SDA Company Due Diligence

Run due diligence on SDA Company: monitor compliance and get alerts when suppliers, ownership or leadership change.

Estonia · owned by Independent (Estonia) · sda.company · 17 vendors

SDA Company is a custom software development firm specializing in business automation, dashboards, AI solutions, and SaaS products for SMBs and startups. They help clients replace manual spreadsheet-based workflows with real-time dashboards and automated systems, delivering projects in 4–8 weeks. The company also offers MVP development, dedicated development teams, and IT outstaffing services across industries such as healthcare, manufacturing, logistics, and fintech.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-26 · revision 2

17 direct vendors, 246 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

SDA Company exhibits very high migration readiness, largely due to its advanced and cloud-native internal tech stack. The extensive use of AWS, Docker, Kubernetes, Jenkins, Terraform, and Ansible signifies a strong foundation in containerization, infrastructure as code, and CI/CD pipelines, which are critical enablers for seamless migrations to new environments or cloud platforms. The company's low vendor lock-in risk, stemming from a diverse base of 14 vendors, further enhances its migration flexibility by reducing dependencies and potential complexities associated with vendor-specific technologies or contracts. While specific data on regulatory environment and data residency requirements is missing, SDA's experience in developing healthcare solutions compliant with HIPAA, GDPR, and PCI standards suggests an inherent capability to navigate complex regulatory landscapes during migration. The primary limitations in fully assessing migration readiness are the absence of specific data on data residency requirements and financial stability, which could impact the scope and funding of large-scale migration initiatives. Nevertheless, the technical and vendor landscape strongly positions SDA for efficient and agile migrations.

Compliance

6 in-scope frameworks identified; showing 3.

EU AI Act (source) — Assessment Required

The company explicitly states it is an "AI-native software development company" and offers "AI Consulting for SaaS," developing AI-powered analytics platforms and solutions for healthcare and other sectors within the EU.

Developing AI for healthcare and data analytics could classify its products as high-risk AI systems. Non-compliance with the AI Act's stringent requirements for such systems would create significant legal and reputational risk.

Evidence: https://sda.company/, https://sda.company/services/, https://techbehemoths.com/company/sda-company, https://sda.company/industries/, https://edpo.com/gdpr-ai-act-dsa-what-it-means-for-non-eu-companies/, https://artificialintelligenceact.eu/

ISO 27001 (source) — Assessment Required

This is not a legal requirement but a voluntary, market-driven standard. Given the company's work with sensitive data in sectors like healthcare and fintech, customers would likely expect this level of security assurance.

For a B2B technology firm, especially one serving healthcare and fintech, ISO 27001 certification is a key market differentiator and is often expected by enterprise clients to demonstrate a commitment to information security.

Evidence: https://sda.company/about-us/, https://cybersapiens.com.au/top-10-best-iso-27001-certification-companies-in-usa/, https://certification.bureauveritas.com/needs/information-security-management-system-iso-27001-certification, https://www.dnv.us/services/iso-iec-27001-information-security-management-system-3327/, https://www.vanta.com/collection/soc-2/soc-2-report-example, https://optro.ai/blog/soc-2-framework-guide-the-complete-introduction

NIS2 (source) — Assessment Required

The company provides custom software, business automation, and SaaS app development, potentially falling under the 'digital providers' or 'ICT service management' categories. Applicability depends on whether it meets the size-cap thresholds (50+ staff or €10M+ turnover).

As a provider of digital services and ICT service management, a security incident could have significant impact. Non-compliance carries financial penalties and reputational damage, though the risk is moderate given its size.

Evidence: https://sda.company/, https://sda.company/services/, https://www.protiviti.com/us-en/whitepaper/enhancing-cybersecurity-compliance-navigating-nis2-directive, https://www.dataguard.com/nis2/, https://www.google.com/sorry/index?continue=https://www.youtube.com/watch%3Fv%3DPVAmoMFLjOU&q=EhAqBdAUBhsnC0uBY_eyjMtZGJ3D3dUGIjBrwVx914inR7z0vxtn_e7N5L5ousVLBGEUdV5OvY5xn9AfVkEoOTFwQ-yuDRj-ioUyAnJSWgFD, https://optro.ai/blog/iso-27001-certification-requirements

Financials

Three-year financials

Financial Resilience Score: 5/10

Serious Development Agency OÜ is a micro-enterprise with a clean compliance record: all annual reports for 2023-2025 have been filed on time, VAT registration has been active since inception, and there are no court decisions, bailiff proceedings, commercial pledges, or recorded debts. Its Inforegister credit score is classed as 'Trustworthy (0.01)' with a recommended credit limit of EUR 24,400 (July 2026). Revenue is stable and recurring, with quarterly turnover held in a tight EUR 315k-387k band from Q2 2025 through Q2 2026, suggesting retainer-type engagements rather than lumpy one-off deals. However, resilience is materially constrained by scale and structure. Full-year turnover of ~EUR 1.37M and a balance sheet total under EUR 50k make this a micro-enterprise below Estonian audit thresholds. Registered share capital is only EUR 2,500 and analytical net asset value is under EUR 90k, leaving a very thin buffer against bad debts or project write-offs. Inforegister's forward model projects negative earnings per employee in both 2025 and 2026 (EUR -10,307 per employee in 2026). Key-person risk is extreme, with a single Ukrainian founder as sole owner and sole board member, and delivery is concentrated in the Ukrainian R&D team (historically Kharkiv), creating ongoing exposure to the Russia-Ukraine war including personnel safety, power outages, mobilisation, and payment friction. Zero labour taxes paid in Estonia confirm that operational staff sit outside the EU parent jurisdiction.

Key strengths: Clean compliance record - all annual reports filed on time (2023, 2024, 2025), No court decisions, bailiff proceedings, commercial pledges, or recorded debts, Inforegister credit score 'Trustworthy (0.01)', VAT-active since incorporation (Nov 2021), Stable recurring quarterly revenue (EUR 315k-387k band across 5 quarters), AWS Select Partner and multiple Clutch awards, AI-native positioning around Cursor/Claude Code differentiator

Risk factors: Micro-enterprise scale (~EUR 1.37M turnover, balance sheet <EUR 50k), Very thin equity buffer (share capital EUR 2,500; analytical NAV <EUR 90k), Forecast losses (negative EUR 10,307 earnings per employee in 2026), Sole owner and sole board member - extreme key-person risk, Ukraine R&D exposure to ongoing war (safety, power, mobilisation, payments), Zero labour taxes paid in Estonia - delivery workforce outside EU parent jurisdiction, Accounts not independently audited (below Estonian audit thresholds), Q1 2026 national taxes fell ~61% QoQ before rebounding, No public segment or geographic revenue disclosure

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report