Workbooks
UK · www.workbooks.com · 28 vendors
Workbooks provides a cloud-based CRM and business application platform designed for mid-market organizations. It offers a comprehensive suite of tools for sales, marketing, customer service, order management, fulfillment, invoicing, and supplier management. The platform aims to streamline business processes, improve customer engagement, and provide a single 360-degree view of customers.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Netlify, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 26 more
Services catalogue
1 service in catalogue across 1 category; runs on 28 sub-vendors.
- CRM
Insights
Last updated 2026-08-14 · revision 7
28 direct vendors, 294 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- Poland: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Romania: 2
- Latvia: 1
- Spain: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Workbooks exhibits a good level of migration readiness, primarily driven by its modern cloud-based tech stack. Their core platform is a cloud-based SaaS built on AWS, utilizing Ruby on Rails, MySQL, and JavaScript, which are contemporary technologies facilitating portability. The presence of an open REST API for third-party integrations further suggests a modular architecture that would ease data and system migration. Financially, the recent £16.6m investment indicates strong backing to fund potential migration initiatives. Regulatory compliance with ISO 27001 and GDPR provides a solid foundation, as these certifications demonstrate adherence to security and data handling best practices that are crucial for any migration. However, several factors present challenges. The "Unknown" status and "Medium risk" associated with SOC2 certification for US operations could be a significant hurdle, as many US enterprises require this for their cloud providers, potentially complicating migration to new environments or attracting new US clients. Data residency requirements for US customers are also a point of complexity; while UK data centers comply with GDPR for EU/UK data, specific US data localization needs might necessitate a complex strategy for US customer data. The most significant unknown is vendor lock-in. The data states "Total Vendors: 0" and "Vendor Lock-in Risk: Unknown." While there are 36 services from vendors in 10 unique countries, the actual number of distinct vendors is not clear. If these 36 services are provided by a very limited number of vendors, it could indicate high lock-in, making migration more complex and costly. Conversely, if they are from a broad base of vendors, it would reduce lock-in. Without this clarity, vendor lock-in remains a notable potential challenge.
Compliance
6 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Compliant
Workbooks explicitly displays ISO 27001 certification on its homepage footer with an ISO logo, confirming active certification. ISO 27001 is the international standard for information security management systems (ISMS) and demonstrates that Workbooks has implemented a structured, audited approach to managing information security risks. This certification significantly reduces information security risk and demonstrates third-party validated controls. Risk is Low because the certification is publicly confirmed, ISO 27001 requires periodic surveillance audits and recertification every three years, and it provides strong assurance of security governance maturity. The certification also partially satisfies security requirements from customers in regulated industries.
Evidence: https://www.workbooks.com/
GDPR (source) — Partially Compliant
Workbooks is a UK-headquartered SaaS CRM provider registered with the UK ICO (Z161136X) and explicitly references UK GDPR compliance in its Privacy Notice (last updated May 2024). It has a Data Processing Addendum (DPA) incorporated into its Master Services Agreement, a Sub-processors Policy, and a dedicated data rights contact (datarequest@workbooks.com). These are strong indicators of active GDPR compliance. However, the company serves customers in 30 countries including EU/EEA jurisdictions, meaning EU GDPR also applies to processing of EU residents' data. The Privacy Notice references partners 'located outside of the EU', raising questions about adequacy of international transfer mechanisms (e.g., Standard Contractual Clauses). No publicly available DPO appointment or EU GDPR representative appointment was found. Risk is Medium rather than High because the company has clearly invested in compliance infrastructure (ICO registration, DPA, privacy notice), but gaps in EU GDPR transfer documentation and absence of a named DPO/EU representative introduce residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover.
Evidence: https://www.workbooks.com/wp-content/uploads/Privacy-Notice-for-Website.pdf, https://www.workbooks.com/legal/, https://ico.org.uk/ESDWebPages/Entry/Z161136X, https://www.workbooks.com/
SOC 2 (source) — Assessment Required
SOC 2 is highly relevant for cloud SaaS providers like Workbooks, as it provides independent assurance over security, availability, processing integrity, confidentiality, and privacy controls. Workbooks is a cloud-based CRM platform processing sensitive customer business data for 1,400+ customers across 30 countries. Many enterprise and mid-market customers, particularly in the US, require SOC 2 Type II reports from their SaaS vendors as part of vendor due diligence. Workbooks holds ISO 27001 certification (which overlaps significantly with SOC 2 security controls) but no SOC 2 report has been found in public sources. The absence of a publicly disclosed SOC 2 report creates medium risk: US customers may require it, and its absence could be a competitive disadvantage or compliance gap for customers in regulated industries. Risk is Medium because ISO 27001 provides partial mitigation, but SOC 2 is increasingly a baseline expectation for SaaS vendors serving the US market.
Evidence: https://www.workbooks.com/, https://www.workbooks.com/about-us/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Workbooks demonstrates solid financial resilience characteristics despite limited public disclosure. As a private UK SaaS company with a recurring-revenue model and self-reported average customer tenure exceeding 10 years, the company benefits from predictable cash flows and high gross retention. The customer base of 1,400+ mid-market clients spread across 30 countries and multiple verticals (media, manufacturing, business services, consultancy, transport, accounting) reduces single-customer concentration risk. The December 2025 £16.6m minority investment from BGF provides multi-year runway for US expansion and AI/product development without a change of control, signaling external validation of the growth trajectory. However, resilience is tempered by significant competitive and execution risks. Workbooks competes against Salesforce, HubSpot, Microsoft Dynamics, Zoho, Pipedrive and Creatio — all with vastly larger R&D budgets — requiring ongoing investment to maintain AI feature parity. Mid-market SaaS spend is more sensitive to macro cyclicality than enterprise contracts, and US expansion execution requires sales-and-marketing spend that can pressure near-term operating margin. Disclosure opacity as a small private UK company (historically filing abbreviated accounts under FRS 102) makes external assessment of profitability trajectory difficult, and the addition of BGF as a board-level minority shareholder introduces future exit-dynamic considerations.
Key strengths: Recurring SaaS revenue model with 10+ year average customer tenure implying high gross retention, Diversified customer base of 1,400+ customers across 30 countries and multiple verticals, Fresh £16.6m BGF minority growth capital (Dec 2025) providing multi-year runway, Cost-competitive positioning with claimed 50-70% TCO discount vs. Salesforce/Microsoft Dynamics, Long-standing founder-CEO management continuity (John Cheney since 2007), ISO 27001 certified; positioned as largest UK-headquartered CRM vendor
Risk factors: Scale gap vs. much larger competitors (Salesforce, HubSpot, Microsoft Dynamics) with vastly larger R&D and AI budgets, Mid-market SaaS spend cyclicality more sensitive to macro slowdown than enterprise contracts, US expansion execution risk with sales-and-marketing spend pressuring near-term margin, Disclosure opacity as private UK company limits external profitability assessment, Ownership complexity following BGF minority investment affecting future exit dynamics, Need for continuous AI/product investment to maintain feature parity
Revenue by geography
- United Kingdom: 65%
- United States: 25%
- Rest of World: 10%
Revenue by product/service
- SaaS Subscription Licenses: 85%
- Professional Services: 15%
Workforce by country
- United Kingdom: 110
- United States: 25
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.