Snap Inc.
United States · www.snapchat.com · 10 vendors
Snap Inc. is an American technology company that develops and maintains technological products and services, including the popular visual messaging application Snapchat, Spectacles (augmented reality glasses), and Bitmoji. The company aims to empower people to express themselves, live in the moment, learn about the world, and have fun together.
Resilience scores
- Digital Sovereignty: 100
- Digital Resilience: 8
Technology vendors
- hCaptcha — Cybersecurity — United States
- Netlify, Inc. — Technology — United States
- Tripadvisor, Inc. — Media & Marketing — United States
- and 7 more
Services catalogue
10 services in catalogue across 3 categories; runs on 10 sub-vendors.
- Augmented Reality Inventory
- Brand lift measurement
- Snapchat Pixel
Insights
Last updated 2026-09-13 · revision 2
10 direct vendors, 142 subvendors
Direct vendors by controlling owner country (sample)
- United States: 10
Subvendors by controlling owner country (sample)
- UK: 1
- Denmark: 4
- Australia: 2
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Snap Inc. exhibits a very high degree of migration readiness, primarily driven by its highly modern and cloud-native internal tech stack. The extensive use of containerization (Docker, Kubernetes) and infrastructure as code (Terraform) significantly streamlines the process of moving and deploying applications across different environments. The adoption of gRPC and Protocol Buffers suggests a microservices architecture, which inherently supports modular and flexible migration. Furthermore, Snap's existing multi-cloud strategy, utilizing both Google Cloud Platform (GCP) and Amazon Web Services (AWS), demonstrates a proven capability to operate and potentially migrate workloads across diverse cloud infrastructures. The company's broad range of programming languages (Python, Go, Java, C++, Swift, Kotlin, JavaScript/TypeScript) also indicates a versatile development environment. However, the assessment is constrained by a lack of information regarding specific regulatory compliance requirements, data residency constraints, and detailed financial stability data, which are crucial for planning and funding large-scale migrations. While the multi-cloud approach reduces general infrastructure lock-in, specific dependencies on vendors like Supabase for the Snap Cloud backend and Qualcomm for AR hardware (Snapdragon processors) could introduce complexities and potential lock-in for those particular components during a migration. The high geographic concentration of vendors (all US-based) could also be a factor, though its impact on migration readiness is less direct than on resilience.
Compliance
12 in-scope frameworks identified; showing 3.
POPIA — Assessment Required
POPIA (South Africa's data protection law, fully effective July 2021) applies to processing of personal information of South African data subjects. Snap operates Snapchat in South Africa and processes personal data of South African users. However, South Africa represents a smaller market for Snap, and POPIA enforcement by the Information Regulator is still developing. Risk is Low-Medium due to the smaller market size and developing enforcement environment.
Evidence: https://values.snap.com/privacy/privacy-policy
SOC 2 (source) — Assessment Required
Snap Inc. operates cloud-based services (Snapchat platform, Snap Ads, Snap Kit developer platform, Camera Kit) and provides services to enterprise advertising clients and developers. SOC 2 is highly relevant for cloud service providers and SaaS companies. Enterprise advertising clients and developer partners may contractually require SOC 2 Type II reports as part of vendor due diligence. The risk is Medium because while SOC 2 is not legally mandated, failure to maintain SOC 2 compliance could impact enterprise customer trust, advertising partnerships, and developer ecosystem relationships. Snap's scale and enterprise customer base make SOC 2 compliance commercially important.
Evidence: https://values.snap.com/privacy/privacy-through-security, https://developers.snap.com, https://forbusiness.snapchat.com
ISO 27001 (source) — Assessment Required
ISO 27001 is the international standard for information security management systems (ISMS). As a major technology company processing personal data of 750M+ monthly active users globally, ISO 27001 certification would be expected and commercially valuable for Snap. The risk is Medium because while ISO 27001 is not legally mandated, the absence of certification could be a concern for enterprise clients, government partners, and regulatory authorities assessing Snap's security posture. Snap's scale of data processing and history of security incidents (2014 data breach, ongoing phishing/account compromise issues) make robust ISMS critical.
Evidence: https://values.snap.com/privacy/privacy-through-security, https://snap.com/en-US/privacy/privacy-center/
Financials
Three-year financials
- 2025: revenue USD 5.93B, EBIT USD -532M, equity USD 2.28B
- 2024: revenue USD 5.36B, EBIT USD -787M, equity USD 2.45B
- 2023: revenue USD 4.61B, EBIT USD -1.40B, equity USD 2.41B
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.