Visual Art

Sweden · www.visualart.com · 23 vendors

Visual Art Sweden AB is a global full-service digital signage provider specializing in in-store and retail media solutions. The company offers end-to-end services including strategy, design, software, hardware, content, installation, and support. They help clients worldwide enhance customer engagement, drive sales, and monetize physical channels through their proprietary IXM platform.

Resilience scores

Disruption prediction

Visual Art has an estimated 13% probability of disruption in the next 6 months.

13 of Visual Art's 23 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 23 sub-vendors.

Insights

Last updated 2026-07-30 · revision 8

23 direct vendors, 272 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Visual Art exhibits high migration readiness, primarily driven by its modern and flexible technology stack. Their IXM Platform is a cloud-hosted, API-first, and hardware-agnostic SaaS solution leveraging Amazon Web Services (AWS). This cloud-native architecture, supporting various operating systems (Debian, Samsung Tizen, Android, LG webOS, ChromeOS, Windows 11, iOS, Raspberry Pi), provides inherent flexibility and reduces technical barriers to migration. The company's strong financial growth suggests ample resources to fund potential migration initiatives. Furthermore, their ISO 27001:2022 certification indicates well-defined security processes that would facilitate a secure and structured migration. The geographic diversity of implied vendors (7 countries) also suggests less reliance on a single vendor ecosystem, potentially reducing vendor-related migration complexities. However, significant challenges exist in the regulatory and data residency landscape. Operating across 39 countries, Visual Art must navigate complex GDPR requirements for international data transfers, including the use of Standard Contractual Clauses and the EU-US Data Privacy Framework. Any data relocation during a migration would require meticulous planning to maintain compliance across these diverse jurisdictions. Additionally, while ISO 27001 is in place, the 'Assessment Required' status for SOC2 compliance means that a migration might need to incorporate efforts to meet these additional security requirements, adding a layer of complexity. The 'Unknown' vendor lock-in risk is also a blind spot, as specific vendor contract details are not available to fully assess potential hurdles.

Compliance

8 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

Visual Art Sweden AB is headquartered in Stockholm, Sweden — an EU member state — making GDPR universally applicable. The company processes personal data of employees, customers, suppliers, job applicants, and website visitors across 8+ countries. Their published Privacy Policy (last updated September 2025) demonstrates a structured compliance posture: it identifies lawful bases for each processing purpose, defines retention periods, addresses international data transfers via SCCs and the EU–US Data Privacy Framework, and references the Swedish supervisory authority (IMY). Risk is rated Medium rather than Low because: (1) the company operates in 39 countries with cross-border data flows to the US and India, increasing transfer complexity; (2) their IXM SaaS platform processes data on behalf of enterprise retail clients, creating data processor obligations in addition to controller obligations; (3) no independent GDPR audit or DPO appointment is publicly disclosed, leaving some uncertainty about the depth of operational compliance. Enforcement by IMY (Sweden's DPA) is active, and fines under GDPR can reach €20M or 4% of global annual turnover.

Evidence: https://visualart.com/privacy-policy, https://visualart.com/cookie-policy, https://vertiseit.whistlelink.com/

ISAE 3000 (source) — Assessment Required

ISAE 3000 is the international assurance standard used for non-financial assurance engagements, commonly applied in Europe as an alternative or complement to SOC 2 for reporting on controls at service organisations. Given that Visual Art has completed a SOC 2 Type II audit (the US-equivalent assurance framework) and holds ISO 27001 certification, there is a possibility that European clients or regulators may request ISAE 3000 or ISAE 3402 (controls at service organisations) reporting. However, no evidence of an existing ISAE 3000 engagement has been found. Risk is Low because: (1) the SOC 2 Type II report largely satisfies the same assurance needs; (2) ISAE 3000 is not a mandatory regulatory requirement for Visual Art's industry; (3) the company's ISO 27001 certification provides an internationally recognised alternative assurance mechanism.

