Upsales AB

Sweden · www.upsales.com · 18 vendors

Upsales Technology AB is a Swedish software company that provides an AI-powered B2B revenue platform. It offers cloud-based solutions for CRM, marketing automation, sales analytics, and subscription billing. The platform helps businesses find new leads, win more deals, and grow existing customer accounts.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 2 categories; runs on 18 sub-vendors.

Insights

Last updated 2026-07-23 · revision 12

18 direct vendors, 279 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Upsales has a foundation for migration with existing 'Cloud hosting' and 'Cloud SaaS' components, and the use of 'REST API' suggests a degree of modularity. Strong financial health (consistent growth, 95% recurring revenue) provides the capacity to fund migration efforts. However, significant challenges exist. The 'Swedish Co-Location' implies a hybrid environment, meaning a full cloud migration might involve re-platforming legacy components. The most critical factor is the stringent data residency requirements, mandating primary processing within the EU/EEA and relying on EU-US Data Privacy Framework or SCCs for international transfers. This severely limits flexibility in choosing new cloud regions or providers and adds complexity to ensuring continued compliance during and after migration. The 'Unknown' vendor lock-in risk, despite 25 services, remains a potential hurdle. The absence of SOC2 and ISO 27001 certifications also suggests that security controls might need significant uplift and documentation before a major migration. These factors collectively place migration readiness in the medium range, leaning lower due to the data residency constraints.

Compliance

8 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 (International Standard on Assurance Engagements) is used for non-financial assurance reporting, including GDPR compliance attestations, sustainability reporting, and other non-financial subject matters. For a B2B SaaS company like Upsales, ISAE 3000 could be relevant in the context of: (1) GDPR compliance attestation reports (increasingly requested by enterprise customers); (2) Data processing assurance for customers requiring third-party validation of data processor obligations. The risk level is Low because ISAE 3000 is not legally mandated for Upsales' industry or size, and its absence does not create direct regulatory risk. However, it may be commercially relevant as enterprise customers increasingly request assurance reports on data processing practices.

Evidence: https://www.upsales.com/legal/privacy-policy/, https://www.upsales.com/legal/product-privacy-policy/

GDPR (source) — Partially Compliant

Upsales AB is headquartered in Sweden (EU), processes extensive personal data both as a data controller (website visitors, customers, suppliers, employees) and as a data processor (customer CRM data). Their published privacy policy is detailed and references GDPR articles explicitly, demonstrating active compliance efforts. However, no formal third-party GDPR audit or DPO appointment is publicly disclosed. The company transfers personal data to the US (Google, Meta, LinkedIn, X, Cookiebot, feedback service provider) relying on the EU-US Data Privacy Framework adequacy decision — a mechanism that carries residual legal risk given ongoing legal challenges in EU courts. The risk level is Medium rather than High because the company has clearly invested in GDPR compliance infrastructure (detailed privacy policy, cookie consent management via Cookiebot, Standard Contractual Clauses as fallback, data minimisation practices), but the absence of a publicly named DPO, formal audit evidence, and reliance on the contested EU-US DPF mechanism introduce moderate residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover.

Evidence: https://www.upsales.com/legal/privacy-policy/, https://www.upsales.com/legal/product-privacy-policy/, https://www.upsales.com/legal/cookie-policy/, https://www.imy.se/en/, https://commission.europa.eu/system/files/2023-07/Adequacy%20decision%20EU-US%20Data%20Privacy%20Framework_en.pdf, https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en

Swedish Marketing Act — Partially Compliant

The Swedish Marketing Act governs commercial marketing practices, including direct marketing and the right to opt out. Upsales AB conducts B2B marketing (newsletters, email campaigns, event invitations) and explicitly references compliance with marketing legislation in their privacy policy, including maintaining an 'unsubscribe-list' as required by law. The risk level is Low because the company has documented compliance mechanisms and the B2B marketing context carries lower regulatory risk than B2C marketing.

Evidence: https://www.upsales.com/legal/privacy-policy/, https://www.upsales.com/legal/cookie-policy/

Financials

Three-year financials

Financial Resilience Score: 8/10

Upsales Technology AB exhibits a high-quality financial profile for a small-cap SaaS company. The business is characterized by ~95% recurring subscription revenue, mostly billed annually in advance, providing strong cash-flow visibility and favorable working capital dynamics (MSEK 76.4 in accrued/prepaid income at year-end 2025). The company has no interest-bearing debt (only a small lease liability of MSEK 2.78) and holds MSEK 37 in net cash. Operating cash flow has been consistently strong at MSEK 30-35 across the last three years, comfortably exceeding capex and capitalised development costs. Management reports 22 consecutive years of profitability, and the company was bootstrapped without VC funding. However, the equity base is small (MSEK 18.3 at year-end 2025) and has been shrinking due to aggressive dividend payouts (~MSEK 25/year) that exceeded net income. The Board has now reduced the 2025 dividend proposal to SEK 0.75/share to prioritize growth investment. The 2023 ARR contraction (-3.7%) demonstrated that sales-execution missteps can materially damage a small SaaS despite sticky subscriptions, and the company has undergone recent leadership changes (new CEO May 2026, new CFO December 2025) and a December 2025 restructuring removing ~14 product positions. Concentration risk is meaningful given the small headcount (67), narrow Nordic/Swedish mid-market focus, and competitive pressure from Salesforce, HubSpot, and Microsoft Dynamics. Balance sheet resilience is high; operating resilience is moderate.

Key strengths: ~95% recurring subscription revenue with annual prepayment, Zero interest-bearing debt; MSEK 37 net cash position, 22 consecutive years of profitability, Consistent operating cash flow of MSEK 30-35 per year, Founder-led with ~44-45% insider ownership, Bootstrapped, never raised VC funding, ARR growth reaccelerated to +7.8% in 2025, High EBITDA margin (25.4% in 2025)

Risk factors: Small absolute equity base (MSEK 18.3) eroded by dividends exceeding net income, Small headcount (67) creating key-person and execution concentration, Recent CEO and CFO transitions plus December 2025 restructuring, Rising capitalised R&D (MSEK 17.1 vs 7.1) inflates reported EBITDA vs cash, Narrow geographic concentration in Sweden/Nordics, Competitive pressure from Salesforce, HubSpot, Microsoft Dynamics, Thin trading liquidity on First North Growth Market, Aira spin-off in 2026 introduces execution risk and changes reporting perimeter, 2023 ARR contraction demonstrated vulnerability to sales-execution missteps

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report