Red Sift

United Kingdom · owned by Independent (United Kingdom) · www.ondmarc.com · 31 vendors

Red Sift is a global cybersecurity company that operates OnDMARC, an award-winning email authentication platform helping organizations achieve DMARC enforcement to stop phishing, spoofing, and business email compromise (BEC) attacks. The platform provides visibility into domain email security posture, automates SPF/DKIM/DMARC/BIMI configuration, and includes tools such as DNS Guardian and Dynamic SPF to protect against a broad range of email-based threats. Trusted by over 1,200 organizations worldwide, Red Sift also offers complementary products covering attack surface management, certificate monitoring, and brand protection.

Resilience scores

Disruption prediction

Red Sift has an estimated 13% probability of disruption in the next 6 months.

17 of Red Sift's 31 vendors monitored for disruptions.

Technology vendors

Services catalogue

5 services in catalogue across 3 categories; runs on 31 sub-vendors.

Insights

Last updated 2026-08-15 · revision 3

31 direct vendors, 316 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Red Sift exhibits high migration readiness. Their internal tech stack is predominantly cloud-native, utilizing major platforms like AWS, Google Cloud Platform, and Microsoft Azure, along with Cloudflare. This multi-cloud strategy inherently reduces vendor lock-in and provides flexibility for future migrations or workload rebalancing. The use of modern web technologies like Next.js and a unified SaaS platform (Pulse Platform) suggests an agile and adaptable architecture. Their strong existing regulatory compliance (GDPR, ISO 27001, SOC 2 Type II) indicates mature internal processes and controls that would facilitate managing the complexities of a migration. The diverse set of vendors identified through their internal tech stack (e.g., Prismic, Wistia, Teamtailor, Salesforce) also points to a lower risk of vendor lock-in, as they are not heavily dependent on a single vendor's ecosystem. The main challenges or unknowns for migration readiness are the lack of specified data residency requirements, which can be a critical factor in migration planning, and the absence of financial stability data (revenue concentration, growth history) to assess the company's capacity to fund significant migration efforts. Despite these unknowns, the modern, multi-cloud, and compliant nature of their operations positions Red Sift very well for future migrations.

Compliance

7 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

Red Sift is headquartered in the United Kingdom and operates globally across EMEA, APAC, and the Americas, serving customers including EU/EEA-based organisations (e.g., TUI, Capgemini, Northmill, Wise, ITV, TalkTalk, Holland & Barrett). As a cloud-based SaaS cybersecurity provider, Red Sift processes personal data of EU/EEA residents both as a data controller (employee data, prospect/customer contact data) and as a data processor (customer email metadata, domain data, IP addresses processed through OnDMARC and related products). GDPR is therefore unambiguously applicable. The risk level is Medium rather than High because: (1) Red Sift publicly references a Privacy Policy and Cookie Policy, indicating awareness of GDPR obligations; (2) the company uses HyperComply for its Security & Trust portal, suggesting active compliance management; (3) however, no publicly confirmed DPO appointment, Article 30 records, or formal GDPR audit evidence was found; (4) post-Brexit, UK GDPR applies domestically while EU GDPR applies to EU data subjects — dual compliance is required; (5) the company's SaaS model means it processes customer email authentication data (which may include personal data such as sender email addresses and IP addresses), creating ongoing data processor obligations. Enforcement risk is moderate given the ICO's active enforcement posture in the UK and EU DPAs' increasing focus on SaaS providers.

Evidence: https://redsift.com/legal/privacy-policy, https://redsift.com/legal/cookie-policy, https://redsift.hypercomply.io/, https://redsift.com/about-us, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/

ISO 27001 (source) — Assessment Required

ISO 27001 (Information Security Management System) is highly relevant for Red Sift as a cybersecurity SaaS provider. The risk is Medium because: (1) Red Sift's enterprise customer base (including large UK and EU organisations) would typically require ISO 27001 certification as a vendor prerequisite, particularly in the UK and European markets where ISO 27001 is more prevalent than SOC 2; (2) Red Sift's Security & Trust portal (HyperComply) is a strong indicator of formal compliance documentation, which often includes ISO 27001 certificates; (3) UK government and public sector customers (Red Sift references NCSC Mail Check and UK compliance use cases) typically require Cyber Essentials Plus and/or ISO 27001; (4) no publicly confirmed ISO 27001 certificate number, certification body, or scope was found in accessible pages. The risk would be elevated if ISO 27001 is not certified, given the UK/EU enterprise market expectations.

