Teamwork
Ireland · www.teamwork.com · 16 vendors
Resilience scores
- Digital Sovereignty: 6
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Anthropic, PBC — Technology — United States
- Netlify, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 13 more
Services catalogue
1 service in catalogue across 1 category; runs on 16 sub-vendors.
- Teamwork
Insights
Last updated 2026-07-23 · revision 2
16 direct vendors, 243 subvendors
Direct vendors by controlling owner country (sample)
- United States: 12
- Australia: 3
- Austria: 1
Subvendors by controlling owner country (sample)
- Poland: 2
- Australia: 1
- China: 9
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Teamwork exhibits a good level of migration readiness, primarily driven by its modern, cloud-native technology stack. The reliance on Amazon Web Services (AWS) and the adoption of Cloud SaaS (multi-tenant) architecture, coupled with advanced features like AI and workflow automation, suggest a flexible and adaptable infrastructure. The established security compliance frameworks (SOC 2 Type 2 and ISO/IEC 27001:2022) provide a solid foundation for managing security requirements during a migration. The company's ability to host data in both AWS US and EU regions indicates preparedness for diverse data residency requirements. However, significant challenges and uncertainties exist. The financial stability required to fund a major migration cannot be assessed due to missing data on revenue concentration and growth history. A critical unknown is the 'Vendor Lock-in Risk'. The provided data is ambiguous regarding the number of unique vendors for the '25 services', making it difficult to gauge the potential complexity and cost associated with disentangling from existing vendor relationships. While the tech stack is modern, explicit details on containerization or microservices adoption, which further enhance migration flexibility, are not provided.
Compliance
8 in-scope frameworks identified; showing 3.
PCI DSS (source) — Partially Compliant
Teamwork.com processes payment card data for subscription payments but explicitly relies on third-party payment processors for PCI DSS compliance. The Privacy Notice states: 'If you pay us by credit card, we and our payment processors protect your payment information in accordance with local laws establishing standards for payment card information.' The company also prohibits customers from storing payment card data on its platform. Risk is Low because: (1) the company appropriately delegates PCI DSS scope to specialized payment processors; (2) the prohibition on storing card data on the platform limits Teamwork.com's direct PCI DSS obligations; (3) this is standard practice for SaaS companies that use payment processors like Stripe.
Evidence: https://www.teamwork.com/legal/privacy-notice/, https://www.teamwork.com/security/
GDPR (source) — Compliant
Teamwork.com is headquartered in Ireland (an EU member state), making GDPR universally applicable. The company demonstrates strong compliance indicators: a published, detailed Privacy Notice explicitly referencing GDPR (EU) 2016/679, a formally appointed Data Protection Officer (DPO) reachable at dpo@teamwork.com, Standard Contractual Clauses (SCCs) in their Data Processing Agreement for US data transfers, and clear articulation of lawful bases for processing. Risk is rated Medium rather than Low because: (1) the company transfers data to the US (where no adequacy decision exists), relying on SCCs which carry inherent transfer risk; (2) as a SaaS platform serving 20,000+ businesses in 140+ countries, the volume and variety of personal data processed is significant; (3) the Irish Data Protection Commission (DPC) is one of the most active EU supervisory authorities and has issued major fines against large tech companies; (4) AI features (TeamworkAI) introduce additional data processing complexity that requires ongoing GDPR assessment. No known enforcement actions or breaches have been publicly reported.
Evidence: https://www.teamwork.com/legal/privacy-notice/, https://www.teamwork.com/legal/teamwork-com-data-processing-agreement/, https://www.teamwork.com/legal/data-transfer-addendum-uk/, https://www.teamwork.com/legal/data-transfer-addendum-us/, https://www.teamwork.com/legal/cookie-policy/, https://www.teamwork.com/legal/teamwork-com-ai-policy/, https://www.teamwork.com/security/
CPRA — Assessment Required
Teamwork.com explicitly serves US customers (the homepage references the United States as a key market) and has published a US Data Transfer Addendum. As a B2B SaaS company with significant US operations and customers, CCPA/CPRA may apply if Teamwork.com meets the thresholds: (1) annual gross revenue exceeding $25M; (2) buys, sells, or shares personal information of 100,000+ California consumers/households annually; or (3) derives 50%+ of annual revenue from selling/sharing personal information. Given 20,000+ business customers globally with significant US presence, threshold (2) is plausible. Risk is Medium because: (1) CPRA enforcement by the California Privacy Protection Agency (CPPA) is active; (2) fines up to $7,500 per intentional violation; (3) B2B exemptions under CCPA have been narrowed under CPRA.
Evidence: https://www.teamwork.com/legal/data-transfer-addendum-us/, https://www.teamwork.com/legal/privacy-notice/, https://www.teamwork.com/
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 7/10
Teamwork.com appears to have solid financial resilience based on qualitative indicators, though exact figures are not publicly retrieved in this analysis. The company has a bootstrapped, profitable heritage having grown without significant outside VC funding, which typically indicates disciplined capital management and healthy free cash flow margins. Its recurring-revenue SaaS model with tiered subscription pricing (Deliver, Grow, Scale, Enterprise) provides predictable, high-gross-margin revenue with strong retention economics. The company benefits from a diversified customer base of 16,000+ customers across agencies, IT services, consultancies, and accounting, resulting in low single-customer concentration risk. Its deep product suite (Projects, Desk, Chat, Spaces, resource management) creates cross-sell opportunities and stickiness. However, the company operates in a highly competitive category with well-funded competitors like Asana, Monday.com, ClickUp, and PSA specialists like Kantata and Scoro. Risks include exposure to agency/professional services spending which is cyclically sensitive, FX exposure between EUR reporting and USD/GBP revenue, and margin pressure from AI capex/opex investments. Private company opacity limits external visibility into leverage and cash position.
Key strengths: Bootstrapped, profitable heritage without significant VC funding, Recurring SaaS subscription revenue model with high gross margins, Diversified customer base of 16,000+ customers with low concentration, Deep product suite with cross-sell opportunities, Strategic AI push (TeamworkAI, AI Teammates) defending ARPU
Risk factors: Intense competition from Asana, Monday.com, ClickUp, Wrike, Smartsheet, Kantata, Scoro, Exposure to cyclical agency and professional services spending, FX exposure between EUR reporting and USD/GBP revenue, Margin pressure from AI capex/opex investments, Private company opacity limits visibility into leverage and cash
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.