Sift Science, Inc.
United States · sift.com · 27 vendors
Resilience scores
- Digital Sovereignty: 67
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Bricks Builder — Germany
- Netlify, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 25 more
Services catalogue
4 services in catalogue across 1 category; runs on 27 sub-vendors.
- Fraud Detection
- Digital Trust & Safety Suite
- Workflows
Insights
Last updated 2026-08-15 · revision 2
27 direct vendors, 320 subvendors
Direct vendors by controlling owner country (sample)
- Poland: 1
- UK: 1
- United Kingdom: 2
Subvendors by controlling owner country (sample)
- Austria: 1
- Slovenia: 1
- Romania: 1
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Sift Science exhibits a moderate to good level of migration readiness. Their existing adoption of Google Cloud Platform (GCP) as a primary cloud provider, coupled with the use of modern, cloud-friendly technologies like Apache Kafka, Elasticsearch, PostgreSQL, and REST APIs, indicates a strong foundation for further cloud migration and modernization. The company has also demonstrated experience with migration, having moved from legacy Apache HBase and partially from Amazon Web Services (AWS) components (EC2, S3, RDS). The geographic diversity of vendor headquarters across 5 countries suggests a potentially diverse vendor ecosystem, which can reduce overall vendor lock-in and simplify migration efforts by offering more flexibility. However, several factors present challenges to achieving a higher readiness score. The presence of legacy technologies such as Apache Hadoop/MapReduce, HDFS, and ZooKeeper suggests that a complete migration might involve significant re-platforming or re-architecting efforts for these older systems. The assessment lacks explicit information on the adoption of containerization (e.g., Docker, Kubernetes) or a full microservices architecture, which are key enablers for highly agile and portable cloud migrations. Furthermore, critical data is missing regarding financial stability (which impacts the ability to fund large-scale migrations), specific regulatory compliance requirements, and data residency constraints. These data gaps make it difficult to fully assess potential migration complexities and the company's capacity to undertake extensive migration projects.
Compliance
7 in-scope frameworks identified; showing 3.
GDPR (source) — Partially Compliant
Sift Science is a US-headquartered company that explicitly serves global brands and processes personal data of end-users worldwide, including EU/EEA residents. As a fraud prevention platform processing behavioral and transactional data of EU consumers on behalf of 700+ global customers, Sift acts as a data processor under GDPR. The company publishes a Service Privacy Notice, a Website Privacy Notice, a Website Cookie Notice, a Global Recruitment Privacy Notice, and references a Data Protection Addendum (DPA) available on request — all indicators of GDPR awareness. However, no publicly confirmed DPO appointment, EU representative designation, or independently verified GDPR audit report has been found. The risk is Medium rather than High because Sift has demonstrated structural compliance efforts (DPA, privacy notices, ISO 27001, SOC 2 Type II), but the absence of publicly verifiable GDPR audit evidence and the sensitivity of behavioral/transactional personal data processed at scale (1T+ events/year) elevates residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://sift.com/legal-and-compliance/service-privacy-notice/, https://sift.com/legal-and-compliance/website-privacy-notice/, https://sift.com/legal-and-compliance/website-cookie-notice/, https://sift.com/legal-and-compliance/sift-global-recruitment-notice/, https://sift.com/legal-and-compliance/trust-and-safety-security/, https://sift.com/legal-and-compliance/uk-modern-slavery-act/
PCI DSS (source) — Assessment Required
Sift's Payment Protection product processes transactional data related to payment fraud, including order data, payment metadata, and behavioral signals associated with payment card transactions. While Sift does not appear to store, process, or transmit raw cardholder data (PANs, CVVs) — which would trigger full PCI DSS scope — its integration with payment flows and access to transaction-level data warrants assessment. Many of Sift's 700+ customers are in e-commerce, fintech, and payment sectors where PCI DSS compliance is mandatory, and they may require Sift to demonstrate PCI DSS compliance or SAQ attestation as a service provider. No public PCI DSS attestation or SAQ has been identified. Risk is Medium because the absence of public PCI DSS documentation creates uncertainty for customers in payment-regulated sectors.
Evidence: https://sift.com/platform/payment-protection/, https://sift.com/legal-and-compliance/trust-and-safety-security/, https://www.pcisecuritystandards.org/
ISO 27001 (source) — Compliant
Sift explicitly confirms ISO/IEC 27001:2013 certification on its Trust & Safety page, stating it 'has been certified to ISO/IEC 27001:2013 with respect to the ISMS for its products and services.' This certification is granted by an independent third-party auditor and covers the Information Security Management System (ISMS) for Sift's products and services. Risk is Low because Sift holds an active, independently verified ISO 27001 certification. The main residual risk is whether the certification has been updated to ISO/IEC 27001:2022 (the current version), as the 2013 version has a transition deadline. This is a minor gap that warrants monitoring.
Evidence: https://sift.com/legal-and-compliance/trust-and-safety-security/, https://www.iso.org/standard/27001
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Sift Science is a well-capitalized private SaaS company operating in the digital fraud prevention space, having raised approximately $157M in cumulative equity funding from top-tier investors including Insight Partners, Union Square Ventures, Spark Capital, and Stripes. The company achieved unicorn status (>$1B valuation) at its April 2021 Series E round and demonstrates strong qualitative signals of scale including 700+ customers, 34,000+ integrated sites/apps, and 1 trillion+ events scored annually. Its enterprise SaaS model with marquee logos like DoorDash, Yelp, Hertz, and Poshmark suggests high recurring revenue and strong customer retention typical of fraud/risk platforms. However, the lack of publicly disclosed financials (revenue, EBIT, equity) limits external assessment of profitability, burn rate, and runway. The absence of a new priced funding round since 2021 raises questions about capital needs during a period of broader late-stage SaaS repricing. Competitive intensity from Riskified, Signifyd, Forter, Kount (Equifax), Stripe Radar, and Adyen's native tooling, combined with leadership transitions (founder moving from CEO to Executive Chairman), creates moderate uncertainty. The strong IP moat (40+ US patents), data network effects, and consistent G2 category leadership support a resilience score of 7, reflecting solid fundamentals tempered by financial opacity and market risks.
Key strengths: Well-capitalized with ~$157M raised from top-tier investors (Insight Partners, USV, Spark, Stripes), Unicorn status with >$1B valuation as of April 2021 Series E, Sticky enterprise SaaS model with 700+ customers including marquee brands, Strong data network effect processing 1 trillion+ events annually, IP moat with 40+ US patents granted/allowed, Product breadth across Payment Protection, Account Defense, Sift Score API, and Expert Services, Consistent G2 Leader recognition across fraud-prevention categories through 2025, $4.2M median annual losses prevented per customer
Risk factors: Opaque financials with no public revenue, EBIT, or equity disclosure, No new priced funding round announced since 2021 amid late-stage SaaS repricing, Intense competition from Riskified, Signifyd, Forter, Kount, Stripe Radar, and Adyen, Customer concentration risk in marketplace/e-commerce/fintech verticals, Regulatory exposure to GDPR, CPRA, and EU AI Act increases compliance costs, Leadership transition with founder Jason Tan moving from CEO to Executive Chairman, Potential flat/down round valuation risk if fresh capital is needed
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.