UX Signals

Norway · uxsignals.com · 6 vendors

UX Signals is a cloud-based platform that helps product teams automatically recruit and schedule user interviews and user tests with people who are using their product. It aims to remove barriers to frequently talking with users and collecting qualitative insights quickly.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 6 sub-vendors.

Insights

Last updated 2026-07-02 · revision 1

6 direct vendors, 94 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

UX Signals shows good potential for migration readiness, primarily due to its core offering being a 'cloud-based SaaS platform'. This suggests a modern architecture, likely leveraging cloud-native principles, which generally facilitates easier migration. The internal use of modern SaaS tools (Sentry, Webflow, Slack) also indicates a familiarity with cloud services and potentially simpler integration/replacement during a migration. GDPR compliance is a known regulatory factor that can be managed during a migration. However, several critical unknowns impact the overall readiness. 'Data Residency Requirements' are not specified, which could introduce significant complexity and cost if strict requirements exist. The 'Vendor Lock-in Risk' is explicitly 'Unknown', which is a major concern as high lock-in could severely impede or complicate migration efforts. Additionally, the lack of financial data (revenue, growth) makes it impossible to assess the company's ability to fund a potentially significant migration project. While only 3 services are used, the geographic concentration of these vendors in the United States could simplify migration if the target environment is also US-centric, but could add complexity if migrating to a different geographic region.

Compliance

7 in-scope frameworks identified; showing 3.

Norwegian Security Act — Assessment Required

Risk is Low. The Norwegian Security Act (Lov om nasjonal sikkerhet) applies to entities classified as critical to national security or that handle classified information. UX Signals is a UX research SaaS tool and does not appear to handle classified information or operate in sectors designated as critical national infrastructure. However, their clients include NAV (a major government agency) and Oslo Kommune, which could theoretically create indirect obligations if UX Signals processes data classified under the Security Act. This is unlikely given the nature of UX research data (user experience feedback), but formal assessment is recommended.

Evidence: https://uxsignals.com, https://lovdata.no/dokument/NL/lov/2018-06-01-24

GDPR (source) — Partially Compliant

GDPR risk is High for UX Signals for several compounding reasons: (1) Their core business model is built entirely around collecting, processing, and managing personal data of end-users on behalf of their clients — this is the very heart of their product. (2) They act as a Data Processor under GDPR (as evidenced by their published EEA Data Processing Agreement v1 March 2024), meaning they carry direct legal obligations under GDPR Articles 28–32. (3) Their clients include major Norwegian public and private sector entities (NAV, DNB, Vipps, Oslo Kommune, Posten Bring, Norsk Tipping, Innovasjon Norge), many of which are themselves subject to strict GDPR obligations and will contractually require UX Signals to be fully compliant. (4) Norway is an EEA member state, making GDPR directly applicable via the EEA Agreement. (5) The platform explicitly handles consent management, data deletion, and personal data of research participants — any failure in these mechanisms could constitute a GDPR breach. (6) Enforcement by Datatilsynet (Norway's DPA) has been active, with significant fines issued to Norwegian companies. Partial compliance is noted because they have a published DPA and built-in consent/deletion features, but no independent audit evidence, DPO appointment, or ROPA documentation is publicly available.

Evidence: https://uxsignals.com, https://docs.google.com/document/d/1MF0P6dt3ycUDYqNfhxQSY1_JHSRqnPXFfjMt7ijrF4Q/, https://docs.google.com/document/d/1H4HPYquLUqU8J1wIK_QMP04CzDo_0duhdYO4LqjGPms/edit?usp=sharing

Norwegian Personal Data Act — Partially Compliant

The Norwegian Personal Data Act (Personopplysningsloven) directly implements GDPR into Norwegian law and adds national-level specifications. Risk is High for the same reasons as GDPR — UX Signals' core business involves processing personal data of Norwegian residents. Datatilsynet (the Norwegian Data Protection Authority) actively enforces this law and has issued significant fines to Norwegian companies. The company's built-in consent and deletion features suggest awareness of obligations, but the absence of a publicly disclosed DPO, privacy policy, and ROPA represents compliance gaps.

Evidence: https://uxsignals.com, https://www.datatilsynet.no/en/, https://lovdata.no/dokument/NL/lov/2018-06-15-38

Financials

Financial Resilience Score: 5/10

UX Signals AS presents a mixed financial resilience profile that cannot be fully quantified due to lack of accessible filed accounts. On the qualitative side, the company demonstrates meaningful strengths: a blue-chip Norwegian customer base including NAV, DNB, Vipps, Posten Bring, Norsk Tipping, Oslo Kommune, and Innovation Norway suggests stable, likely multi-year SaaS contracts with low churn risk. Public-sector and financial-services anchor customers typically provide predictable recurring revenue, which supports resilience for a small SaaS company. However, significant risks weigh against this. The company appears to be a small, founder-led operation with only two named executives and an estimated headcount below 15 FTE, indicating limited scale and potential key-person risk. Revenue appears highly concentrated in Norway with a small number of large enterprise/public accounts, meaning the loss of a single anchor customer could materially impact the business. The company also faces well-funded global competitors (UserTesting, Maze, Dscout, Lyssna, User Interviews) whose scale dwarfs UX Signals'. Its defensibility rests primarily on GDPR-compliant consent management and Nordic localization. Without access to filed årsregnskap from Brønnøysundregistrene, revenue, EBIT, and equity trends cannot be verified. Small Norwegian SaaS AS companies commonly operate at a loss during early years and rely on shareholder funding, so profitability is uncertain. A score of 5 reflects the balance between strong customer references and unverified financial fundamentals combined with concentration and scale risks.

Key strengths: Blue-chip Norwegian customer base (NAV, DNB, Vipps, Posten, Norsk Tipping, Oslo Kommune), GDPR-compliant consent management provides regulatory moat, Lean cost base with small founder-led team, Clear product-market fit indicators from named enterprise practitioners, Single-product SaaS focus with bilingual EN/NO positioning

Risk factors: Small-company scale risk with unverified profitability, Geographic concentration in Norway (likely >90% of revenue), Customer concentration risk among a handful of large accounts, Competition from far larger, better-funded global players, Key-person risk with only two named leaders, No visibility into revenue, EBIT, or equity from filed accounts

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report