Spreedly

United States · www.spreedly.com · 30 vendors

Resilience scores

Technology vendors

Services catalogue

7 services in catalogue across 4 categories; runs on 30 sub-vendors.

Insights

Last updated 2026-08-16 · revision 1

30 direct vendors, 300 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Spreedly exhibits a high degree of migration readiness primarily due to its cloud-native architecture on Amazon Web Services (AWS), including deployments across multiple regions and availability zones. Its foundational "Payments Orchestration Platform (Core API)" and extensive use of REST API indicate a modular, API-driven approach, which significantly simplifies potential migrations. The company's adherence to stringent regulatory standards like PCI DSS 4.0.1, SOC 2 Type II, and GDPR & DPF suggests mature processes and controls that can be adapted during migration. Furthermore, the use of modern security development practices like SAST and DAST points to a well-engineered and maintainable codebase. However, several factors temper the readiness score. The absence of data on data residency requirements could pose a challenge if strict geographical constraints exist. Financial stability (revenue concentration, growth history) is unknown, which impacts the perceived ability to fund a significant migration effort. Crucially, the "Vendor Lock-in Risk" is unknown, and while there is vendor geographic diversity, the "Total Services: 43" suggests a potentially complex ecosystem of external dependencies that would need careful management during any migration.

Compliance

9 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

Spreedly has achieved SOC 2 Type II certification with no exceptions, as explicitly stated on their Trust Center. This is a strong indicator of mature security controls. Risk is Low because: (1) the certification is current and publicly disclosed; (2) it was achieved with no exceptions, indicating robust control implementation; (3) the report is available via Whistic for customer review under NDA; (4) SOC 2 Type II is the gold standard for cloud service providers and Spreedly has clearly invested in maintaining it. The primary residual risk is that the report is not publicly available (requires NDA via Whistic), so the specific audit period and scope cannot be independently verified without access.

Evidence: https://www.spreedly.com/trust-center, https://public-profile.whistic.com/4dff16a8-1d18-49af-a67d-bafd75f4eee8, https://cloudsecurityalliance.org/star/registry/spreedly, https://securityscorecard.com/security-rating/spreedly.co

PCI DSS (source) — Compliant

PCI DSS compliance is the most critical regulatory requirement for Spreedly's core business as a payments orchestration and card vaulting platform. Risk is Low because: (1) Spreedly is a PCI DSS Level 1 Service Provider — the highest level of compliance; (2) the company is publicly listed on the Visa Global Registry of Service Providers; (3) an Attestation of Compliance (AOC) is publicly available; (4) the company is an official PCI SSC Associate Participating Organization; (5) the card data environment (CDE) is architected across multiple AWS availability zones and regions for resilience. Non-compliance would be existential for Spreedly's business, creating strong incentive for ongoing compliance.

Evidence: https://www.spreedly.com/trust-center, https://s3.amazonaws.com/spreedly-compliance/pci-dss-aoc.pdf, https://www.spreedly.com/blog/ciso-2025-year-in-review

LGPD — Partially Compliant

Spreedly explicitly acknowledges LGPD applicability in its DPA (Attachment 3) and has implemented compliance measures. Risk is Medium because: (1) Spreedly explicitly acknowledges that 'the full details of the interpretation and enforcement of the LGPD are still being developed'; (2) Brazil's ANPD (National Data Protection Authority) is actively developing regulations; (3) Spreedly uses EU SCCs as a proxy for Brazil data transfers (as Brazil has not yet promulgated its own SCCs); (4) the company serves customers in Brazil (evidenced by the 'Payments in Brazil' white paper and LATAM expansion guide); (5) LGPD enforcement has been increasing with fines up to 2% of Brazil revenue (capped at R$50M per violation).

Evidence: https://legal.spreedly.com/, https://www.spreedly.com/white-papers/payments-in-brazil

Financials

Three-year financials

Financial Resilience Score: 7/10

Spreedly demonstrates solid financial resilience based on qualitative indicators, despite the lack of public audited financial statements. The company operates a recurring, usage-based revenue model tied to Gross Merchant Volume (GMV), which grew from approximately US$50 billion in 2024 to an expected US$60 billion+ in 2025 (approximately +20% YoY). Enterprise segment growth of +54% YoY in Q3 2025 and doubling of new business bookings in H2 2025 signal strong commercial momentum. The company has been well-capitalized since its $75M Spectrum Equity growth investment in 2019 and has shown no signs of financial distress. The company's diversified customer base includes marquee enterprise logos (Adidas, Priceline, HBO Max, Chargebee, Cabify, Lemonade, Bandcamp) reducing single-customer dependency risk. Product breadth across Connect, Vault, Optimize, Protect, and Resolve pillars provides multiple revenue streams. The successful acquisition of Dodgeball in September 2025 demonstrates M&A capacity and ability to invest strategically. A robust partnership ecosystem (Visa, EBANX, Trustly, Checkout.com, Paysafe, Forter, dLocal, PayPal) contributed approximately one-third of new business in 2025. However, the score is constrained by significant financial opacity — no public disclosure of revenue, EBIT, equity, cash runway, or burn rate makes independent assessment impossible. Competitive intensity in payments orchestration is rising (Primer, Gr4vy, Stripe, Adyen, Checkout.com), and the aging 2019 funding round without a subsequent raise or IPO could create investor liquidity pressure. Regulatory/PCI-DSS compliance risk as a vault operator remains existential.

Key strengths: Recurring usage-based revenue model tied to GMV growth (~+20% YoY in 2025), GMV expected to exceed US$60 billion in 2025, up from ~US$50 billion in 2024, Enterprise segment grew +54% YoY in Q3 2025, H2 2025 new business bookings doubled vs. prior period, Vault active cards under management up ~50% YoY in 2025, $75M Spectrum Equity growth investment in 2019 provides capital base, Diversified marquee enterprise customer base (Adidas, Priceline, HBO Max, Lemonade), Product breadth across five pillars (Connect, Vault, Optimize, Protect, Resolve), Successful acquisition of Dodgeball (fraud orchestration) in September 2025, Strong partnership ecosystem contributing ~1/3 of new 2025 business

Risk factors: No public audited financials — profitability, burn rate, and cash runway opaque, Rising competitive intensity from Primer, Gr4vy, Stripe, Adyen, Checkout.com, Dependence on merchants' processing volumes — vulnerable to e-commerce slowdown, Pricing pressure from commoditization of card connectivity, Regulatory and PCI-DSS compliance risk as a vault operator, No new equity round or IPO since 2019 — potential investor liquidity pressure, Undisclosed customer concentration risk, Large PSPs (Stripe/Adyen) with internal orchestration capabilities can pressure margins

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report