SpinetiX SA

Switzerland · www.spinetix.com · 23 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 23 sub-vendors.

Insights

Last updated 2026-08-04 · revision 2

23 direct vendors, 256 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

SpinetiX SA exhibits moderate to low migration readiness. A significant challenge stems from their reliance on a proprietary operating system (DSOS™) and purpose-built, industrial-grade hardware media players (iBX & HMP Series). This tightly integrated, specialized ecosystem creates a high degree of internal lock-in, making migration to generic cloud infrastructure or alternative hardware platforms complex and costly. The 'Elementi Software' being a desktop application (Windows compatible) further complicates migration to a fully cloud-native or containerized environment, requiring substantial re-architecture. While the 'SpinetiX ARYA™ CMS' is cloud-based (SaaS), indicating some experience with cloud deployments, it represents only a portion of their overall product suite. There is no explicit mention of containerization or microservices adoption, suggesting a more traditional architectural approach for key components. The assessment is hampered by the lack of data on financial stability, which is crucial for funding significant migration efforts, and the absence of information on specific regulatory or data residency requirements. The 'Vendor Lock-in Risk: Unknown' and the inconsistent 'Total Vendors: 0' make it difficult to fully assess external vendor lock-in, but the strong internal ecosystem lock-in is a primary factor reducing migration readiness.

Compliance

6 in-scope frameworks identified; showing 3.

Cyber Resilience Act (source) — Assessment Required

The EU Cyber Resilience Act (Regulation (EU) 2024/2847), adopted in October 2024 with phased implementation through 2027, introduces mandatory cybersecurity requirements for products with digital elements (hardware and software) sold in the EU market. SpinetiX manufactures digital signage hardware players (IBX410, HMP400 series) and software (DSOS, Elementi) that are sold throughout the EU via its reseller network. As a manufacturer of connected hardware and software products placed on the EU market, SpinetiX would be subject to CRA requirements including: security by design, vulnerability handling, security updates, CE marking for cybersecurity, and conformity assessments. Risk is Medium because SpinetiX already demonstrates security-by-design principles (dedicated Trust Center, purpose-built DSOS OS, security white paper), which may facilitate CRA compliance, but formal CRA conformity assessment and documentation requirements will need to be addressed by the applicable deadlines.

Evidence: https://www.spinetix.com/what-is-digital-signage/trust-center, https://www.spinetix.com/digital-signage-products/dsos, https://www.spinetix.com/digital-signage-products/players

GDPR (source) — Partially Compliant

SpinetiX SA is headquartered in Switzerland (not EU/EEA), but explicitly acknowledges GDPR applicability in its Privacy Notice (last updated January 23, 2026), referencing both GDPR and the Swiss nFADP. The company actively serves EU/EEA customers, processes personal data of EU/EEA residents (customers, partners, employees), and uses EU-based processors (OVH for website hosting, listed as 'Safe list' under nFADP). The Privacy Notice references the right to contact 'your national data protection authority with regards to GDPR rights,' confirming GDPR scope. Risk is Medium rather than High because the company has a published Privacy Notice, cookie consent management (Usercentrics), documented processor agreements with Standard Contractual Clauses (SCCs), and explicit data subject rights. However, no formal GDPR audit, DPO appointment, or Article 27 EU representative is publicly disclosed, and the company's cloud infrastructure (AWS) may involve cross-border transfers requiring ongoing monitoring. Fines under GDPR can reach €20M or 4% of global annual turnover.

Evidence: https://www.spinetix.com/about-spinetix/legal/privacy-notice, https://www.spinetix.com/about-spinetix/legal, https://www.spinetix.com/about-spinetix/legal/cookie-notice, https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/links/data-protection---switzerland.html

Swiss Federal Act on Information Security — Assessment Required

The Swiss Federal Act on Information Security in the Confederation (ISG, in force since January 1, 2024) primarily applies to federal authorities and organizations providing critical services to the Swiss federal government. SpinetiX SA is a private company and not a federal authority. However, if SpinetiX provides digital signage solutions to Swiss federal government entities (listed as a target industry on their website), it may be subject to ISG supply chain requirements as a vendor. Risk is Low as the ISG's direct applicability to SpinetiX as a private technology vendor is limited, though government sector customers may impose ISG-aligned security requirements.

Evidence: https://www.spinetix.com/digital-signage-solutions/industries/government, https://www.spinetix.com/

Financials

Three-year financials

Financial Resilience Score: 6/10

SpinetiX SA is a privately held Swiss company with approximately 20 years of operating history in the digital signage industry. As a private SA under Swiss law, it is not obliged to publish annual accounts, and no revenue, EBIT, or equity figures are publicly disclosed. This opacity limits any quantitative assessment of financial resilience. However, qualitative indicators suggest reasonable stability: the company has established itself as a niche leader with blue-chip enterprise customers (IBM, Equifax, Fannie Mae, Armani, Prada, Mercedes-Benz), operates a vertically integrated stack (hardware, OS, authoring software, cloud CMS), and is transitioning toward a SaaS recurring-revenue model via SpinetiX ARYA. Risks include competitive intensity from larger players (BrightSign, Samsung MagicINFO, LG webOS, Scala/Stratacache, and VC-backed SaaS peers), hardware component exposure to semiconductor supply cycles, transition risk from perpetual licenses to SaaS, small scale relative to global rivals, and FX exposure given a Swiss CHF cost base against USD/EUR-denominated sales. The company has not announced large equity fundraising rounds recently and remains privately held with no IPO plans disclosed. Overall, resilience appears moderate — sufficient for a niche specialist but constrained by scale and opacity.

Key strengths: Established ~20-year track record in digital signage niche, Blue-chip enterprise reference customers (IBM, Equifax, Fannie Mae, Armani, Prada, Mercedes-Benz), Vertically integrated stack: proprietary players, DSOS operating system, Elementi authoring software, ARYA cloud CMS, Shift to SaaS (SpinetiX ARYA / HUB) supporting recurring revenue, Strong technical leadership (ex-VisioWave, EPFL, Silicon Valley background), Global reseller/partner distribution network, New distribution agreement with ALGAM Enterprise for France (2025/2026)

Risk factors: Opaque financials — no public disclosure of revenue, EBIT, or equity, Competitive intensity from BrightSign, Samsung MagicINFO, LG webOS, Scala/Stratacache, Navori, Signagelive, and others, Hardware margin pressure from ODM/SoC players and displays with embedded signage OS, Semiconductor supply chain exposure for player hardware, Transition risk from perpetual licenses to SaaS may pressure top-line optics, Small scale relative to VC-backed SaaS competitors, FX exposure: CHF cost base vs. USD/EUR-denominated revenue

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report