Evidence: https://visualart.com/knowledge-hub/why-soc-2-type-ii-matters-for-the-future-of-ixm, https://d2gsqvrtuna5bz.cloudfront.net/2026/01/vertiseit-ab_iso-27001-2.pdf

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into Swedish law via the Cybersäkerhetslagen effective 2024) may apply to Visual Art as a digital service provider. The company operates the IXM SaaS platform used by global retailers across 39 countries, which could qualify it as a 'digital provider' (specifically a managed service provider or cloud computing service provider) under NIS2 Annex II (Important Entities). The company's parent group, Vertiseit AB, is listed on Nasdaq First North Growth Market, suggesting it likely exceeds the 50-employee / €10M turnover thresholds for NIS2 applicability. Risk is Medium because: (1) the digital provider classification requires formal legal assessment; (2) NIS2 non-compliance in Sweden carries administrative fines up to €10M or 2% of global turnover for Important Entities; (3) the company's existing ISO 27001 certification and SOC 2 Type II audit significantly reduce the likelihood of substantive non-compliance even if formally subject to NIS2. A formal NIS2 scoping assessment by Swedish legal counsel is recommended.

Evidence: https://visualart.com, https://d2gsqvrtuna5bz.cloudfront.net/2026/01/vertiseit-ab_iso-27001-2.pdf, https://visualart.com/knowledge-hub/why-soc-2-type-ii-matters-for-the-future-of-ixm

Financials

Three-year financials

Financial Resilience Score: 7/10

Visual Art Sweden AB benefits from being a subsidiary of Vertiseit AB (publ), a Nasdaq First North Growth Market listed Swedish company, which provides access to capital markets, audited group reporting transparency, and financial backing beyond what a standalone SME would enjoy. The company operates a recurring SaaS-like revenue base through its proprietary IXM (In-Store Experience Management) platform, which reportedly manages approximately 85,000–100,000 active software licenses across 39 countries. This subscription/software-driven model typically produces sticky, high-margin revenue streams that enhance resilience through economic cycles. The company's blue-chip customer roster spans multiple industries including QSR (McDonald's, KFC, Subway), retail (ICA, Kesko, Salling Group, 7-Eleven), fuel/convenience (Circle K, Preem, OKQ8), automotive (Audi, NIO), electronics (Samsung, LG), and banking (SEB), which diversifies customer concentration risk. ISO 9001, ISO 14001, ISO 27001 certifications and SOC 2 Type II work strengthen its position for enterprise contracts. The company self-reports 'doubling revenue over the past years,' indicating strong growth momentum. However, risks include retail cyclicality (digital signage capex is discretionary), a crowded competitive landscape (Broadsign, STRATACACHE/Scala, Samsung VXT, LG webOS), FX exposure across eight countries, potential QSR customer concentration, and small-cap liquidity at the parent level as Vertiseit trades on First North rather than the main Nasdaq list. Exact financial figures were not verifiable in this session, limiting definitive assessment.

Key strengths: Subsidiary of Nasdaq First North listed Vertiseit AB (publ) providing capital market access, Recurring SaaS-like revenue base with ~85,000–100,000 active software licenses across 39 countries, Diversified blue-chip customer roster across QSR, retail, automotive, banking, and real estate, ISO 9001, ISO 14001, ISO 27001 certifications plus SOC 2 Type II compliance, Two-brand group model (Grassfish/Dise platforms + Visual Art solutions) enabling internal R&D scale, Self-reported doubling of revenue over recent years, Presence in 8 countries across Nordics, DACH, Iberia, UK and North America

Risk factors: Retail and QSR cyclicality — digital signage capex is discretionary, Crowded competitive market (Broadsign, STRATACACHE/Scala, Samsung VXT, LG webOS, Signagelive), FX exposure across SEK, NOK, DKK, EUR, GBP, USD, Potential customer concentration within QSR master agreements, Small-cap liquidity risk at parent level (Nasdaq First North, not Main Market), Hardware pass-through revenue typically lower margin than software

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report