TableFlow
United States · tableflow.com · 5 vendors
TableFlow is an AI-powered platform that automates complex data tasks, including document processing and data workflows. It enables businesses to extract, transform, and validate unstructured data from various sources like PDFs, spreadsheets, and images. The company aims to reduce manual effort, accelerate processing speed, and improve data accuracy for its users.
Resilience scores
- Digital Sovereignty: 80
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Google LLC — Technology — United States
- group.one — Technology — Denmark
- Next.js — Technology — United States
- and 2 more
Services catalogue
1 service in catalogue across 1 category; runs on 5 sub-vendors.
- TableFlow
Insights
Last updated 2026-05-21 · revision 2
5 direct vendors, 121 subvendors
Direct vendors by controlling owner country (sample)
- United States: 4
- Denmark: 1
Subvendors by controlling owner country (sample)
- Australia: 1
- Spain: 1
- Germany: 5
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
TableFlow exhibits high migration readiness due to its modern, API-driven, and cloud-friendly technical architecture. The internal tech stack, featuring TypeScript, Go, React, PostgreSQL, Webhooks, and REST API, along with multi-region cloud infrastructure, indicates a highly portable and adaptable system. The company's strategic use of 'Multi-Provider AI Routing' across various LLM vendors (Anthropic Claude, Amazon Bedrock, Mistral AI, Google Gemini, GPT-5 / OpenAI Models) is a significant strength, actively mitigating vendor lock-in for its core AI capabilities. The open-source CSV importer also suggests a commitment to flexible, non-proprietary solutions. SOC 2 Type II compliance further streamlines migration by ensuring established data governance and security practices. The absence of specified data residency requirements also simplifies potential migration efforts. Key challenges for migration readiness stem from the lack of financial data (revenue concentration, growth history), which prevents an assessment of the company's ability to fund a significant migration. Additionally, while AI vendor lock-in is addressed, the general 'Vendor Lock-in Risk' for other services remains 'Unknown' due to conflicting vendor data ('Total Vendors: 0' vs. 'Total Services: 7'), which could pose unforeseen complexities during a migration.
Compliance
3 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
As a US-based cloud service provider serving global customers, TableFlow likely processes personal data of EU/EEA residents through business documents (invoices, purchase orders, employee data, etc.). GDPR applies to any processing of EU/EEA personal data regardless of company location. Non-compliance can result in fines up to 4% of annual turnover or €20M. The high risk is due to: (1) Severe financial penalties for non-compliance, (2) Complex cross-border data transfer requirements, (3) Strict consent and data subject rights requirements, (4) High likelihood of processing EU personal data given their global customer base.
Evidence: https://tableflow.com/privacy, https://tableflow.com/security
ISO 27001 (source) — Assessment Required
ISO 27001 is a critical information security management standard for cloud service providers handling sensitive business data. While TableFlow demonstrates security awareness through SOC 2 compliance and security practices, there's no evidence of ISO 27001 certification. Medium risk because: (1) Many enterprise customers expect ISO 27001 for vendor qualification, (2) It's increasingly required for international business, (3) Lack of certification may limit market opportunities, though it's not legally mandated.
Evidence: https://tableflow.com/security
SOC 2 (source) — Compliant
TableFlow has successfully completed SOC 2 Type II audit, demonstrating compliance with security, availability, processing integrity, confidentiality, and privacy controls. This significantly reduces risk as they have third-party validation of their security controls. The low risk reflects their proactive compliance stance and the fact that SOC 2 is well-suited for their cloud service provider business model.
Evidence: https://tableflow.com/security
Financials
Three-year financials
- 2025:
- 2024:
- 2023:
Financial Resilience Score: 6/10
TableFlow (Portola Labs, Inc.) is an early-stage, venture-backed private company with no publicly disclosed financial statements. Its resilience is therefore assessed qualitatively. The company benefits from strong institutional investor backing, including Y Combinator, BOND (Mary Meeker's firm), Precursor Ventures, Nomad Capital, and TwentyTwo Ventures, which provides funding runway and credibility. Product-market fit signals are positive, with marquee customers across multiple verticals and published case studies demonstrating measurable customer value (e.g., 90% manual-work reduction, 300% volume increases at Ghost). However, as a seed/early Series A stage company, TableFlow likely operates unprofitably and depends on continued venture funding rather than operating cash flow. The intelligent document processing market is highly competitive, with established players (Conexiom, Rossum, Esker, Hyperscience) and hyperscaler offerings (AWS Textract, Google Document AI, Azure AI Document Intelligence). Additionally, reliance on third-party LLMs creates gross-margin exposure to inference pricing. Customer concentration risk is typical at this stage, and the lack of public financial disclosure limits external verification of burn rate or ARR.
Key strengths: Strong investor backing including Y Combinator and BOND, Marquee enterprise customers (Ghost, True Classic, Resend, Homebot, GCG), SOC 2 Type II certification, High product velocity with V2 platform launched September 2025, Multi-LLM routing across Anthropic, Bedrock, Mistral, Gemini, Enterprise integrations with NetSuite, SAP, Salesforce, Capital-efficient two-founder engineering-led team, Short customer go-live cycles (~2 weeks)
Risk factors: Early-stage company likely unprofitable, dependent on VC funding, Highly competitive IDP market with established incumbents and hyperscalers, LLM dependency exposes gross margins to inference pricing changes, Customer concentration risk typical of seed-stage startups, No public financial disclosure limits transparency, Small team size relative to enterprise-focused competitors
Revenue by geography
- United States: 0%
Revenue by product/service
- Integrated Document Extraction & Automation Platform: 100%
Workforce by country
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.