Smartlook
Czech Republic · www.smartlook.com · 27 vendors
Smartlook is a qualitative analytics solution for websites and mobile applications. It helps businesses understand user behavior through features such as session recordings, heatmaps, automatic event tracking, and conversion funnels. The platform enables data-driven decisions to improve user experience and product performance.
Resilience scores
- Digital Sovereignty: 81
- Digital Resilience: 7
- Financial Resilience: 3
Technology vendors
- Adobe Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- The Apache Software Foundation — Technology — United States
- and 35 more
Services catalogue
1 service in catalogue across 1 category; runs on 27 sub-vendors.
- Smartlook
Insights
Last updated 2026-07-30 · revision 5
27 direct vendors, 316 subvendors
Direct vendors by controlling owner country (sample)
- France: 1
- Germany: 2
- Canada: 1
Subvendors by controlling owner country (sample)
- Unknown: 2
- Ireland: 1
- Switzerland: 2
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Smartlook exhibits a high level of migration readiness, largely driven by its modern technology stack and an active, significant organizational transition. The company's tech stack, featuring modern SDKs (Web and Mobile), REST APIs, and a webhook architecture, is inherently flexible and well-suited for cloud-native environments and integration. The existing multi-region cloud infrastructure (EU & North America) and established processes for GDPR compliance, including data residency management and the use of Standard Contractual Clauses for international data transfers, provide a solid foundation for managing data during migration. A critical factor indicating high readiness is the ongoing acquisition by Cisco and the planned integration with Splunk Observability Cloud. This demonstrates that Smartlook is already undergoing a substantial migration and integration effort, implying a high degree of organizational and technical capability to adapt to new platforms and architectures. The geographic diversity of its implied vendor base (6 countries) also suggests a reduced risk of vendor lock-in from a single region, although the specific number of distinct vendors and explicit lock-in risk remain unknown. Challenges and opportunities for migration include the unknown financial stability, which could impact the funding available for future migration initiatives. The unclear status of SOC2, ISO 27001, and the pending assessment for NIS2 could introduce additional compliance requirements and complexities during any future migration planning. While the current integration with Splunk highlights readiness for that specific transition, it also means the company is in a state of flux, which might impact its immediate capacity for *other* large-scale migrations.
Compliance
4 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
Smartlook is headquartered in the Czech Republic (EU member state) and processes personal data of EU residents through their session recording and analytics services. They have implemented GDPR compliance measures including a Data Protection Officer, privacy policies, data processing agreements with customers, and opt-out mechanisms. However, as a data processor handling sensitive user behavior data, there's inherent medium risk due to the nature of their services and potential for data breaches or non-compliance issues.
Evidence: https://help.smartlook.com/docs/privacy-policy, https://help.smartlook.com/docs/data-security, https://www.smartlook.com/opt-out/
ISO 27001 (source) — Assessment Required
ISO 27001 certification would be valuable for a company handling sensitive user behavior data and session recordings. The medium risk reflects that while not legally mandated, lack of ISO 27001 certification could indicate gaps in information security management systems and impact customer confidence, especially with enterprise clients.
Evidence: https://help.smartlook.com/docs/data-security
SOC 2 (source) — Assessment Required
As a cloud-based analytics service provider handling customer data, SOC2 compliance would be expected and valuable for customer trust. The medium risk reflects that while not legally required, lack of SOC2 certification could impact business relationships with enterprise customers who require such certifications from their vendors.
Financials
Financial Resilience Score: 3/10
Smartlook's financial resilience as a standalone entity is effectively terminal. The company has been acquired by Cisco/Splunk and is being wound down with a clearly defined sunset timeline: End of Sale on 31 May 2026, End of Contract Renewals on 31 August 2026, Last Day of Support on 31 August 2027, and full platform decommission on 30 September 2027 with customer data deletion. This makes any forward-looking standalone financial resilience assessment moot — the revenue line will be absorbed into Splunk Observability Cloud's Digital Experience Analytics offering. Historically (pre-acquisition), Smartlook had reasonable resilience characteristics: a SaaS subscription model with recurring revenue, a global customer base spanning hundreds of thousands of registered websites and apps, strong product breadth across web and mobile session recording/heatmaps/funnels/events/crash reporting, and backing from credible Czech VC Credo Ventures (Series A ~US$3M in 2019). The strategic acquisition by Cisco/Splunk itself signals enterprise value was realized. However, the realized wind-down risk, guaranteed customer churn through 2026, customer-data deletion friction at decommission, intense competition from consolidating observability suites (Datadog, Dynatrace, New Relic, Microsoft Clarity), and ongoing GDPR/privacy scrutiny on session-recording vendors all weigh heavily. No audited revenue, EBIT, or equity figures were retrievable from primary Czech Collection of Deeds sources in this analysis.
Key strengths: Acquired by Cisco/Splunk — strategic exit realized, SaaS subscription model with recurring revenue, Global customer base across hundreds of thousands of sites/apps, Broad product suite (web + mobile session recording, heatmaps, funnels, events, crash reports), Backed by Credo Ventures (Series A ~US$3M in 2019), Integration into Splunk Observability Cloud's Digital Experience Analytics
Risk factors: End of Sale 31 May 2026 — no new paid subscriptions thereafter, End of Contract Renewals 31 August 2026, Last Day of Support 31 August 2027, Platform decommissioned 30 September 2027 with customer data deletion, Guaranteed customer churn during 2026 wind-down, Intense competition from Datadog, Dynatrace, New Relic, Splunk, Microsoft Clarity, Hotjar, FullStory, LogRocket, Mixpanel, GDPR/privacy regulatory exposure on session recording, Migration friction and reputational impact from data deletion at decommission
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.