Tito

Ireland · ti.to · 9 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 9 sub-vendors.

Insights

Last updated 2026-07-02 · revision 2

9 direct vendors, 127 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Tito exhibits medium migration readiness. Opportunities for migration include a modern frontend (Nuxt.js), strong integration capabilities via a comprehensive REST API and Webhooks, and existing adoption of Amazon CloudFront, indicating some familiarity with cloud services. The absence of specified data residency requirements could offer flexibility in cloud region selection. However, several challenges temper readiness. The core backend, built on Ruby on Rails and PostgreSQL, while mature, may require substantial refactoring to align with cloud-native, containerized, or microservices architectures. A significant impediment is the lack of financial data (revenue concentration, growth history), making it impossible to assess Tito's capacity to fund a potentially costly migration. The "Vendor Lock-in Risk: Unknown" is a major concern, as dependencies on 10 external services with low geographic diversity (2 unique countries) could complicate disentanglement or re-platforming efforts. The lack of specified regulatory environment means potential future compliance hurdles are unknown and could emerge during migration planning.

Compliance

7 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is an internationally recognised information security management standard relevant to any organisation processing sensitive data. Tito processes personal data of event attendees and organisers globally, including payment-related data flows via Stripe. No ISO 27001 certification has been publicly disclosed. Risk is Medium because: (1) Tito's global customer base (including enterprise clients like Shopify and Mozilla) may expect ISO 27001 certification; (2) the absence of certification may create competitive disadvantage and procurement barriers; (3) Tito's documented security controls (penetration testing, SSL, bcrypt hashing, AWS hosting) suggest security awareness but without formal ISMS certification, gaps may exist. Non-compliance with ISO 27001 carries no direct regulatory penalty but has significant commercial implications.

Evidence: https://ti.to/privacy, https://github.com/teamtito/tito-gdpr-compliance

SOC 2 (source) — Assessment Required

Tito is a cloud-based SaaS platform that stores and processes customer and attendee personal data on behalf of event organisers, making it a service organisation in scope for SOC 2 consideration. Many of Tito's enterprise customers (e.g., Shopify, Mozilla) may contractually require SOC 2 Type II reports as part of vendor due diligence. No SOC 2 report or attestation has been publicly disclosed by Tito. Risk is Medium because: (1) Tito processes significant volumes of personal and transactional data for third-party organisations; (2) enterprise clients increasingly mandate SOC 2 compliance from SaaS vendors; (3) the absence of a SOC 2 report may limit Tito's ability to serve enterprise customers and represents a reputational and commercial risk. However, SOC 2 is a voluntary framework and non-compliance does not carry regulatory penalties.

Evidence: https://ti.to/privacy, https://ti.to/terms

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into Irish law) applies to Essential and Important Entities operating in the EU. Tito is an event registration and ticketing SaaS platform headquartered in Ireland. Its primary sector — event management software / digital services — does not fall within the NIS2 Essential Entity categories (energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space). It could potentially qualify as an 'Important Entity' under the 'digital providers' category (online marketplaces, online search engines, or cloud computing services), but Tito's platform is a specialised B2B SaaS tool for event ticketing rather than a general-purpose cloud or marketplace. The size threshold (50+ employees or €10M+ turnover) is uncertain as Tito does not publicly disclose headcount or revenue. Risk is Low because the sector match is weak and the company appears to be a small-to-medium enterprise, but a formal assessment is required to confirm employee count and whether the digital provider classification applies.

Evidence: https://ti.to/about, https://www.irishstatutebook.ie/eli/2024/si/322/made/en/print, https://www.ncsc.gov.ie/pdfs/NIS2_Guidance.pdf

Financials

Three-year financials

Financial Resilience Score: 7/10

Tito demonstrates above-average financial resilience for a company of its size, despite the lack of publicly disclosed financials. The company operates with a very small team of six people, resulting in minimal fixed costs and low burn. Its transaction-fee (SaaS + GMV) business model carries little working-capital risk since organiser funds flow through third-party payment processors like Stripe and PayPal. The company has processed over $1 billion in cumulative ticket sales for customers, demonstrating operational maturity and scale. Tito's customer base of annually recurring B2B tech and developer conferences (Shopify, Mozilla, SmashingConf, DjangoCon, etc.) provides quasi-subscription revenue characteristics with high stickiness. The company was funded through Enterprise Ireland and small angel investment rather than VC, meaning no runway pressure or growth-at-all-costs mandate. It notably survived COVID-19, when the events industry collapsed and several venture-funded competitors failed. Key risks include heavy concentration in the tech/developer-conference vertical, which is exposed to tech-industry cyclicality (2020–2021 pandemic, 2023 tech layoffs). The small team creates significant key-person risk. Competition from far larger, better-capitalised platforms (Eventbrite, Cvent, Hopin, Bevy, Luma, Ticket Tailor) is intense. The absence of public P&L disclosure is itself a counterparty risk factor, and ongoing R&D investment in the new Tito Pro platform introduces execution risk.

Key strengths: Very small, low-overhead team (6 people) with minimal fixed costs, Transaction-fee model with limited working-capital exposure (funds flow through Stripe/PayPal), Sticky recurring B2B conference customers providing quasi-subscription revenue, Non-dilutive funding history (Enterprise Ireland + angels), no VC runway pressure, Deliberate anti-hypergrowth, self-sustaining culture, Over $1B cumulative GMV processed, demonstrating operational scale, Survived COVID-19 industry collapse

Risk factors: Heavy concentration in tech/developer-conference vertical, Event-industry cyclicality and tail risk (pandemics, travel restrictions), Competitive pressure from larger platforms (Eventbrite, Cvent, Hopin, Luma), Key-person risk given team of only 6, No public financials limits counterparty risk visibility, Execution risk on new Tito Pro product launch, FX exposure across USD/EUR/GBP with EUR-reporting entity

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report