UserVoice, Inc.
United States · uservoice.com · 17 vendors
Resilience scores
- Digital Sovereignty: 65
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Adobe Inc. — Technology — United States
- Demandware — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 14 more
Services catalogue
3 services in catalogue across 3 categories; runs on 17 sub-vendors.
- Eptura Workplace
- Personal Data Processing
- UserVoice
Insights
Last updated 2026-08-05 · revision 2
17 direct vendors, 295 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- Poland: 1
- Sweden: 1
Subvendors by controlling owner country (sample)
- South Korea: 1
- Brazil: 1
- United Kingdom: 9
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
UserVoice, Inc. exhibits a high level of migration readiness, scoring 80. The company's internal tech stack is highly conducive to migration, featuring a multi-cloud strategy (GCP and AWS) and extensive use of Docker for containerization. This indicates a modern, cloud-native approach that facilitates portability and reduces infrastructure-level vendor lock-in. The adoption of AI/ML, NLP, and REST APIs further points to a flexible and modular architecture. While the extensive regulatory compliance (SOC 2, GDPR, PCI-DSS) means more requirements to consider during migration, the fact that these frameworks are already established suggests mature processes and controls are in place, which can streamline compliance efforts in a new environment. Data residency requirements are not specified, which could be a hidden complexity if strict rules apply. The main challenges and unknowns for migration readiness stem from vendor relationships: while vendor geographic diversity is good, the total number of vendors is unclear (stated as 0 but 21 services are listed), and the specific vendor lock-in risk for these 21 services is unknown. A high number of services could imply complex integrations that might need to be re-architected during a migration. Financial stability (revenue concentration, growth history) is also unknown, which could impact the ability to fund a significant migration effort.
Compliance
7 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
UserVoice explicitly self-declares GDPR compliance and has implemented a comprehensive GDPR compliance program. They have a dedicated GDPR compliance page, a published Data Processing Agreement (DPA), a designated Data Protection Officer (DPO) contact (dpo@uservoice.com), documented data subject rights mechanisms (right to access, portability, erasure/opt-out), consent collection tooling, breach notification procedures (48-hour notification), and a sub-processor list. They operate as both a data controller and data processor. The EU-US and Swiss-US Privacy Shield certification (now superseded by the EU-US Data Privacy Framework) is also referenced. Risk is Low given the depth of documented compliance measures, though self-declaration without a third-party GDPR audit means some residual risk remains.
Evidence: https://uservoice.com/gdpr-compliance, https://uservoice.com/security-compliance, https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000XZoMAAW&status=Active, https://cdn.prod.website-files.com/60d5fccd073e73765ce22806/65e18684da5fed0d4d48bbae_UserVoice%20DPA%20(2024%20Current).pdf
CCPA — Assessment Required
UserVoice is headquartered in the United States (Raleigh, NC) and serves US-based businesses and consumers. As a SaaS company processing personal data of California residents (both as a data processor for its business customers and potentially as a data controller for its own users), CCPA/CPRA may apply. The CCPA applies to for-profit businesses that: (1) have annual gross revenues over $25M, OR (2) buy, sell, or share personal information of 100,000+ consumers/households annually, OR (3) derive 50%+ of annual revenues from selling/sharing personal information. UserVoice's revenue and user base size are not publicly disclosed, making a definitive determination impossible without further information. Risk is Medium because non-compliance with CCPA carries civil penalties of up to $7,500 per intentional violation.
Evidence: https://uservoice.com/privacy, https://uservoice.com/security-compliance
ISO 27001 (source) — Assessment Required
No ISO 27001 certification is mentioned anywhere on UserVoice's public-facing compliance pages, security page, or terms of service. UserVoice has chosen SOC 2 Type II as its primary information security assurance framework, which is common for US-based SaaS companies. ISO 27001 is more prevalent in European markets. The absence of ISO 27001 certification is not unusual for a US-headquartered SaaS company of this size, but it may be a gap for enterprise customers (particularly in Europe) who require ISO 27001. Risk is Medium because the absence of ISO 27001 could be a procurement barrier for EU/global enterprise customers, even though SOC 2 Type II provides comparable assurance.
Evidence: https://uservoice.com/security-compliance
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
UserVoice is a mature (~17-year-old) private SaaS company owned by Curious Holdings, a permanent-capital holding company that acquires software businesses in the $1M–$5M revenue range. No audited financials are publicly disclosed since the company is not an SEC registrant and its parent does not publish portfolio-company financials. This creates significant opacity for external assessment. Resilience is supported by long operating tenure, an established brand in the product-feedback category, enterprise customer stickiness (multi-year contracts with clients like Optimizely and Freewheel), SOC 2 Type 2 and GDPR compliance that eases enterprise procurement, and a diversified integration ecosystem (Salesforce, Zendesk, Jira, Gainsight, Slack, Azure DevOps, Gong). The permanent-capital ownership model reduces refinancing and forced-exit risk relative to PE-backed peers. However, the small revenue scale ($1M–$5M range) implies limited cash cushion and vulnerability to customer churn. The company also faces well-funded competitors (Productboard, Canny, Aha!, Enterpret) and potential category disruption from generative AI. Post-acquisition transition risk exists as the founder has departed and the product is being repositioned as a 'customer intelligence platform.'
Key strengths: 17-year operating history and established brand, Permanent-capital ownership by Curious Holdings reduces forced-exit risk, Enterprise SaaS revenue stickiness with multi-year contracts, SOC 2 Type 2 and GDPR compliance supports enterprise sales, Diversified integration ecosystem (Salesforce, Zendesk, Jira, etc.), Named enterprise customers including Optimizely and Freewheel
Risk factors: Small revenue scale ($1M–$5M) limits cash cushion, Vulnerability to loss of a few large customers, Crowded competitive set with well-funded rivals (Productboard, Canny, Aha!, Enterpret), Generative AI category disruption risk, Post-acquisition repositioning and founder departure transition risk, Zero public financial disclosure creates counterparty opacity
Revenue by geography
- North America: 100%
Revenue by product/service
- Customer Intelligence / Feedback SaaS Platform: 100%
Workforce by country
- United States: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.