WeSupply

United States · www.wesupplylabs.com · 27 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 27 sub-vendors.

Insights

Last updated 2026-06-19 · revision 2

27 direct vendors, 297 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

WeSupply demonstrates medium migration readiness. A key strength is its internal tech stack, which includes AWS, indicating existing cloud adoption and familiarity with modern infrastructure. The use of API-driven integrations further suggests a modular architecture that can facilitate easier migration and integration with new platforms. However, several factors introduce uncertainty and potential challenges. The financial stability required to fund a significant migration effort is unknown due to a lack of data on revenue concentration and growth. Similarly, the absence of specified regulatory environment and data residency requirements means these critical aspects would need thorough investigation, potentially adding complexity and cost to any migration. While "Total Vendors" is contradictory, the presence of "Total Services: 25" and vendor HQs in four unique countries (Denmark, United States, Israel, Canada) suggests a diverse vendor ecosystem, which could reduce overall vendor lock-in if managed effectively. However, the specific vendor lock-in risk remains unknown, which is a significant factor in migration planning. The use of WordPress and Elementor, while common, might require refactoring or specific migration strategies if a move to a fully cloud-native, serverless architecture is desired.

Compliance

7 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

WeSupply is a cloud-based SaaS platform that processes sensitive customer data (names, addresses, order histories, payment card information) on behalf of enterprise ecommerce clients. SOC 2 is highly relevant for cloud service providers handling customer data. WeSupply's Trust Center lists 'SOC 2 Report' as an available document under the Reports section and 'SOC 2' under the Compliance section. This strongly indicates WeSupply has undergone or is undergoing a SOC 2 audit. However, the full report is not publicly available (requires access request via Trust Center), so the exact Type (Type I vs. Type II), scope (Trust Service Criteria covered), and audit period cannot be confirmed. Risk is medium because enterprise clients increasingly require SOC 2 Type II reports, and any gaps in the audit scope or findings could impact client trust and contract renewals.

Evidence: https://wesupply.safebase.us/, https://www.wesupplylabs.com/privacy-policy/

CCPA — Partially Compliant

WeSupply explicitly addresses CCPA in its privacy policy with a dedicated California Residents section and on its GDPR & CCPA page. The company has built APIs for data subject rights and acknowledges acting as both a 'Business' and 'Service Provider' under CCPA. However, the privacy policy was last updated in October 2022 and may not fully reflect CPRA (California Privacy Rights Act) amendments effective January 2023, which expanded consumer rights and introduced new obligations (e.g., sensitive personal information rights, opt-out of sharing for cross-context behavioral advertising, data minimization). Risk is medium because California enforcement has increased under the California Privacy Protection Agency (CPPA), and gaps in CPRA compliance could result in fines of up to $7,500 per intentional violation.

Evidence: https://www.wesupplylabs.com/privacy-policy/, https://www.wesupplylabs.com/gdpr-ccpa/, https://wesupply.safebase.us/

PCI DSS (source) — Assessment Required

WeSupply's privacy policy explicitly states it collects 'First Name, Last Name, full PAN and Card Address' as Credit Card Information. Processing full Primary Account Numbers (PANs) places WeSupply squarely within PCI DSS scope. PCI DSS v4.0 (effective March 2024) imposes stringent requirements on any entity that stores, processes, or transmits cardholder data. The Trust Center lists PCI DSS as a compliance item. Risk is HIGH because: (1) full PAN storage is one of the most sensitive PCI DSS obligations; (2) non-compliance can result in fines of $5,000–$100,000/month from card brands, termination of card processing privileges, and mandatory forensic audits following breaches; (3) the compliance status (SAQ level, QSA audit results) is not publicly disclosed. This is the highest-risk regulatory item for WeSupply.

Evidence: https://wesupply.safebase.us/, https://www.wesupplylabs.com/privacy-policy/

Financials

Three-year financials

Financial Resilience Score: 6/10

WeSupply Labs is a private US-based e-commerce SaaS vendor with no public financial disclosure (no SEC filings, no audited statements). Quantitative assessment of liquidity, burn rate, gross margin, or churn is not possible from primary sources. Third-party aggregators estimate revenue in the low-to-mid single-digit USD millions, but these are modeled and unverified. Resilience is materially supported by the company's affiliation with and apparent integration into EasyPost, a well-funded shipping API/logistics platform that reportedly raised ~$25M in a 2021 Series B at a valuation in the hundreds of millions. EasyPost provides capital backing, carrier relationships, and cross-sell distribution, which de-risks the standalone startup profile. The sticky SaaS model, diversified product breadth (tracking, returns, BOPIS, warranty, fraud, protection insurance), and notable mid-market/enterprise customer logos (EVEREVE, Rudsak, J.McLaughlin, Greenworks) suggest an established book of business. However, WeSupply faces a crowded competitive space with much larger and better-funded rivals (Narvar, AfterShip, Loop Returns, Returnly/Affirm, Happy Returns/UPS, parcelLab, Route, Shippo, Shopify-native tools). SMB/mid-market customer exposure ties revenue to consumer-discretionary cycles and shipping cost inflation. The insurance/protection revenue model also carries underwriting/regulatory risk in certain jurisdictions.

Key strengths: Integration with EasyPost provides capital, carrier relationships, and distribution, Sticky SaaS model with embedded checkout/returns workflows and high switching costs, Diversified product breadth across tracking, returns, BOPIS, warranty, fraud, and protection insurance, Notable mid-market/enterprise customer logos (EVEREVE, Rudsak, J.McLaughlin, Greenworks, Hamilton Jewelers), Heritage from WeltPixel Magento agency provides engineering depth and ecosystem access

Risk factors: Crowded competitive space with much larger rivals (Narvar, AfterShip, Loop, Returnly, parcelLab, Route, Shippo), SMB/mid-market customer exposure to consumer-discretionary spending cycles, No public financial disclosure; opacity on liquidity, burn rate, gross margin, churn, Insurance/protection revenue model exposes to underwriting/regulatory risk in some jurisdictions, Dependence on parent EasyPost's strategic priorities for continued investment

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report