Trezor

Czech Republic · trezor.io · 18 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 18 sub-vendors.

Insights

Last updated 2026-08-08 · revision 7

18 direct vendors, 258 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Trezor exhibits medium migration readiness, scoring 40 out of 100. **Strengths:** * **Modern and Flexible Tech Stack:** Trezor's internal tech stack, featuring Next.js, React, TypeScript, Electron, and React Native, is relatively modern and adaptable. The use of open-source components like firmware, Trezor Blockbook, and the TROPIC01 secure element reduces proprietary lock-in for core technologies, offering more flexibility for potential migrations. * **Some Cloud Adoption:** The use of Cloudflare for CDN and image delivery indicates existing integration with cloud services, which can ease future cloud migration efforts. * **Vendor Geographic Diversity:** The geographic diversity of vendor headquarters across 6 countries (United States, Czech Republic, France, Germany, Malta, Denmark) suggests that Trezor is not solely reliant on a single regional vendor ecosystem, potentially offering more options during vendor transitions in a migration scenario. **Weaknesses:** * **Complex and High-Risk Regulatory Environment:** The most significant challenge to migration readiness is Trezor's complex and high-risk regulatory landscape. Regulations such as GDPR, MiCA, AML/CFT, and the EU Cyber Resilience Act are all 'Assessment Required' with 'High' risk. Any migration, especially involving data or infrastructure changes, would necessitate rigorous compliance planning, legal reviews, and potentially costly adjustments to ensure adherence to these stringent EU regulations, particularly concerning data residency and cross-border data transfers. * **Strict Data Residency Requirements:** As an EU-based company, Trezor is subject to GDPR's strict Chapter V restrictions on international data transfers. Any migration involving moving data outside the EU/EEA would require robust legal mechanisms (e.g., SCCs, DPF certification) and careful documentation, adding complexity and potential delays. * **Unknown Financial Stability:** The lack of available revenue data makes it difficult to assess Trezor's financial capacity to fund a significant migration project, which can often be a substantial undertaking in terms of cost and resources. * **Vendor Lock-in (Uncertainty):** While open-source components mitigate some lock-in, the reliance on specific SaaS providers (e.g., Sentry, Cloudflare, Vimeo, GitHub, Cocuma) for 26 services, combined with the 'Vendor Lock-in Risk: Unknown' status, introduces uncertainty regarding the ease and cost of switching these services during a migration. The contradiction of 'Total Vendors: 0' with other vendor data makes a precise assessment difficult, but the number of services suggests a moderate dependency on external providers.

Compliance

8 in-scope frameworks identified; showing 3.

Czech Consumer Protection Act — Partially Compliant

Risk is Medium because: (1) Trezor operates a global e-commerce platform selling hardware products to consumers in the EU and worldwide; (2) Czech consumer protection law and EU Consumer Rights Directive (2011/83/EU) apply to Trezor's e-shop operations; (3) Trezor publishes Terms of Use, returns policy, and warranty information — indicating awareness of consumer protection obligations; (4) however, the complexity of crypto-asset products and the 'no liability' clauses in Trezor's terms may conflict with EU consumer protection requirements; (5) Czech Trade Inspection Authority (ČOI) supervises consumer protection compliance; (6) risk is Medium rather than High because Trezor appears to have basic consumer protection infrastructure in place.

Evidence: https://trezor.io/terms-of-use, https://trezor.io/returns, https://trezor.io/documents/trezor_shop_terms_and_conditions.pdf

AML — Assessment Required

AML/CFT risk is High because: (1) Trezor operates in the cryptocurrency sector, which is a high-risk sector for money laundering and terrorist financing per FATF guidance and EU AMLD; (2) Trezor Suite facilitates crypto buy/sell/swap transactions, which may trigger 'obliged entity' status under Czech AML Act No. 253/2008 Coll. (implementing AMLD6); (3) the EU's Transfer of Funds Regulation (TFR, Regulation 2023/1113) — the 'travel rule' — applies to crypto-asset transfers and may impose obligations on Trezor's transaction facilitation services; (4) Czech Financial Intelligence Unit (FAÚ) and ČNB supervise AML compliance in the crypto sector; (5) FATF's 2021 updated guidance on virtual assets explicitly addresses hardware wallet providers and their potential VASP status; (6) penalties for AML non-compliance in Czech Republic can reach CZK 10 million or 10% of annual turnover.

