Umami

United States · umami.is · 16 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 16 sub-vendors.

Insights

Last updated 2026-06-11 · revision 1

16 direct vendors, 230 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Umami demonstrates high migration readiness due to its highly modern and cloud-native oriented tech stack. The use of Next.js, Node.js, React, and TypeScript indicates a contemporary web development approach. Crucially, the inclusion of Docker signifies containerization, which greatly facilitates portability across different cloud environments. The use of Vercel also suggests experience with cloud deployment platforms. PostgreSQL and MySQL are widely supported databases, further aiding migration. The primary challenges for migration readiness stem from the lack of data regarding financial stability (revenue concentration, growth history), which could impact the ability to fund a migration project. Similarly, "Regulatory Environment: []" and "Data Residency Requirements: Not specified" mean potential compliance hurdles are unknown. While "Total Vendors: 0" is stated, the reliance on "Total Services: 9" with "Vendor HQ Countries: United States" and "Vendor Geographic Diversity: 1 unique countries" suggests a concentration of service providers. This could introduce some complexity if a migration requires moving away from US-centric services or if there are unstated vendor lock-in risks ("Vendor Lock-in Risk: Unknown"). Despite these unknowns, the highly modern and containerized tech stack is a significant enabler for migration, placing Umami in the "high readiness" category. The unknowns regarding financials, regulatory compliance, and potential vendor lock-in prevent a perfect score but do not outweigh the strong technical foundation.

Compliance

3 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

As a web analytics platform processing personal data (IP addresses, user behavior data, potentially PII), GDPR applies if they process data of EU/EEA residents. Given their global reach as a Google Analytics alternative, they likely process EU resident data. Non-compliance could result in fines up to 4% of annual turnover or €20M. The privacy-focused positioning suggests awareness of GDPR requirements, but compliance status needs verification.

SOC 2 (source) — Assessment Required

SOC2 is highly relevant for cloud service providers handling customer data. As Umami offers cloud analytics services, customers would expect SOC2 Type II compliance for security, availability, and confidentiality. While not legally mandated, lack of SOC2 certification could impact customer trust and enterprise sales, representing moderate business risk.

ISO 27001 (source) — Assessment Required

ISO 27001 is not legally required but is industry best practice for information security management, especially for companies handling personal data. For a privacy-focused analytics platform, ISO 27001 certification would strengthen customer confidence and competitive positioning. Risk is moderate as it affects market credibility rather than legal compliance.

Financials

Financial Resilience Score: 5/10

Umami's financial resilience cannot be objectively quantified due to the absence of any disclosed financial statements. As a private, US-based open-source/SaaS company, Umami has no SEC filings, no published revenue, EBIT, equity, or cash flow data. Any assessment must rely on qualitative signals from the business model and competitive positioning. On the positive side, Umami benefits from a strong open-source distribution moat with one of the largest GitHub footprints in the privacy-analytics category, providing low-cost customer acquisition. The company rides tailwinds from privacy regulation (GDPR, ePrivacy) and the discontinuation of Universal Analytics, which drives demand for cookie-free GA4 alternatives. The lean operating model typical of bootstrapped analytics SaaS companies (similar to Plausible and Fathom) suggests capital efficiency and predictable recurring revenue via subscription pricing. However, significant risks weigh on resilience: intense competition from better-funded peers (Plausible, Fathom, Simple Analytics, PostHog, Matomo, Cloudflare Web Analytics), structural cannibalization from the free self-hosted version limiting OSS-to-Cloud conversion, key-person/founder dependence, and platform risk from Google's privacy moves and browser-level analytics features. With no disclosed runway or balance sheet data, a mid-range score reflects the balanced but unverifiable position.

Key strengths: Strong open-source distribution moat with tens of thousands of GitHub stars, Tailwind from privacy regulation (GDPR, ePrivacy) and GA4 alternatives demand, Lean, capital-efficient operating model typical of bootstrapped SaaS, Recurring revenue from Umami Cloud SaaS subscription tiers (Pro, Enterprise), Self-serve SaaS model with predictable cash flow potential

Risk factors: Intense competition from Plausible, Fathom, Simple Analytics, PostHog, Matomo, and Cloudflare, Open-core cannibalization limits OSS-to-Cloud conversion rates, Key-person/founder concentration risk typical of small private companies, No disclosed financials, runway, or balance sheet data, Big-tech platform risk from Google Consent Mode v2, GA4, and browser-level analytics

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report