ThreeFold Foundation

Switzerland · threefold.io · 6 vendors

ThreeFold Foundation provides a decentralized Cloud and Internet infrastructure, building a peer-to-peer network that runs on bare metal. It leverages blockchain technology to offer scalable compute, data, and network solutions, aiming to create a more accessible and autonomous internet.

Resilience scores

Disruption prediction

ThreeFold Foundation has an estimated 11% probability of disruption in the next 6 months.

3 of ThreeFold Foundation's 6 vendors monitored for disruptions.

Technology vendors

Services catalogue

3 services in catalogue across 2 categories; runs on 6 sub-vendors.

Insights

Last updated 2026-08-14 · revision 1

6 direct vendors, 143 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

ThreeFold Foundation exhibits very high migration readiness, largely due to its modern, cloud-native oriented tech stack and its unique position of having minimal external vendor dependencies. The internal tech stack, including Go, Rust, TypeScript, Docker, and Kubernetes, aligns perfectly with contemporary cloud migration strategies, enabling containerization and microservices architectures. Products like 'Kubernetes on Decentralized Infrastructure' and 'AI / LLM Compute at the Edge' further underscore their proficiency in deploying and managing workloads in highly distributed and flexible environments. A significant advantage for migration readiness is the stated 'Total Vendors: 0.' This implies a complete absence of external vendor lock-in, which is often a major impediment to migration. ThreeFold is not constrained by complex vendor contracts, proprietary technologies, or the need to untangle deeply integrated third-party services. While this means they are highly self-reliant, it also grants them maximum flexibility to adapt their own platform or even re-platform if strategic needs dictate. The 'Vendor Geographic Diversity' data, while seemingly contradictory to 'Total Vendors: 0,' does not indicate any significant vendor-related migration complexities if 'Total Vendors: 0' holds true for core services. However, the assessment is limited by the lack of data on 'Regulatory Environment' and 'Data Residency Requirements,' which can introduce significant complexities and costs during any migration effort. Similarly, the absence of 'Financial Stability' data means the ability to fund a large-scale migration cannot be fully assessed. Despite these unknowns, the inherent architectural flexibility, modern technology adoption, and the critical absence of external vendor lock-in position ThreeFold Foundation as exceptionally ready for migration or significant architectural evolution.

Compliance

8 in-scope frameworks identified; showing 3.

UAE VARA — Assessment Required

ThreeFold DMCC is registered in the Dubai Multi Commodities Centre (DMCC) Free Zone. The UAE has established the Virtual Assets Regulatory Authority (VARA) as the primary regulator for virtual assets in Dubai. DMCC also operates its own Crypto Centre with specific licensing requirements for virtual asset activities. ThreeFold's token-based economy (TFT, and planned AUR/SPORE tokens) likely constitutes virtual asset activity subject to VARA and/or DMCC regulation. Risk is High because: (1) operating virtual asset services without proper UAE/DMCC licensing can result in significant penalties; (2) the regulatory landscape is actively evolving; and (3) no VARA license or DMCC Crypto Centre registration has been publicly disclosed.

Evidence: https://threefold.io/impressum/, https://threefold.io/our-journey

Blockchain — Assessment Required

ThreeFold operates a token-based economy with TFT (ThreeFold Token) and is developing Project Mycelium with a dual-token model (AUR and SPORE). The EU's Markets in Crypto-Assets Regulation (MiCA), which became fully applicable in December 2024, regulates crypto-asset issuers and crypto-asset service providers (CASPs) operating in or targeting EU markets. ThreeFold's grid spans 40+ countries including EU member states, and its tokens are used by EU-based 'farmers' and deployers. Risk is High because: (1) MiCA imposes significant obligations on token issuers including whitepapers, authorization requirements, and ongoing disclosure; (2) non-compliance can result in prohibition of token offerings in the EU; (3) ThreeFold's token model (utility tokens for grid capacity) may qualify as 'utility tokens' under MiCA, requiring a compliant whitepaper; and (4) no MiCA compliance documentation has been publicly disclosed.

Evidence: https://threefold.io/, https://threefold.io/our-journey, https://threefold.io/project-mycelium

SOC 2 (source) — Assessment Required

ThreeFold is a cloud infrastructure and services provider — precisely the type of organization for which SOC 2 is designed. Enterprise and institutional customers deploying workloads on the ThreeFold Grid would typically require SOC 2 Type II reports as part of vendor due diligence. The absence of a publicly disclosed SOC 2 report is a significant gap for commercial credibility and enterprise customer acquisition. Risk is Medium because while SOC 2 is not legally mandated, its absence creates commercial and reputational risk, particularly as ThreeFold targets enterprise cloud workloads.

Evidence: https://threefold.io/, https://threefold.io/our-journey

Financials

Three-year financials

Financial Resilience Score: 3/10

ThreeFold's financial resilience is difficult to assess due to complete opacity — no audited financials are publicly available, and the operating entity has migrated to a UAE free-zone jurisdiction (DMCC) with minimal disclosure requirements. The project has demonstrated technical longevity (nearly a decade since 2016) and continues to operate its Grid V3.18 across 40+ countries, suggesting some level of ongoing operational funding. However, the company's own retrospective acknowledgment that 'we couldn't protect the token' is a direct admission that its primary financing mechanism (the TFT token) failed to achieve sustainability. The apparent contraction from a peak of ~2,500+ nodes to ~750 active independent nodes signals material ecosystem shrinkage and likely reduced participant economics. The community/token-financed model spreads capex to distributed farmers, limiting entity-level infrastructure cost, but it also creates severe revenue volatility tied to crypto market conditions. The upcoming pivot to Project Mycelium with a new dual-token model (AUR/SPORE) targeted for 2026 introduces significant execution and adoption risk. Combined with leadership concentration (single named manager at DMCC entity) and no visibility into runway, burn rate, or solvency, resilience must be scored low despite technical persistence.

Key strengths: Nearly a decade of continuous technical development since 2016, Operational Grid V3.18 live across 40+ countries, Distributed farmer model shifts hardware capex away from the entity, Multi-jurisdiction footprint (Switzerland, Belgium, UAE) provides regulatory optionality, Same core team executing pivot to Project Mycelium with revised tokenomics

Risk factors: No audited financials publicly available — complete opacity on revenue, EBIT, equity, and runway, Company's own admission that 'we couldn't protect the token' — TFT tokenomics failed, Node attrition from ~2,500+ peak to ~750 active — material ecosystem contraction, Migration of operating entity to UAE DMCC reduces creditor/counterparty transparency, Product pivot to Project Mycelium (2026 launch) carries re-platforming and adoption risk, Leadership concentration risk — single manager (Adnan Fatayerji) named on DMCC entity, Token dependency exposes project to crypto market volatility

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report