Unily
UK · www.unily.com · 14 vendors
Unily is an enterprise Employee Experience Platform that provides intranet software and internal communications solutions for large, complex organizations. It aims to connect, engage, and empower employees through a unified digital workplace, fostering collaboration and knowledge sharing. The platform offers AI-powered capabilities to improve productivity and engagement across distributed and frontline workforces.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Anthropic, PBC — Technology — United States
- EasyDMARC Inc. — Cybersecurity — United States
- HubSpot, Inc. — Technology — United States
- and 12 more
Services catalogue
2 services in catalogue across 2 categories; runs on 14 sub-vendors.
- Employee experience platform
- Personal Data Processing
Insights
Last updated 2026-07-29 · revision 1
14 direct vendors, 177 subvendors
Direct vendors by controlling owner country (sample)
- United States: 12
- Denmark: 1
- Sweden: 1
Subvendors by controlling owner country (sample)
- Germany: 5
- Denmark: 2
- Canada: 6
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Unily exhibits high migration readiness, largely attributable to its highly modern and cloud-native technology stack. Its foundation on "Microsoft Azure" as a "Cloud SaaS Platform" with "CI/CD pipelines" and an "Open Integration Framework" using "REST APIs" suggests a flexible, modular, and interoperable architecture. This technical setup significantly reduces the complexity and effort typically associated with system migrations. Furthermore, the company's adherence to stringent security and compliance frameworks (ISO 27001, SOC 2 Type II) indicates mature internal processes for managing data and systems, which would streamline any migration effort. While the assessment lacks data on financial stability (ability to fund migration) and specific data residency requirements, these are critical factors that would need to be evaluated for a comprehensive migration plan. The vendor relationships, indicating 8 services from vendors in 2 countries, suggest moderate vendor diversity. Although there's a strong reliance on the Microsoft ecosystem (Azure, Microsoft 365), the presence of an open integration framework mitigates potential platform-specific lock-in risks, especially for migrations within cloud-native environments.
Compliance
10 in-scope frameworks identified; showing 3.
Australian Privacy Act 1988 — Compliant
Unily has a registered Australian entity (Unily Australia Pty Ltd, Neutral Bay NSW) and explicitly addresses Australian privacy law in its Privacy Notice, including references to the Privacy Act 1988 (Cth), the Office of the Australian Information Commissioner (OAIC), and Australian-specific provisions for sensitive information and data subject rights. Risk is Low because: (a) Unily proactively addresses Australian privacy law in its Privacy Notice; (b) an Australian legal entity is registered; (c) complaint escalation to the OAIC is documented; (d) Australian-specific provisions (e.g., sensitive information consent requirements) are addressed.
Evidence: https://www.unily.com/policies/privacy-hub/privacy-notice
Cyber Essentials — Compliant
Unily holds a current Cyber Essentials certification, which is a UK Government-backed scheme administered by the National Cyber Security Centre (NCSC). This certification is a mandatory requirement for Unily to supply services to UK Government and Public Sector organisations. Risk is Low because: (a) certification is current and publicly verifiable; (b) Cyber Essentials is a baseline security certification covering five key controls (boundary firewalls, secure configuration, access control, malware protection, patch management); (c) Unily's broader security posture (ISO 27001, SOC 2 Type II) significantly exceeds Cyber Essentials requirements.
Evidence: https://www.unily.com/policies/privacy-hub/security-certifications, https://www.unily.com/hubfs/Unily%20theme%20SpotDev%202025/Policies/unily-cyber-essentials-certificate.pdf
GDPR (source) — Compliant
Unily demonstrates a mature, well-documented GDPR compliance posture. Evidence includes: a formally published Privacy Notice (updated April 2025) explicitly referencing UK GDPR and EU GDPR; a dedicated Data Protection Officer (DPO) appointed and reachable at privacy@unily.com; an EU Article 27 Representative appointed (BizLegal Limited t/a EU Rep, Cork, Ireland) for EU data subjects; a published Data Protection Addendum (DPA) and Standard Contractual Clauses (SCC) Addendum for international transfers; an intra-group data transfer agreement covering UK/EEA/US/Australia transfers; a published sub-processor list; and a comprehensive Privacy Hub. The company is UK-headquartered (post-Brexit UK GDPR applies) and explicitly processes EU/EEA personal data, making EU GDPR applicable. The breadth and quality of published compliance documentation significantly reduces residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover, but the documented controls and DPO appointment substantially mitigate enforcement risk.
Evidence: https://www.unily.com/policies/privacy-hub/privacy-notice, https://www.unily.com/policies/privacy-hub, https://www.unily.com/policies/privacy-hub/data-protection-addendum, https://www.unily.com/policies/privacy-hub/scc-addendum, https://www.unily.com/policies/privacy-hub/sub-processors, https://www.unily.com/policies/privacy-hub/privacy-faqs
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Unily is a mature, PE-backed UK enterprise-SaaS business with strong qualitative indicators of financial resilience, though no specific financial figures are publicly disclosed on its website. The company benefits from an enterprise SaaS revenue model with multi-year contracts and large ACVs, providing high revenue visibility and predictable recurring cash flows. Its blue-chip, diversified customer base spans aviation, energy, healthcare, financial services, professional services, retail, pharma, and manufacturing, reducing sector-concentration risk. Strong analyst validation from Gartner, Forrester, and IDC MarketScape as a Leader provides a competitive moat and lowers customer acquisition risk. The backing of CVC Capital Partners (majority stake acquired September 2020) provides access to capital for M&A and product investment, including the recent build-out of AI agents Glass and Indi. Unily has a 20-year heritage giving it maturity relative to newer entrants. However, PE ownership typically comes with meaningful debt burden from the buyout, and interest costs and covenants are unknown. The competitive landscape is intense with Microsoft Viva, Staffbase, Simpplr, Firstup, LumApps, Interact, Workvivo, and Happeo, and Microsoft's bundling of Viva with M365 SKUs creates structural pricing risk. AI investment cycles require sustained R&D spend that can pressure near-term margins.
Key strengths: Enterprise SaaS revenue model with multi-year contracts and high revenue visibility, Blue-chip diversified customer base across multiple sectors (Shell, CVS Health, J&J, British Airways, Wipro), Leader positioning in Gartner, Forrester, and IDC MarketScape analyst reports, CVC Capital Partners majority ownership providing capital access, 20-year heritage and mature platform, AI-native product positioning with Glass and Indi agents
Risk factors: Private-equity leverage from CVC buyout with unknown debt burden, Intense competition from Microsoft Viva, Staffbase, Simpplr, LumApps and others, Microsoft bundling Viva with M365 creates structural pricing risk, AI investment cycle pressuring near-term operating margins, FX exposure (USD/GBP) on GBP-reporting entity, Potential customer concentration in enterprise (undisclosed), No public financial disclosure; filings lag by up to 9 months
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.