Spline

United States · spline.design · 5 vendors

Spline is a web-based, no-code 3D design and collaboration platform that allows users to create, iterate, and publish interactive 3D content and experiences directly in the browser. It provides tools for 3D modeling, animation, material editing, and importing models, making 3D design accessible for various platforms and web experiences. The platform supports real-time collaboration and aims to simplify the creative process for designers.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 1 category; runs on 5 sub-vendors.

Insights

Last updated 2026-08-03 · revision 2

5 direct vendors, 125 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Spline exhibits high migration readiness. The company's technology stack is modern and highly conducive to migration, leveraging AWS, Next.js, React, and Node.js, which are well-suited for cloud-native and potentially microservices architectures. The established compliance frameworks (SOC 2, ISO 27001, GDPR) indicate a mature operational environment with processes in place to handle data security and regulatory requirements, which can streamline migration planning. While the geographic diversity of vendors is a positive, the total number of 6 services and the unknown vendor lock-in risk suggest a moderate level of vendor integration that would require careful assessment and management during a migration. A key challenge is the absence of data regarding financial stability, making it difficult to assess the company's capacity to fund a significant migration initiative. Data residency requirements are also not specified, which could introduce unforeseen complexities depending on the target migration environment.

Compliance

5 in-scope frameworks identified; showing 3.

CPRA — Partially Compliant

Spline's Privacy Policy (Section 7) includes a 'California Privacy Rights' section referencing California Civil Code Section 1798.83, which is the older 'Shine the Light' law predating CCPA. However, the policy does not explicitly address CCPA/CPRA rights introduced in 2020 and expanded in 2023, including: the right to know categories of personal information sold/shared, the right to opt-out of sale/sharing, the right to limit use of sensitive personal information, or the requirement to disclose whether personal information is 'sold' to third parties. Given Spline's use of third-party advertising cookies and behavioral advertising (disclosed in Section 10), there is a risk that data sharing with advertising partners constitutes a 'sale' or 'sharing' under CCPA's broad definitions. The Privacy Policy was last updated December 1, 2020 — before CCPA's full enforcement and before CPRA amendments took effect in January 2023. Risk is Medium due to the outdated policy, advertising data practices, and incomplete CCPA/CPRA disclosures.

Evidence: https://spline.design/privacy

ISO 27001 (source) — Compliant

Spline's Security page explicitly states 'Spline holds ISO 27001 certification,' and the Trust Center provides a mechanism to access certifications. ISO 27001 is an internationally recognized information security management standard requiring independent third-party certification by an accredited certification body. Holding this certification demonstrates that Spline has implemented a formal Information Security Management System (ISMS) that has been independently audited. Risk is Low because the certification is publicly disclosed and independently verified. The main residual risk is that the certificate's current validity period and scope are not publicly confirmed — ISO 27001 certificates require annual surveillance audits and triennial recertification.

Evidence: https://spline.design/security, https://trust.spline.design/

COPPA — Assessment Required

Spline's Privacy Policy (Section 4) states it does not knowingly collect personal information from children under 13 and requires users to be at least 18 (or supervised by a parent/guardian). However, Spline offers a free tier accessible to anyone with an email address, has an active community platform, and markets to students and educators (spline.design/education). The combination of a free, publicly accessible creative tool with an education program creates a risk that minors under 13 may access the platform. COPPA requires verifiable parental consent before collecting personal information from children under 13. The adequacy of Spline's age verification mechanism (self-declaration only) is uncertain. Risk is Medium because the policy prohibits under-13 use but the enforcement mechanism is unclear, and the education program may attract minors.

Evidence: https://spline.design/privacy, https://spline.design/education

Financials

Three-year financials

Financial Resilience Score: 6/10

Spline is a small, YC-backed, VC-funded private SaaS company at an early-growth stage. Financial resilience appears reasonable in the short term thanks to a fresh $10M Series A closed in August 2024 (led by Third Point Ventures, with participation from Gradient Ventures, Y Combinator, and Firestreak) combined with a lean team of approximately 25 employees, which extends runway substantially compared to peers with heavier burn. However, no revenue, EBIT, or equity figures are publicly available, so financial resilience cannot be quantitatively verified. The company benefits from a freemium + Enterprise product-led growth motion, tier-1 institutional backing, broad platform strategy (Web/iOS/Android integrations with Webflow, Framer, Wix, React, Next.js), and alignment with the generative AI investment thesis via its AI-3D generation and Omma products. Risks include very small scale limiting durability through a prolonged fundraising winter, undisclosed unit economics, intense competition from Figma, Framer, Rive, Unity, Unreal, Blender, and Adobe Substance, an emerging and unproven category, single-founder key-person risk, and absence of regulatory filings that would allow creditors or enterprise buyers to assess financial health.

Key strengths: Recent $10M Series A (Aug 2024) from Third Point Ventures, Gradient Ventures (Google), Y Combinator, and Firestreak, Tier-1 institutional backing and validation, Freemium + Enterprise PLG SaaS motion with published pricing, Broad multi-platform strategy (Web/iOS/Android) and integrations with Webflow, Framer, Wix, React, Next.js, Strong brand pull in design/dev community (Resend, Oscilar, Koji Studio testimonials), AI-3D generation and Omma natural-language builder align with generative AI investment thesis, Small, capital-efficient team (~25 employees) extending runway

Risk factors: Very small scale (~25 employees) limits ability to withstand prolonged fundraising winter, Undisclosed unit economics — no public revenue or margin data, Intense competition from Figma, Framer, Rive, Unity, Unreal, Blender, Adobe Substance, Category (web-based interactive 3D design) still emerging and unproven as enterprise budget line, Single-founder company — key-person risk, No SEC or regulatory filings — creditors/partners cannot easily assess financial health, No official valuation disclosed alongside Series A

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report