties about their controls and processes — commonly used by Danish IT service providers and cloud operators as an alternative or complement to SOC 2. Danish public sector procurement often requires ISAE 3402 (a subset of ISAE 3000 for service organizations) or ISAE 3000 reports. Given Safewhere's public sector client base (Danish municipalities, Danish Environmental Portal), there is a moderate possibility that ISAE 3000/3402 reports are required by clients. However, no public evidence of such reports has been found. Risk is Low because ISAE 3000 is not a legal requirement, though its absence may affect public sector procurement eligibility.
Evidence: https://safewhere.com, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits
GDPR (source) — Assessment Required
Safewhere A/S is headquartered in Denmark, an EU member state, making GDPR unconditionally applicable. As an Identity and Access Management (IAM) provider, Safewhere processes personal data at its core — including employee identities, customer identities, and end-user authentication data for clients such as Danish municipalities and the Danish Environmental Portal (200,000+ user identities). This places Safewhere in a dual role: as a data controller for its own operations and as a data processor for its clients. Non-compliance risks include fines of up to €20 million or 4% of global annual turnover under Article 83(5), plus reputational damage in a sector where trust is paramount. The company's website references GDPR compliance features in its product ('Reports & GDPR'), suggesting awareness, but no formal DPO appointment, GDPR audit, or Article 30 records have been publicly confirmed. Enforcement by Datatilsynet (the Danish DPA) is active and well-documented.
Evidence: https://safewhere.com, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679, https://www.datatilsynet.dk/english
Financials
Three-year financials
- 2025: gross profit DKK 797K, equity DKK 11.1M
- 2024: gross profit DKK 3.52M, equity DKK 9.85M
- 2023: gross profit DKK 5.04M, EBIT DKK 5.04M, equity DKK 6.84M
Financial Resilience Score: 5/10
Safewhere A/S operates as a niche Danish IAM (Identity and Access Management) specialist with a sticky public-sector customer base, including Danmarks Miljøportal (200,000+ users across 98 municipalities) and the Municipality of Halsnæs. Identity infrastructure carries very high switching costs, which supports recurring revenue streams and low customer churn. Regulatory tailwinds from GDPR, NIS2, and eIDAS 2.0 in the EU are driving IAM demand, particularly for Danish public entities requiring MitID/NemLog-in integrations where Safewhere has domain expertise. However, the company faces significant structural risks. Competitive pressure from hyperscalers—particularly Microsoft Entra ID bundled with Microsoft 365—represents a major threat as Entra is the default IAM for most Danish organisations. As a small niche Danish A/S, Safewhere's revenue is likely modest (typical peers generate low double-digit million DKK), limiting R&D capacity relative to global competitors like Okta, Microsoft, and Ping. Customer concentration risk is inferable from marketing references relying on a small number of large Danish public-sector accounts, and there is limited international/FX diversification with primarily DKK-denominated exposure. Quantitative financial data (revenue, EBIT, equity) could not be verified from CVR filings in this analysis, so the resilience score reflects qualitative assessment only and carries uncertainty.
Key strengths: Sticky public-sector customer base with high switching costs in Danish municipalities, Regulatory tailwind from GDPR, NIS2, and eIDAS 2.0 driving IAM demand, Domain expertise in Danish MitID/NemLog-in public-sector federations, Product focus on IAM enables depth competition against larger global players, Recurring revenue model from identity infrastructure
Risk factors: Competitive pressure from Microsoft Entra ID bundled with Microsoft 365, Small scale limits R&D capacity relative to global IAM competitors, Customer concentration in a small number of large Danish public-sector accounts, Limited geographic diversification with primarily DKK/Denmark exposure, Competition from global IAM vendors (Okta, Microsoft, Ping)
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Safewhere Identify (IAM/SSO/MFA platform): 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.