Evidence: https://trezor.io/trezor-suite, https://trezor.io/terms-of-use, https://www.fatf-gafi.org/en/publications/Virtualassets/Guidance-RBA-virtual-assets-2021.html, https://www.fau.cz/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R1113

NIS2 (source) — Assessment Required

NIS2 risk is Medium because: (1) Trezor is an EU-based digital product and software provider (Trezor Suite app, cloud-connected services, firmware updates) which may qualify as a 'digital provider' or fall under the 'digital infrastructure' or 'ICT service management' categories under NIS2 Annex I/II; (2) Trezor has 110+ employees, meeting the medium enterprise threshold (50+ employees) for NIS2 applicability; (3) however, Trezor's primary business is hardware manufacturing and self-custody software — it does not operate critical infrastructure in the traditional sense (e.g., it is not a cloud computing provider, DNS resolver, or online marketplace in the NIS2 sense); (4) Czech Republic transposed NIS2 via Act No. 181/2014 Coll. (Cybersecurity Act), updated in 2024; (5) the Czech National Cyber and Information Security Agency (NÚKIB) is the competent authority; (6) non-compliance penalties under Czech NIS2 transposition can reach CZK 250 million (~€10 million) or 2% of global turnover. The 'Assessment Required' status reflects genuine ambiguity about whether Trezor's digital services cross the NIS2 threshold for 'Important Entity' classification.

Evidence: https://trezor.io/company, https://trezor.io/trezor-suite, https://nukib.gov.cz/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://trezor.io/security

Financials

Three-year financials

Financial Resilience Score: 7/10

Trezor demonstrates strong structural financial resilience despite the absence of publicly verified financial statements. The company is 100% self-funded with no venture capital or external debt, giving it significant strategic flexibility and reducing solvency risk. As the pioneer of the hardware wallet category (since 2013/2014), it holds a defensible market position with 2M+ users, strong brand loyalty, and a diversified product ladder spanning entry-level (Safe 3) to premium (Safe 7) devices, plus accessories and software services. Industry reporting suggests the company has been consistently profitable with revenue in the hundreds of millions of CZK during peak crypto cycles. However, resilience is meaningfully tempered by the company's exposure to crypto market cyclicality — hardware wallet demand spikes during Bitcoin bull markets and slumps in bear markets, creating high revenue volatility. Revenue is also concentrated in a single product category (hardware wallets) tied to a single industry (crypto self-custody). Competitive pressure from Ledger (much larger by units) and a growing field of new entrants (BitBox, Coldcard, Keystone, Tangem) presents ongoing margin pressure. Regulatory uncertainty (EU MiCA, potential travel-rule extensions) and catastrophic security-incident risk further constrain the resilience score. Without verified financials, a mid-to-upper score reflects strong qualitative fundamentals balanced against unverifiable quantitative data.

Key strengths: 100% self-funded with no VC investors or external debt, Category pioneer with 12+ years of operating history, 2M+ users and strong brand loyalty (4.7 Trustpilot rating), Diversified product ladder (Safe 3/5/7, Keep Metal, Trezor Suite), Recurring/adjacent revenue from in-app buy/sell/swap/stake services, Vertically integrated with in-house Secure Element (Tropic01 via Tropic Square), Global multi-language distribution (7 languages), Industry standards authorship (BIP39, BIP44, SLIP39)

Risk factors: High revenue cyclicality tied to crypto market sentiment, Concentrated in a single product category and industry, Intense competition from Ledger and new entrants (BitBox, Coldcard, Keystone, Tangem, OneKey), Regulatory risk from EU MiCA and potential self-custody restrictions, Security incident/supply-chain compromise could catastrophically damage brand, Limited external financial transparency as a private s.r.o., Small headcount (~110) relative to larger competitors

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report