SelectSoftware Reviews

United States · www.selectsoftwarereviews.com · 12 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 12 sub-vendors.

Insights

Last updated 2026-08-17 · revision 2

12 direct vendors, 186 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The company demonstrates medium migration readiness, scoring 55 out of 100. A significant strength is its internal tech stack, which is almost entirely composed of modern, cloud-based SaaS platforms such as Webflow, GitHub Pages, YouTube, and Luma. This eliminates the challenges associated with migrating legacy on-premise infrastructure or monolithic applications, as the company is already operating in a highly distributed, cloud-leveraged environment. The absence of specified data residency requirements also simplifies potential migration efforts. However, several factors temper the readiness score. While the SaaS-heavy architecture avoids legacy migration issues, it introduces vendor lock-in to specific platforms. Migrating core functionalities, such as the website and CMS from Webflow, or event management from Luma, to alternative providers would involve considerable effort in data export, content re-platforming, and re-integration, despite the underlying infrastructure being managed by the vendors. The "Total Vendors: 0" is misleading given the "Total Services: 17" and the explicit tech stack, which clearly indicates reliance on multiple implicit vendors. The lack of information regarding the regulatory environment and financial stability (revenue concentration, growth history) makes it impossible to assess potential compliance hurdles or the company's capacity to fund a significant migration initiative. The unknown vendor lock-in risk further complicates a precise assessment of migration flexibility.

Compliance

7 in-scope frameworks identified; showing 3.

CPRA — Assessment Required

CCPA/CPRA risk is High because: (1) SSR is headquartered in Cambridge, MA but operates a national digital platform serving US consumers, including California residents — CCPA applies to businesses that collect personal information from California residents regardless of where the business is headquartered; (2) SSR collects personal data from 1M+ annual users and 150,000+ newsletter subscribers, a significant portion of whom are likely California residents given California's large HR/tech workforce; (3) SSR's business model involves sharing personal data with vendor partners for advertising purposes — this may constitute 'selling' or 'sharing' personal information under CCPA/CPRA, triggering opt-out rights; (4) CPRA (effective January 1, 2023) expanded CCPA requirements and created the California Privacy Protection Agency (CPPA) with active enforcement authority; (5) CCPA thresholds: applies to businesses with annual gross revenues over $25M, OR that buy/sell/share personal information of 100,000+ consumers/households annually, OR derive 50%+ of annual revenues from selling/sharing personal information. SSR likely meets the 100,000+ consumers threshold given 1M+ annual users; (6) Fines up to $7,500 per intentional violation. Risk is High due to likely threshold applicability, active enforcement environment, and SSR's data-sharing business model.

Evidence: https://www.selectsoftwarereviews.com/advertise-with-us, https://www.selectsoftwarereviews.com/privacy-policy, https://www.selectsoftwarereviews.com/about-us, https://cppa.ca.gov/regulations/, https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.100

GDPR (source) — Assessment Required

SSR is a US-based company (Cambridge, MA) with no confirmed EU/EEA establishment. However, GDPR risk is Medium rather than Low because: (1) SSR's newsletter has 150,000+ subscribers and their advertise page states '93% US-based' — implying up to 7% (~10,500+) may be non-US, potentially including EU/EEA residents; (2) SSR covers global HR software topics (EOR services, global payroll) and likely attracts EU-based HR professionals to its website and newsletter; (3) SSR collects personal data (email addresses, contact form submissions, behavioral tracking via cookies) from website visitors globally; (4) SSR's vendor advertising model involves sharing lead/contact data with HR software vendors, some of which may be EU-based; (5) GDPR fines can reach €20M or 4% of global annual turnover. The risk is Medium (not High) because SSR is a small company with limited EU footprint, primarily US-focused audience (93% US per their own data), and enforcement against small US media companies without EU establishment is less common. However, the extraterritorial scope of GDPR Article 3(2) — which applies to non-EU companies offering goods/services to EU residents or monitoring their behavior — likely triggers applicability given SSR's global web presence and newsletter.