Evidence: https://redsift.hypercomply.io/, https://redsift.com/about-us, https://redsift.com/legal/customer-agreements

SOC 2 (source) — Assessment Required

Red Sift is a cloud-based SaaS provider serving enterprise and mid-market customers globally, including large organisations such as Capgemini, ZoomInfo, TalkTalk, and Fortune Global 500 companies. SOC 2 (System and Organization Controls 2) is the de facto standard for cloud service providers demonstrating security, availability, processing integrity, confidentiality, and privacy controls to enterprise customers. The risk is Medium because: (1) enterprise customers routinely require SOC 2 Type II reports as part of vendor due diligence; (2) Red Sift's Security & Trust portal (HyperComply) suggests active compliance management, which often includes SOC 2; (3) however, no publicly confirmed SOC 2 report or certification was found in accessible pages; (4) absence of a confirmed SOC 2 report could be a commercial risk when competing for enterprise contracts, particularly in the US market where Red Sift has a dedicated GM for Americas. The HyperComply platform is specifically used by companies to share SOC 2 and other compliance reports with prospects/customers under NDA.

Evidence: https://redsift.hypercomply.io/, https://redsift.com/about-us, https://redsift.com/pulse-platform/ondmarc

Financials

Three-year financials

Financial Resilience Score: 7/10

Red Sift is a well-capitalised mid-stage venture-backed UK cybersecurity SaaS scale-up. The company raised a US $54 million Series B in January 2022 led by Highland Europe, with participation from Sands Capital, MMC Ventures, Oxford Capital and Wing VC, supplemented by venture debt. This provided multi-year runway and a high-quality investor syndicate capable of supporting follow-on funding. The recurring-revenue SaaS model across OnDMARC, Brand Trust, Certificates and ASM products provides predictable ARR that investors and lenders favour. The company benefits from strong market tailwinds including Google/Yahoo/Microsoft bulk-sender enforcement (2024-25), PCI DSS 4.0.1 DMARC requirements, and the shutdown of the UK NCSC Mail Check driving demand for DMARC-as-a-service. Red Sift has a blue-chip diversified customer base of over 1,200 organisations including ZoomInfo, Domino's, TalkTalk, Wise, Holland & Barrett, Capgemini, ITV, TUI, and Save the Children, reducing single-customer concentration risk. Product breadth has expanded from single-product DMARC to a Pulse platform covering email, web/PKI (via Hardenize acquisition) and attack surface management. Key risks include likely continued operating losses typical of VC-backed SaaS scale-ups at this stage, competitive pressure from a crowded DMARC market (Valimail, Proofpoint, Cisco/Agari, EasyDMARC, dmarcian), ongoing R&D investment requirements for newer products (Brand Trust, Certificates, ASM, Radar), and the fact that the last equity round was raised in Q1 2022 under a very different rate environment—future rounds or refinancing may involve dilution or covenants. FX exposure exists due to UK cost base with significant USD revenue base.

Key strengths: US $54M Series B raised January 2022 led by Highland Europe with additional venture debt, High-quality investor syndicate: Highland Europe, Sands Capital, MMC Ventures, Oxford Capital, Wing VC, Recurring-revenue SaaS model providing predictable ARR, Strong regulatory tailwinds (Google/Yahoo/Microsoft enforcement, PCI DSS 4.0.1), Over 1,200 blue-chip customer organisations with diversified base, Broadened product platform via Hardenize acquisition (2022), G2 leader status in DMARC market

Risk factors: Likely still loss-making as typical VC-backed SaaS scale-up, Crowded competitive DMARC market with commoditisation pressure on pricing, Continued R&D spend required for newer products (Brand Trust, Certificates, ASM, Radar), Last equity round raised Q1 2022 in different rate environment; future refinancing risk, FX exposure between UK cost base and USD revenue base, Profitability inflection date not publicly disclosed

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report