SheerID
United States · www.sheerid.com · 30 vendors
Resilience scores
- Digital Sovereignty: 63
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Anthropic, PBC — Technology — United States
- IST Group AB — Other — Sweden
- TransUnion (Neustar UltraDNS) — Financial Services — United States
- and 27 more
Services catalogue
2 services in catalogue across 2 categories; runs on 30 sub-vendors.
- Personal Data Processing
- SheerID
Insights
Last updated 2026-08-01 · revision 2
30 direct vendors, 285 subvendors
Direct vendors by controlling owner country (sample)
- United States: 19
- Netherlands: 1
- Sweden: 3
Subvendors by controlling owner country (sample)
- Sweden: 7
- Japan: 4
- Belgium: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
SheerID exhibits a good level of migration readiness, scoring 70. The company's internal and key technologies are largely modern and API-first, including REST API, Webhooks, and Swagger/OpenAPI specifications, which are conducive to modular and flexible deployments. The core products are AI/ML-powered and designed for 'Global Solutions,' supporting 190+ countries with region-specific authoritative data sources and compliance with local data protection regulations, indicating an architecture built for adaptability and international deployment. The extensive 400+ Martech & AdTech Platform Integrations also suggest a well-defined and accessible data architecture. Professional Services offered for custom onboarding and support further aid in potential migration efforts. However, the readiness score is tempered by several unknowns: there is no explicit mention of cloud-native architecture, containerization, or microservices, which are key indicators of advanced migration readiness. Crucially, data residency requirements are 'Not specified,' which is a significant factor in migration planning. Financial stability data (revenue concentration, growth) is also missing, which impacts the ability to fund a large-scale migration. The 'Vendor Lock-in Risk' is 'Unknown,' although the geographic diversity of vendors (6 countries) is a positive factor against concentrated vendor risk. The presence of Jekyll and WordPress in the internal tech stack, while likely for non-core functions, could represent minor complexities depending on the scope of migration.
Compliance
8 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
SheerID is a US-headquartered company that explicitly processes personal data of EU/EEA, UK, and Swiss residents through its identity verification and audience marketing platform. The company has implemented a robust GDPR compliance framework including: appointment of a named Data Protection Officer (Greg Damon), appointment of an EU GDPR Representative (EDPO, Brussels), appointment of a UK GDPR Representative (EDPO UK Ltd, London), adherence to the EU-U.S. Data Privacy Framework (DPF), use of Standard Contractual Clauses (SCCs) for international transfers, and a published Global Privacy Policy with explicit EU data subject rights. Risk is rated Medium rather than Low because SheerID processes large volumes of personal data (200M+ verifications) including sensitive eligibility credentials (military status, healthcare worker status, student status) across many EU member states, and as a data processor for EU-based clients, any breach or non-compliance by SheerID could trigger significant GDPR enforcement. The company's dual role as both Controller (for its own services like Remember Me and Audience Services) and Processor (for client verification flows) adds compliance complexity. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://www.sheerid.com/global-privacy-policy/, https://www.sheerid.com/privacy-overview/, https://www.dataprivacyframework.gov/, https://edpo.com/gdpr-data-request/, https://edpo.com/uk-gdpr-data-request/, https://www.sheerid.com/press-releases/sheerid-achieves-updated-information-security-based-iso-iec-certification-status/
ISO 27001 (source) — Compliant
SheerID has confirmed ISO/IEC 27001 certification, with the most recent update confirmed in January 2023 (ISO/IEC 27001:2013). The company also undergoes annual ISO 27001 audits as stated on its Data Safety page. Risk is Low because the company has demonstrated active certification maintenance. The primary ongoing risk is ensuring timely transition to ISO/IEC 27001:2022 (the updated standard), as the 2013 version's transition deadline was October 2025. It is unclear from public sources whether SheerID has completed this transition, which introduces a minor medium-term risk.
Evidence: https://www.sheerid.com/press-releases/sheerid-achieves-updated-information-security-based-iso-iec-certification-status/, https://www.sheerid.com/privacy-overview/, https://www.sheerid.com/about/
CCPA — Compliant
SheerID explicitly addresses CCPA and multiple US state privacy laws (California, Colorado, Connecticut, Virginia, Nevada) in its Global Privacy Policy. The company has implemented required mechanisms including data subject request processes, opt-out of sale/sharing, a dedicated privacy phone line (1-833-317-3372), and a privacy email. Risk is Medium because SheerID's Audience Services may constitute 'sale' or 'sharing' of personal data under CCPA definitions (the company explicitly acknowledges this), which triggers heightened obligations. The company processes data of millions of US consumers, and the rapidly expanding patchwork of US state privacy laws (with new states adding laws regularly) creates ongoing compliance complexity. CCPA enforcement by the California Privacy Protection Agency (CPPA) has been increasingly active.
Evidence: https://www.sheerid.com/global-privacy-policy/, https://www.sheerid.com/california-consumer-privacy-act-categories/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
SheerID is a mid-stage, VC-backed private SaaS company with a 14-year operating history, a marquee enterprise customer base (ASICS, Comcast/Xfinity, Peacock, Michaels, Intuit, Home Depot, J. Crew, Bass Pro Shops, Sleep Number, Headspace, Princess Cruises, Unity, SoundCloud), and multiple institutional funding rounds including a publicly reported ~$64M Series C led by CVC Growth Partners in 2019. Its recurring-revenue SaaS model with diversified end-markets (retail, media & entertainment, consumer software, travel, telecom, AI, airlines) provides revenue visibility and gross-margin stability typical of mid-stage private SaaS companies. The company holds ISO/IEC 27001 certification and has an experienced CFO (Dave Miller) with prior IPO/M&A experience at AWS Elemental, FinancialForce, EY, and Zynga. Third-party estimator sites suggest annual revenue in the US$30–60M range, and Inc. 5000 inclusion in 2022 and 2023 implies sustained multi-year revenue growth. However, SheerID does not disclose audited financials, so profitability, cash burn, debt levels, and runway are opaque to outsiders. Key risks include dependence on cyclical enterprise marketing budgets, competitive pressure from ID.me, GovX, Student Beans, UNiDAYS, and in-house verification, evolving data-privacy/age-verification regulation, potential AI-era pricing compression on verification services, and execution risk from a recent CEO transition to Stephanie Copeland Weber. Overall, qualitatively the business appears resilient but the lack of transparency limits confidence in the score.
Key strengths: 14-year operating history since 2011, Marquee blue-chip enterprise customer base across multiple verticals, Multiple institutional funding rounds including ~$64M Series C in 2019 (CVC Growth Partners), Recurring-revenue SaaS model with diversified end-markets, ISO/IEC 27001 certification supporting enterprise credibility, Experienced CFO with IPO/M&A background, Inc. 5000 recognition in 2022 and Inc. 5000 Pacific Regionals #128 in 2023, 200M+ verifications and ~$55B in prevented offer abuse to date, Expansion into Audience Data Platform (ADP) beyond core verification
Risk factors: No audited public financials; profitability, cash burn, and runway unknown, Dependence on cyclical enterprise marketing budgets, Competition from ID.me, GovX, Student Beans, UNiDAYS, and in-house verification, Data-privacy and regulatory exposure (GDPR, CCPA, age-verification laws), AI-era pricing pressure and potential substitution risk, Recent CEO transition introduces execution/strategy risk, Possible consumer-brand concentration risk (not verifiable)
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.