Evidence: https://www.selectsoftwarereviews.com/about-us, https://www.selectsoftwarereviews.com/advertise-with-us, https://www.selectsoftwarereviews.com/privacy-policy, https://gdpr-info.eu/art-3-gdpr/, https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-32018-territorial-scope-gdpr-article-3_en

Massachusetts Data Privacy Law — Assessment Required

Massachusetts data privacy risk is Medium because: (1) SSR is headquartered in Cambridge, MA and is subject to Massachusetts law as a business operating in the Commonwealth; (2) 201 CMR 17.00 requires any person or business that owns, licenses, stores, or maintains personal information about Massachusetts residents to implement a comprehensive written information security program (WISP); (3) SSR collects personal information (names, email addresses, contact details) from Massachusetts residents through its website, newsletter, and advisor service; (4) The regulation requires specific technical and organizational security measures; (5) Risk is Medium because 201 CMR 17.00 is well-established (since 2010) and SSR as a Cambridge-based company should be aware of it, but enforcement against small businesses is less frequent than against larger entities. Massachusetts also enacted the Massachusetts Data Privacy Act (MDPA) which is pending implementation.

Evidence: https://www.selectsoftwarereviews.com/about-us, https://www.mass.gov/regulations/201-CMR-1700-standards-for-the-protection-of-personal-information-of-residents-of-the, https://www.mass.gov/info-details/massachusetts-data-privacy-law

Financials

Three-year financials

Financial Resilience Score: 7/10

SelectSoftware Reviews (Strazzulla, LLC) demonstrates strong financial resilience for a small, bootstrapped digital media business. The company is self-described as profitable and has operated without outside venture funding since its 2018 founding, which eliminates debt service obligations, dilution pressure, and runway concerns that typically afflict early-stage companies. Its capital-light content-driven model (SEO plus newsletter) requires minimal fixed costs beyond staff and hosting, allowing for high margin flexibility. Revenue diversification across 1,000+ vendor advertisers (including major HR-tech players like Deel, HiBob, Rippling, Workday, Greenhouse, and BambooHR) reduces single-customer concentration risk. Semi-recurring newsletter sponsorships and vendor retainers provide revenue stability, while newer service lines launched in 2024 (Talk to an HR Advisor concierge, webinars, PeopleOpsJobs.io job board) add product diversification. However, the company faces material structural risks that cap its resilience score. Heavy dependence on Google SEO makes it vulnerable to algorithm updates (2023-2024 Helpful Content updates hit similar publishers hard), and emerging AI/LLM disintermediation via ChatGPT, Perplexity, and Google AI Overviews threatens the core buyer-guide traffic model. The small team (~15-20 FTE) creates key-person risk around founder Phil Strazzulla, and single-vertical concentration in HR/recruiting tech exposes revenue to sector-specific marketing budget contractions as seen in 2023.

Key strengths: Bootstrapped and self-described as profitable with no outside funding dependency, Capital-light content-driven business model with minimal fixed costs, Diversified vendor advertiser base of 1,000+ clients including major HR-tech players, Semi-recurring revenue from newsletter sponsorships and vendor retainers, Strong SEO moat built up since 2018 in HR-tech buyer-guide niche, New service line diversification (HR Advisor concierge, webinars, job board), Employee-owned structure with no debt or dilution pressure

Risk factors: Heavy Google/SEO dependency vulnerable to algorithm updates, AI/LLM disintermediation threat from ChatGPT, Perplexity, and Google AI Overviews, Small team (~15-20 FTE) with limited redundancy and key-person risk around founder, No public capital access limits defensive M&A or investment capacity, Single-vertical concentration in HR/recruiting tech sensitive to sector downturns, Tightening FTC endorsement/affiliate disclosure regulatory requirements, HR-tech vendor marketing budget contraction observed in 2023

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report