Web of Trust

Israel · www.mywot.com · 10 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 10 sub-vendors.

Insights

Last updated 2026-08-17 · revision 4

10 direct vendors, 203 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Web of Trust demonstrates medium-low migration readiness, largely hampered by an exceptionally complex regulatory and data residency landscape. The company faces 'High Risk' or 'Partially Compliant' statuses across numerous privacy regulations (GDPR, UK GDPR, CCPA/CPRA, ePrivacy Directive, NIS2, Israeli PPL, US State Privacy Laws). These regulations impose stringent requirements on data processing, consent, and cross-border transfers, making any large-scale migration effort extremely challenging and costly due to the need for extensive data mapping, legal reviews, and re-architecting for compliance. Data residency requirements are a major constraint, with explicit processing in the EEA, US, and internationally, reliance on Standard Contractual Clauses (SCCs), and significant Schrems II compliance risks. The potential for data localization requirements in any of its 79 countries of operation further complicates data movement and infrastructure planning during a migration. The lack of financial data (revenue, employees) makes it impossible to assess the company's ability to fund a potentially expensive and resource-intensive migration. While the tech stack includes modern elements such as a RESTful API, Android SDK, and integration with cloud-based services like Google Analytics, Stripe, and PayPal, suggesting some architectural modularity, the absence of explicit mention of containerization or microservices means the extent of cloud-native readiness is unclear. Vendor lock-in is moderate, with approximately 11 distinct vendors identified in the internal tech stack. The presence of WordPress (Elementor) could also introduce specific migration challenges depending on its integration depth. The lack of SOC2 or ISO 27001 certifications also suggests a less mature security framework, which could complicate the secure migration of sensitive user data. Overall, the overwhelming regulatory and data residency complexities are the primary inhibitors to high migration readiness.

Compliance

9 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

WOT provides cloud-based security services (browser extension backend, website reputation API, mobile apps) to millions of users and enterprise API customers. SOC2 Type II certification is increasingly expected by enterprise customers and B2B API clients as a baseline security assurance. The absence of any publicly available SOC2 report or certification represents a medium risk: enterprise customers may require it for procurement, and its absence could limit WOT's ability to win or retain B2B contracts. The risk is medium rather than high because SOC2 is a voluntary framework with no regulatory mandate, but market pressure from enterprise clients makes it commercially significant.

Evidence: https://www.mywot.com/privacy, https://www.mywot.com/terms

CPRA — Partially Compliant

WOT explicitly acknowledges CCPA/CPRA applicability and has dedicated sections in its privacy policy for California residents. However, WOT explicitly discloses that it 'sells' personal data (identifiers, commercial information, internet/network activity, profiles, inferences, and sensitive personal information) to business customers — a high-risk activity under CCPA/CPRA. The sale of sensitive personal information and the breadth of data sold (including browsing history and behavioral profiles) creates significant enforcement risk from the California Privacy Protection Agency (CPPA). Fines can reach $7,500 per intentional violation. The risk is high given the scale of California users and the explicit acknowledgment of data sales.

Evidence: https://www.mywot.com/privacy

GDPR (source) — Partially Compliant

WOT explicitly acknowledges GDPR applicability and has implemented several compliance measures (DPO appointment at dpo@mywot.com, data subject rights, EEA transfer safeguards via SCCs, lawful basis documentation). However, the company's core business model involves collecting extensive browsing data, messaging data (Android), in-app activity, and selling/sharing personal data to third-party affiliates for market intelligence — activities that have historically attracted GDPR enforcement scrutiny. The breadth of data collected (including sensitive browsing habits, messaging content, and e-commerce behavior) from millions of EU/EEA users creates elevated risk. WOT's 2017 scandal (where it was found to be selling user browsing data) adds historical context to enforcement risk. No public GDPR audit or DPA clearance has been found, and the privacy policy's reliance on 'legitimate interests' for extensive data collection may be challenged by EU regulators. Fines under GDPR can reach €20M or 4% of global annual turnover.

Evidence: https://www.mywot.com/privacy, https://edpb.europa.eu/about-edpb/about-edpb/members_en#member-at, https://ico.org.uk/global/contact-us/contact-us-public/

Financials

Three-year financials

Financial Resilience Score: 5/10

WOT Services operates as a private small-to-mid-sized consumer cybersecurity company with no publicly disclosed financial statements. The company benefits from a large installed base (140M+ downloads across 79 countries), a freemium consumer model with recurring premium subscription revenue, and low-cost distribution via browser extension stores. It appears to be operating from cash flow with no disclosed institutional funding round since approximately 2013, suggesting some degree of self-sustainability. However, resilience is materially constrained by significant risk factors: a serious 2016 reputational crisis in which the company was delisted from major browser stores after being exposed for selling de-anonymizable browsing data, heavy platform dependency on browser store policies, intense competition from free integrated safe-browsing services (Google Safe Browsing, Microsoft SmartScreen, Norton, Bitdefender, Avast), and opaque LP ownership structure across Israel and Finland that makes third-party diligence difficult. Without access to actual revenue, EBIT, or equity figures, a mid-range resilience score reflects the balance between the durable user community moat and the substantial structural and reputational risks.

Key strengths: Large installed base of 140M+ downloads across 79 countries providing community moat, Freemium consumer model with paid Premium subscription tier (Adult Protection, Identity & Privacy), Low-cost distribution via browser extension stores, Multi-platform diversification across Chrome, Firefox, Edge, Opera, Safari, Yandex, Samsung, iOS, and Android, Crowdsourced dataset of 100M+ reviewed websites difficult to replicate, Appears to operate from cash flow without recent institutional funding needs

Risk factors: 2016 privacy scandal (NDR expose) led to delisting from major browser stores - reputational damage to a trust-based business, Heavy platform dependency - Chrome/Firefox/Apple/Microsoft can delist extensions with little notice, Competitive pressure from free integrated safe-browsing (Google Safe Browsing, Microsoft SmartScreen, Norton, Bitdefender, Avast), Opaque LP ownership structure and jurisdiction unclear, No publicly disclosed financial statements available, No disclosed institutional funding round since approximately 2013, Historical data-monetization revenue stream discontinued post-2016 backlash

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report