SpeedCurve

New Zealand · speedcurve.com · 10 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 10 sub-vendors.

Insights

Last updated 2026-05-05 · revision 1

10 direct vendors, 180 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

SpeedCurve exhibits high migration readiness due to its cloud-native architecture, primarily built on Amazon AWS. This foundation provides inherent flexibility and compatibility with modern cloud migration strategies. The absence of specified data residency requirements significantly reduces potential migration complexities and costs. The company's strong integration with various CI/CD platforms (Jenkins, GitHub, CircleCI, Travis CI) indicates an agile development and deployment environment, which is conducive to adopting new technologies or migrating existing ones. The use of open-source components like Google Lighthouse and WebPageTest, along with standard APIs (REST API, RUM JavaScript API), suggests a less proprietary and more portable technology landscape. The lack of data on financial stability (e.g., revenue concentration, growth history) makes it difficult to assess the company's capacity to fund a significant migration effort. Information on the regulatory environment is also missing, which could introduce unforeseen compliance challenges during migration. While the tech stack is cloud-native, explicit details on containerization or microservices adoption are not provided, though these are often natural extensions of a cloud-native approach. The specific vendor lock-in risk, particularly with AWS, is unknown, although AWS's widespread adoption and tooling generally offer more migration options than highly specialized platforms.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

SpeedCurve processes personal data from EU/EEA residents through their web performance monitoring services. While they have GDPR-compliant data processing agreements and privacy policies in place, the medium risk stems from the complexity of international data transfers and the need for ongoing compliance monitoring. The company has implemented Standard Contractual Clauses for data transfers and maintains appropriate technical and organizational measures.

Evidence: https://www.speedcurve.com/terms/, https://embrace.io/docs/privacy-policy/, https://embrace.io/docs/dpa/

SOC 2 (source) — Assessment Required

As a cloud-based SaaS provider handling customer data, SOC2 compliance would be expected and beneficial for customer trust and security assurance. The medium risk reflects the importance of SOC2 for SaaS providers and the potential business impact if compliance gaps exist. Many enterprise customers require SOC2 compliance from their vendors.

ISO 27001 (source) — Assessment Required

ISO 27001 is a critical information security management standard for technology companies handling customer data. The medium risk reflects the importance of formal information security management systems for maintaining customer trust and meeting enterprise customer requirements. The company has documented security measures but no evidence of ISO 27001 certification was found.

Evidence: https://embrace.io/docs/dpa/

Financials

Three-year financials

Financial Resilience Score: 6/10

SpeedCurve is a highly respected niche SaaS company with a 12-year operating track record and a blue-chip customer roster including BBC, The Guardian, Forbes, New York Times, Hyatt, Trivago, Shopify, Eventbrite, NerdWallet, Expedia, Zillow, Vox Media, Ancestry, and GOV.UK. The company appears to have grown organically without announced VC rounds for its entire history prior to the November 2025 acquisition, which is a strong indicator of profitability or at least disciplined cash-flow management. Its recurring SaaS subscription model and sticky enterprise customers provide revenue stability. However, financial resilience cannot be precisely assessed due to total opacity of financials—no revenue, EBIT, or equity figures are publicly disclosed. The company is small (estimated 8-10 employees), creating key-person risk and limited surge capacity. It operates in a competitive and consolidating market with well-funded rivals like Datadog, New Relic, Dynatrace, Akamai mPulse, Catchpoint, Calibre, DebugBear, and Sentry. The November 10, 2025 acquisition by Embrace Mobile, Inc. (backed by NEA, Greycroft, AV8/Allianz, and Eniac) removes single-company risk and provides access to a well-funded venture-backed parent, which improves overall resilience.

Key strengths: 12-year operating track record with organic growth (no announced VC rounds pre-acquisition), Blue-chip customer roster (BBC, Guardian, Forbes, NYT, Shopify, Expedia, Zillow), Recurring SaaS subscription revenue model with sticky enterprise contracts, Strong brand authority - co-founder Steve Souders is the 'father' of web performance, Helped define Core Web Vitals and contributed to W3C standards, Acquired by well-funded Embrace (NEA, Greycroft, AV8/Allianz, Eniac backing), Scale indicators: 25M+ RUM page views and 600K+ synthetic tests processed daily

Risk factors: Total opacity of financials - no public disclosure of revenue, EBIT, or equity, Very small team (~8-10 employees) creates key-person risk, Niche market with well-funded competitors (Datadog, New Relic, Dynatrace, etc.), Defensibility is reputation-driven rather than scale-driven, Integration / brand-dilution risk post-acquisition, Unknown but plausible customer-concentration risk, Combined post-deal customer base of 'nearly 1,000' implies modest standalone scale

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report