Whoisvisiting
United Kingdom · www.whoisvisiting.com · 10 vendors
Resilience scores
- Digital Sovereignty: 10
- Digital Resilience: 7
- Financial Resilience: 5
Technology vendors
- Demandware — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- Rain-Task Limited — Technology — United Kingdom
- and 7 more
Services catalogue
1 service in catalogue across 1 category; runs on 10 sub-vendors.
- Whoisvisiting
Insights
Last updated 2026-07-17 · revision 2
10 direct vendors, 157 subvendors
Direct vendors by controlling owner country (sample)
- United States: 8
- France: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Bulgaria: 1
- Israel: 1
- Sweden: 4
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Whoisvisiting exhibits a medium-to-low level of migration readiness. The primary challenge stems from its core internal tech stack, which includes WordPress and WPBakery Page Builder. These technologies typically represent a more traditional, potentially monolithic architecture that is not inherently cloud-native, containerized, or microservices-based. Migrating such a stack to a modern cloud environment would likely require significant refactoring, re-platforming, or a less optimized 'lift-and-shift' approach, increasing complexity, cost, and time. While GDPR compliance is a strength, it also means any migration must meticulously maintain these compliance standards, adding a layer of complexity. The company's use of Zapier for workflow automation could aid in integrating new cloud services, but the overall architecture remains a hurdle. Critical information regarding financial stability (revenue concentration, growth history) is missing, which makes it impossible to assess the company's ability to fund a potentially large and complex migration project. Furthermore, data residency requirements are not specified; if strict requirements exist, they could significantly complicate cloud deployment strategies. The 'Vendor Lock-in Risk' is unknown, and with 13 services identified, there are a number of external integrations that would need careful management and potential re-configuration during a migration. The lack of clarity on these key factors significantly lowers the migration readiness score.
Compliance
7 in-scope frameworks identified; showing 3.
CPRA — Assessment Required
Whoisvisiting has a US office at 1250 Oakmead Pkwy, Sunnyvale, CA 94085 (Silicon Valley), and a US phone number (408-290-0181), indicating active US operations. The company serves businesses globally including US customers. CCPA/CPRA applies to for-profit businesses that: (1) have annual gross revenues over $25M; (2) buy, sell, or share personal information of 100,000+ consumers/households annually; or (3) derive 50%+ of annual revenues from selling personal information. The company's prospecting database of 4.5M companies with employee emails, combined with its website visitor tracking across thousands of client websites, could trigger CCPA thresholds — particularly criterion (2) if US consumer data is processed at scale. Risk is Medium because: US presence is confirmed but the scale of US consumer data processing is unknown; the company's B2B focus means it primarily processes business contact data (which has more limited CCPA protections), but individual employee data is still covered by CCPA.
Evidence: https://www.whoisvisiting.com/privacy-policy/, https://www.whoisvisiting.com/terms-conditions/, https://www.whoisvisiting.com/prospecting/
GDPR (source) — Partially Compliant
Whoisvisiting (operated by Whois Data Ltd) is headquartered in Northampton, UK, and explicitly acknowledges operating across multiple EU member states, making GDPR directly applicable. The company processes IP addresses and website visitor data on behalf of its clients, acting as a data processor. While the company has published a GDPR compliance page and claims to have taken steps toward compliance since May 2018, several risk factors elevate this to High: (1) The company's core product — IP-based website visitor identification — sits in a legally contested area under GDPR, as the CJEU and ICO have clarified that IP addresses CAN constitute personal data depending on context; (2) The company's GDPR page makes the legally questionable assertion that 'an IP address on its own is not personal data,' which contradicts established EU regulatory guidance (Breyer case, C-582/14); (3) No formal third-party GDPR audit or DPO appointment is publicly evidenced; (4) The company serves 6,000+ users across 2,000+ businesses globally, amplifying the scale of potential non-compliance; (5) UK post-Brexit operates under UK GDPR (essentially mirroring EU GDPR), and the company explicitly serves EU customers, triggering full EU GDPR obligations as well. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://www.whoisvisiting.com/gdpr/, https://www.whoisvisiting.com/privacy-policy/, https://www.whoisvisiting.com/terms-conditions/, https://ico.org.uk/media/1624219/preparing-for-the-gdpr-12-steps.pdf, https://ico.org.uk/for-organisations/resources-and-support/data-protection-self-assessment/data-controllers/
ISO 27001 (source) — Assessment Required
ISO 27001 is the international standard for information security management and is highly relevant for SaaS companies like Whoisvisiting that store and process client business data, IP tracking data, and a database of 4.5M company records including employee emails. Risk is Medium because: (1) the company processes commercially sensitive data (website visitor intelligence, prospect contact data) that would be attractive targets for breaches; (2) no ISO 27001 certification is publicly evidenced, representing a gap in demonstrable security assurance; (3) enterprise and agency clients may require ISO 27001 as a vendor prerequisite; (4) the company's GDPR page references data breach procedures but provides no evidence of a formal ISMS. Risk is not High because ISO 27001 is voluntary and the company's scale (SME-level) means enforcement pressure is lower than for large enterprises.
Evidence: https://www.whoisvisiting.com/terms-conditions/, https://www.whoisvisiting.com/gdpr/, https://www.whoisvisiting.com/privacy-policy/
Financials
Three-year financials
- null:
Financial Resilience Score: 5/10
Whoisvisiting is a small, privately held UK SaaS company operating in the B2B website-visitor-identification and lead-generation category. As a small private entity, it files abbreviated small-company or micro-entity accounts with Companies House, which do not require disclosure of revenue, EBIT, or segment data. This limits external visibility into financial durability. However, the company has been operating for approximately 10+ years, indicating a viable niche and repeatable customer acquisition model, and its subscription-based SaaS revenue model provides predictable ARR and favorable working-capital dynamics. The company operates in a highly competitive space with well-funded rivals such as Lead Forensics, Leadfeeder/Dealfront, Albacross, CANDDi, Visitor Queue, ZoomInfo, 6sense, and RB2B, creating persistent pricing pressure. With only ~2,000 business customers, scale is limited and SMB SaaS churn tends to be high. Additionally, structural headwinds from GDPR, ePrivacy, CCPA/CPRA regulations, and browser-level anti-tracking measures pose material risk to the deterministic IP-tracking business model. On balance, the company shows signs of operational resilience through diversification into multiple products (Visiting, White Label, Prospecting, Personalize), an international UK/US footprint providing FX diversification, and low capital intensity typical of pure software businesses. However, the lack of financial transparency, competitive intensity, and regulatory/technological headwinds warrant a middling resilience assessment.
Key strengths: Recurring SaaS revenue model with predictable ARR, Established ~10+ year operating history, Multi-product portfolio (Visiting, White Label, Prospecting, Personalize), International UK/US footprint providing FX diversification, Low capital intensity as pure software business, White Label agency channel creates leveraged distribution, ~6,000 users across 2,000+ businesses
Risk factors: Highly competitive category with larger rivals (Lead Forensics, Leadfeeder/Dealfront, ZoomInfo, 6sense), Small scale (~2,000 business customers) with typical SMB SaaS churn, Regulatory/privacy risk under GDPR, UK DPA, ePrivacy, CCPA/CPRA, Cookieless/signal-loss trend from browser anti-tracking measures, Concentration in niche IP-to-company matching, reliant on third-party data vendors, Limited public financial transparency limiting enterprise buyer confidence, Persistent pricing pressure from crowded market
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.