Thenum ApS
Denmark · owned by Independent (Denmark) · thenum.dk · 10 vendors
Thenum ApS is a Danish IT consultancy and software development company based in Copenhagen, Denmark. The company offers custom software development, IT advisory services, web and mobile application development, and digital marketing solutions tailored to Danish businesses. They help clients digitise and optimise their operations, delivering end-to-end digital solutions from concept to finished product.
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 5
- Financial Resilience: 4
Technology vendors
- Appwrite — Israel
- Cloudinary — Technology — United States
- Nayax — Financial Services — Israel
- and 7 more
Insights
Last updated 2026-09-15 · revision 3
10 direct vendors, 157 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 1
- United States: 6
- Cyprus: 1
Subvendors by controlling owner country (sample)
- Brazil: 1
- United States: 114
- Romania: 2
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Thenum ApS demonstrates medium migration readiness, leaning towards the higher end due to its technical foundation. A significant opportunity lies in its internal tech stack, particularly the use of Docker, which indicates a strong foundation for containerization and a move towards cloud-native architectures. This significantly reduces the technical hurdles for migration to modern cloud platforms. The adoption of other modern services like Appwrite, Cloudinary, and GitHub further supports a flexible and adaptable environment for migration. However, substantial unknowns present major challenges. The absence of information on the regulatory environment (e.g., specific compliance requirements like GDPR, NIS2) and data residency requirements means that critical legal and operational constraints for a cloud migration cannot be adequately planned for. Financial stability and the ability to fund a potentially costly migration are also unknown. The vendor relationship data is contradictory ('Total Vendors: 0' versus 'Vendor HQ Countries'), making it difficult to accurately assess vendor lock-in risk, which can complicate or impede migration efforts. While vendor geographic diversity is noted, the total number of vendors and the complexity of their contracts remain unclear, preventing a precise evaluation of potential lock-in.
Compliance
7 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC 2 is a voluntary assurance framework. For a company handling financial data, it is a highly relevant framework to demonstrate security controls to customers and partners.
While not legally required, a SOC 2 report would enhance trust, especially for a financial app. The risk of not having one is low for a small B2C company but could become a factor if they expand into B2B services.
Digital Services Act — Assessment Required
The DSA applies to online intermediaries. It is unclear if the 'Sub Agent' app would be classified as such. It primarily provides a service to the user and may not host third-party content in a way that brings it into scope.
Applicability depends on whether Thenum ApS's app is considered an 'intermediary service'. If so, non-compliance with transparency and user rights obligations could result in fines. The risk is medium as the service appears to be a direct-to-consumer tool rather than a platform for third-party content.
Evidence: https://www.deleporte-wentz-avocat.com/actualite-the-digital-services-act-scope-obligations-and-practical-implications-for-micro-and-small-enterprises, https://producentansvar.dk/en/products-and-responsibility/electronics/, https://shepwedd.com/knowledge/eu-digital-services-act-are-you-scope/, https://edaa.eu/digital-services-act/, https://martech.org/eu-digital-services-act-now-applies-to-all-but-the-smallest-businesses/
ISO 27001 (source) — Assessment Required
ISO 27001 is an internationally recognized standard for information security management. It is highly relevant for a company that processes personal and financial data.
Similar to SOC 2, ISO 27001 is a voluntary standard that would build trust. The risk of not having it is currently low but will increase with the company's growth and data processing volume.
Financials
Three-year financials
- 2025: revenue DKK 119K, EBIT DKK 85.3K, equity DKK 73.2K
- 2024: gross profit DKK 0.00, EBIT DKK -195, equity DKK 6.67K
- 2023: revenue DKK 0.00, EBIT DKK -678, equity DKK 5.96K
Financial Resilience Score: 4/10
Thenum ApS is a debt-light, equity-financed Danish micro-entity that transitioned from a dormant/near-dormant state (2022-2024) to its first year of meaningful commercial activity in 2025. The company generated DKK 119K in revenue with an exceptional gross margin (~75%) and EBIT margin (~72%), consistent with a solo/founder-led consulting practice with minimal cost base. Equity grew nearly tenfold to DKK 73.2K, driven almost entirely by retained profit. However, the absolute scale is extremely small — FY 2025 revenue of roughly €16K is below the level needed to sustain even a single full-time employee at Danish market rates. The equity buffer of DKK 73K provides only a modest cushion against project delays or bad debts. Revenue is almost certainly concentrated in a handful of project-based clients (three named on the website), with no indication of recurring/subscription revenue. Prior years show consistent small losses, suggesting the business only recently found commercial traction. While there is no evidence of external debt and the margin profile is strong, the micro-scale, client concentration, and absence of workforce disclosure limit the company's overall resilience.
Key strengths: No external debt; fully equity-financed, Very high margins in FY 2025 (~75% gross, ~72% EBIT), First profitable year on record in 2025, Equity grew ~997% year-on-year through retained earnings, Named reference clients validate commercial pipeline
Risk factors: Extremely small scale (revenue ~€16K equivalent), High customer concentration across a handful of projects, Thin equity buffer (DKK 73K), No disclosed workforce; likely single-founder dependency, Project-based, non-recurring revenue model, Prior years of dormancy and small losses (2022-2024)
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Digital marketing: 0%
- Software development: 0%
- IT consulting / advisory: 0%
- Web and mobile application development: 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.