Turso
Finland · turso.tech · 7 vendors
Resilience scores
- Digital Sovereignty: 29
- Digital Resilience: 4
- Financial Resilience: 6
Technology vendors
- Clerk, Inc. — Technology — United States
- Datadog, Inc. — Technology — United States
- Google LLC — Technology — United States
- and 7 more
Services catalogue
1 service in catalogue across 1 category; runs on 7 sub-vendors.
- Turso
Insights
Last updated 2026-08-06 · revision 2
7 direct vendors, 185 subvendors
Direct vendors by controlling owner country (sample)
- United States: 5
- Denmark: 1
- Sweden: 1
Subvendors by controlling owner country (sample)
- Romania: 1
- Australia: 2
- United States: 139
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Turso demonstrates high migration readiness, primarily driven by its modern and portable technology stack. The core products, including an open-source SQLite rewrite in Rust (libSQL) and a managed DBaaS (Turso Cloud), are inherently cloud-native and designed for flexibility. The use of Rust, WebAssembly, AWS S3, and S3 Express further underscores a highly adaptable and modern architecture, which significantly eases migration efforts. A major opportunity for migration is the potentially low vendor lock-in; if 'Total Vendors: 0' is taken literally, it implies minimal external vendor dependencies, greatly simplifying any migration. Even if there are vendors for the '12 services' from countries like the US and Denmark, the open-source and portable nature of Turso's core technology mitigates much of the vendor lock-in risk. Challenges include the unknown financial stability, as the lack of revenue and growth data makes it difficult to assess Turso's capacity to fund a significant migration. Additionally, the absence of information on regulatory environment and data residency requirements means potential compliance hurdles or specific architectural considerations for migration are currently unknown.
Compliance
7 in-scope frameworks identified; showing 3.
CPRA — Assessment Required
CCPA/CPRA may apply to Turso given: (1) The legal entity ChiselStrike Inc. is a US Delaware corporation described as 'technically San Francisco based'; (2) California law applies to businesses that collect personal information of California residents and meet threshold criteria (annual gross revenue >$25M, OR buy/sell/share personal information of 100,000+ consumers/households, OR derive 50%+ of revenue from selling personal information); (3) As a cloud DBaaS provider with a global customer base, Turso likely processes personal information of California residents. Risk is MEDIUM because the revenue threshold is uncertain for a startup, but the data volume threshold (100,000+ consumers) may be met given Turso's scale.
Evidence: https://turso.tech/terms-of-use, https://turso.tech/privacy-policy
GDPR (source) — Assessment Required
GDPR is mandatorily applicable because: (1) The HQ country provided is Finland, an EU member state, meaning Turso has an EU establishment triggering GDPR Article 3(1); (2) The CTO Pekka Enberg is Finnish and the company describes itself as globally distributed including EU presence; (3) As a cloud DBaaS provider, Turso processes personal data of EU/EEA residents both as a data controller (employee/customer account data) and as a data processor (customer databases may contain personal data of EU residents); (4) Risk is HIGH because non-compliance with GDPR can result in fines up to €20M or 4% of global annual turnover, and cloud/digital service providers are a priority enforcement sector for EU DPAs. While Turso's Terms of Use reference a Data Processing Agreement (DPA) available to subscribers — a positive GDPR signal — no public DPA, appointed DPO, or GDPR audit evidence has been confirmed. The legal entity is a US Delaware corporation (ChiselStrike Inc.), which adds complexity around EU-US data transfer mechanisms (SCCs, adequacy decisions). Missing information: No public DPA text, no confirmed DPO appointment, no confirmed EU-US transfer mechanism (SCCs/adequacy), no GDPR audit report found.
Evidence: https://turso.tech/terms-of-use, https://turso.tech/privacy-policy, https://trust.turso.tech, https://turso.tech/about
SOC 2 (source) — Assessment Required
SOC2 is highly relevant for Turso as a cloud DBaaS provider. Enterprise customers routinely require SOC2 Type II reports as a condition of procurement. Risk is MEDIUM because: (1) Turso operates a Trust Center via Vanta — a compliance automation platform commonly used to prepare for and maintain SOC2 compliance — suggesting active pursuit of SOC2; (2) No publicly confirmed SOC2 Type I or Type II report has been found; (3) Without SOC2 certification, Turso may face barriers to enterprise customer acquisition and may be unable to satisfy vendor security questionnaires from large customers; (4) The absence of SOC2 is a competitive disadvantage and a risk for customers who rely on Turso for critical data infrastructure.
Evidence: https://trust.turso.tech, https://turso.tech/terms-of-use
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Turso is a VC-backed private database infrastructure startup with no publicly disclosed revenue, EBIT, or equity figures. It is a US Delaware C-corp (formerly ChiselStrike) and does not file audited statements with the SEC or Finnish PRH/Virre. Financial resilience must therefore be inferred from funding quality and investor pedigree rather than disclosed statements. On the positive side, the company is well-capitalized for its stage, having raised approximately $7M seed (led by Andreessen Horowitz) in 2021 and a reported ~$25M Series A in 2024 led by Norwest Venture Partners, with participation from Blumberg Capital, Essence VC, Jamstack Innovation Fund, and notable founder-angels from Vercel, GitHub, Netlify, and Datadog. The founding team (Glauber Costa, Pekka Enberg) has strong technical pedigree from ScyllaDB and Linux kernel work, reducing execution risk. Named customers include Vercel, Prisma, Val Town, Adaptive AI, Kin, and Spice AI. Risks include lack of financial transparency, likely pre-profitability typical of Series A infrastructure startups, intense competition (Cloudflare D1, Neon, PlanetScale, Supabase, SQLite Cloud), open-source cannibalization risk given the Apache-licensed core, and a July 2026 strategic pivot signal (building Postgres in Rust) that may indicate difficulty monetizing SQLite-only. Overall, the company appears to have adequate runway and investor support but lacks the disclosure needed for a higher confidence score.
Key strengths: Well-capitalized Series A (~$25M) led by Norwest Venture Partners in 2024, Strong investor base including a16z (seed), Blumberg, Essence VC, Jamstack Innovation Fund, Founder pedigree from ScyllaDB, Datadog, and Linux kernel background, Recurring-revenue SaaS/usage-based business model via Turso Cloud, Named customer traction with Vercel, Prisma, Adaptive AI, Kin, Spice AI, Differentiated 'database-per-agent' positioning for AI wave, Open-source community with 277+ GitHub contributors
Risk factors: No public financials — unit economics, gross margin, burn, and runway unknown, Likely pre-profitability at Series A stage, Intense competition from Cloudflare D1, Neon, PlanetScale, Supabase, SQLite Cloud, hyperscalers, Open-source cannibalization risk (Apache-licensed core is self-hostable), Strategic pivot signal — July 2026 Postgres-in-Rust announcement may indicate SQLite monetization challenges, Concentration on AI-agent narrative vulnerable to shifts in AI infrastructure spending, Prior pivot from ChiselStrike (TypeScript backend) to Turso indicates earlier product-market fit challenges
Revenue by product/service
- Turso Cloud (managed SQLite): 100%
- Turso (open-source embedded): 0%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.