Solibri

Finland · www.solibri.com · 15 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 15 sub-vendors.

Insights

Last updated 2026-06-25 · revision 7

15 direct vendors, 241 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Solibri exhibits medium migration readiness, leaning towards the lower end, primarily due to significant regulatory and data residency complexities. A major challenge is their tech stack, where 90% of revenue comes from the 'Solibri desktop product line', indicating a substantial legacy component that would require significant re-platforming for a full cloud-native migration. While they utilize cloud services like AWS S3 and Cloudflare, the core product architecture is not explicitly described as cloud-native or microservices-based. The regulatory environment presents considerable hurdles, with GDPR, NIS2, SOC2, and ISO 27001 all requiring assessment and potentially extensive compliance efforts, adding complexity, cost, and time to any migration. Data residency requirements are particularly stringent due to GDPR, a global customer base across 99 countries, and specific data sovereignty needs for government and defense sector clients, making data migration and placement a major undertaking. Financial stability for a large-scale migration is unclear due to the absence of recent revenue figures (2024 revenue is null). Regarding vendor relationships, the provided 'Total Vendors: 0' contradicts other data; assuming they do have vendors, their reliance on '20 services' from vendors in only '3 unique countries' suggests a potentially moderate level of vendor lock-in, with 'unknown' lock-in risk, which could complicate integration and exit strategies during migration. On the positive side, their existing use of AWS S3, Cloudflare, Zendesk, and HubSpot demonstrates familiarity with cloud services. Additionally, the 'Solibri Security+' product for air-gapped environments suggests internal expertise in secure and controlled deployments, which could be valuable in planning a secure migration strategy.

Compliance

8 in-scope frameworks identified; showing 3.

Finnish Data Protection Act — Assessment Required

As a Finnish company, Solibri is subject to the Finnish Data Protection Act (Tietosuojalaki 1050/2018), which implements and supplements GDPR in Finland. This includes specific national provisions on employee data processing, special categories of data, and the role of the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) as the supervisory authority. Risk is Medium because compliance with Finnish national data protection law is mandatory and the Finnish DPA has enforcement powers including fines. No specific Finnish DPA compliance documentation was found publicly.

Evidence: https://www.solibri.com/legal, https://www.solibri.com/solibri-sub-processors, https://tietosuoja.fi/en/frontpage

GDPR (source) — Partially Compliant

Solibri is headquartered in Helsinki, Finland (EU), making GDPR universally applicable. The company processes personal data of EU/EEA residents including employee data, customer data (email, name, phone, IP, activity data), and payment data across its SaaS and desktop products. Evidence of active GDPR compliance infrastructure exists: a published Privacy Policy, a Customer Data Processing Annex (DPA), a detailed sub-processor list with DPAs for each processor, and data storage primarily in the EU via AWS EMEA SARL (Luxembourg). Risk is rated Medium rather than Low because: (1) no public confirmation of a formally appointed Data Protection Officer (DPO) was found; (2) no third-party GDPR audit or certification was publicly disclosed; (3) some sub-processors (HubSpot, Salesforce, Verifone, Mixpanel, SuprStack) are US-headquartered, requiring valid transfer mechanisms (SCCs/adequacy decisions); (4) Solibri CheckPoint optionally stores data in the US, which requires careful transfer compliance. The existence of a comprehensive DPA and sub-processor register indicates active compliance efforts, but the absence of publicly verifiable DPO appointment and audit evidence prevents a 'Compliant' rating.

Evidence: https://www.solibri.com/legal, https://www.solibri.com/solibri-sub-processors, https://solibri-assets.s3.amazonaws.com/Customer-data-processing-annex_2025-06-30-114612_xzuq.pdf, https://solibri-assets.s3.amazonaws.com/privacy-policy.pdf, https://www.solibri.com/legal/cookie-policy

EU AI Act (source) — Assessment Required

The EU AI Act (Regulation 2024/1689), applicable from August 2024 with phased obligations, regulates AI systems placed on the EU market. Solibri's BIM validation products use rule-based checking and model validation algorithms. If any Solibri products incorporate AI/ML components (e.g., automated clash detection using machine learning, predictive analytics), they may fall within the AI Act's scope. Risk is currently Low because Solibri's core products appear to be rule-based validation tools rather than AI systems, but this requires formal assessment as Solibri evolves its product capabilities. The AI Act's prohibited AI practices apply from February 2025, and general-purpose AI model obligations from August 2025.

Evidence: https://www.solibri.com/about, https://www.solibri.com, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202401689

Financials

Three-year financials

Financial Resilience Score: 8/10

Solibri Inc. benefits substantially from being a wholly-owned subsidiary of Nemetschek SE, a publicly listed German company with group revenue of approximately €851m (2023) and a strong investment-grade financial profile. This parent backing materially reduces standalone liquidity and solvency risk. Solibri's business model is centered on tiered B2B SaaS subscriptions (Starter, Essential, Advanced, Premium, Security+), which typically generates high gross margins and predictable recurring cash flow. The company holds a niche leadership position as the de-facto standard in rule-based BIM quality assurance with a moat in IFC/openBIM validation. Its customer base is diversified across blue-chip AEC firms (WSP, Skanska, Ramboll, Sweco, NCC, Arup, HOK, Hensel Phelps) and public bodies (Statsbygg), reducing single-customer concentration risk. Structural tailwinds from government BIM mandates in the UK, Nordics, Germany, and Singapore, alongside IDS workflow adoption, support multi-year demand. Key risks include exposure to construction-cycle dynamics (particularly the 2023-2024 European construction slowdown), competitive pressure from Autodesk, Trimble, and cloud-native entrants (Speckle, BIMcollab, Revizto), and temporary revenue/profit pressure from the perpetual-to-subscription transition. FX exposure as a Helsinki-based EUR/USD exporter also affects reported results. Disclosure opacity limits external monitoring of standalone KPIs.

Key strengths: Wholly-owned subsidiary of Nemetschek SE (€800m+ group revenue, investment-grade profile), Recurring B2B SaaS subscription revenue model with high gross margins, Diversified blue-chip AEC customer base (WSP, Skanska, Ramboll, Arup, Statsbygg), Niche leadership and moat in IFC/openBIM rule-based model validation, Structural tailwinds from government BIM mandates (UK, Nordics, Germany, Singapore), Nemetschek Build segment compounding at ~20%+ annual growth

Risk factors: Construction-cycle exposure amid 2023-2024 European construction slowdown, Competition from Autodesk, Trimble, Speckle, BIMcollab, Revizto, Subscription transition can temporarily depress revenue and operating profit, FX exposure (EUR/USD) as Helsinki-based exporter, Limited public disclosure of standalone KPIs

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report