Workbuster AB
Sweden · www.workbuster.com · 8 vendors
Resilience scores
- Digital Sovereignty: 38
- Digital Resilience: 5
- Financial Resilience: 5
Technology vendors
- Google LLC — Technology — United States
- HubSpot, Inc. — Technology — United States
- WP Rocket — Technology — France
- and 5 more
Services catalogue
1 service in catalogue across 1 category; runs on 8 sub-vendors.
- Workbuster
Insights
Last updated 2026-08-16 · revision 1
8 direct vendors, 173 subvendors
Direct vendors by controlling owner country (sample)
- United States: 5
- France: 1
- Sweden: 1
Subvendors by controlling owner country (sample)
- Canada: 6
- Bangladesh: 3
- Netherlands: 2
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Workbuster AB demonstrates medium migration readiness, leaning towards the lower end due to several significant challenges. The company operates exclusively in Sweden and handles sensitive participant data for a government agency (Arbetsförmedlingen). While not explicitly stated, this context strongly implies strict data residency requirements within Sweden or the EU, which would significantly limit potential cloud migration targets and regions. The core application's architecture is not described as cloud-native, containerized, or microservices-based, suggesting it might be a more traditional setup, which could complicate a lift-and-shift or re-platforming effort. Integrations with 'Hello Talent' and 'Excel/KA-Webbstöd' for Arbetsförmedlingen data might represent specific vendor dependencies or legacy interfaces that could lead to vendor lock-in, the risk of which is currently unknown. Furthermore, the financial stability (revenue concentration, growth history) is unknown, making it difficult to assess the company's capacity to fund a significant migration project. On the opportunity side, the company's explicit GDPR compliance indicates a strong foundation in data governance, which is crucial for managing data during a migration. The use of modern features like an AI Assistant and automated workflows suggests internal technical capabilities that could be leveraged for migration planning and execution. Cloudflare is a modern component that can be easily integrated into cloud environments.
Compliance
7 in-scope frameworks identified; showing 3.
EU AI Act (source) — Assessment Required
Risk is Medium and increasing. Workbuster AB has publicly announced AI-assisted features including automated profile summarisation and draft report generation for job seekers. The EU AI Act, which entered into force in August 2024 with phased applicability, classifies AI systems used in employment and labour market contexts as HIGH-RISK under Annex III (Article 6). Specifically, AI systems used for recruitment, selection, promotion, task allocation, or monitoring of workers/job seekers are explicitly listed as high-risk. This means Workbuster's AI features may be subject to the most stringent requirements of the AI Act, including conformity assessments, transparency obligations, human oversight requirements, and registration in the EU AI database. Non-compliance risk is significant given the explicit sector listing.
Evidence: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689, https://www.multisoft.se/kunskapsbank/workbuster-lanserar-ai%e2%80%91stod-for-en-enklare-och-mer-effektiv-arbetsdag/, https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
GDPR (source) — Partially Compliant
GDPR risk is High for Workbuster AB for several compounding reasons: (1) The company is a Swedish-registered data processor and controller operating entirely within the EU, making GDPR unconditionally applicable. (2) The platform processes sensitive personal data of job seekers — including employment history, skills assessments, personal profiles, and potentially special category data (e.g., health or disability information relevant to labour market participation) — on behalf of public and private employment service providers. (3) As a SaaS data processor under Article 28 GDPR, Workbuster bears contractual and regulatory obligations to all its data controller clients. A breach or non-compliance event could trigger enforcement by the Swedish Authority for Privacy Protection (IMY), fines of up to €20M or 4% of global annual turnover, reputational damage, and loss of public sector contracts. (4) The Swedish IMY has an active enforcement record. (5) The company's AI-assisted features (launched for profile summarisation and reporting) introduce additional GDPR obligations around automated processing, transparency, and potentially Article 22 (automated decision-making). (6) While a DPA and privacy policy are published, no independent audit or DPO appointment evidence was found publicly, and the privacy policy references a named individual rather than a formally appointed DPO, which may be insufficient for a company of this profile.
Evidence: https://workbuster.com/security/, https://workbuster.com/integritetspolicy/, https://workbuster.com/en/integritetspolicy-sso/, https://www.imy.se/en/
ISAE 3000 (source) — Assessment Required
ISAE 3000 risk is Low. ISAE 3000 is an assurance standard used for non-financial assurance engagements, including sustainability reporting, internal control reporting, and data privacy assurance. It is not a legal requirement for Workbuster AB's sector. However, as the company grows and serves more public sector clients, demand for third-party assurance reports (e.g., on GDPR compliance, data security controls, or sustainability) may increase. The risk is Low because there is no current regulatory or contractual driver identified for ISAE 3000 reporting in Workbuster's specific context.
Evidence: https://workbuster.com/security/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits-or
Financials
Financial Resilience Score: 5/10
Workbuster AB's financial resilience cannot be quantitatively assessed due to the absence of retrievable financial statements in this research session. However, qualitative factors provide a mixed picture. The company benefits from being part of the larger Multisoft group, which likely provides operational stability, shared services, and financial backing that a standalone niche SaaS company would lack. Its product suite serves public-sector-linked customers through Sweden's Arbetsförmedlingen 'Rusta och Matcha 2' programme, which typically offers stable, contractually predictable revenue streams. On the other hand, the business shows significant concentration risk. Revenue is heavily tied to a single Swedish government programme, and the company operates exclusively in Sweden with no evidence of geographic diversification. The recent corporate transformation (Grade Matcha rebranding to Workbuster and integration into Multisoft) introduces discontinuity that complicates trend analysis and may create restructuring-related volatility in the accounts. As a small Swedish AB, the company likely faces the typical risks of small SaaS firms: thin margins, contract dependency, and limited financial buffers. The mid-range score reflects the balance between group-backed stability and material concentration/small-company risks, with the caveat that no verified financial data was available.
Key strengths: Backed by larger Multisoft group providing scale and shared services, Public-sector customer base linked to Arbetsförmedlingen offers contractual predictability, Diversified public-sector use cases across independent providers, municipal AME units, and event/training modules, Active product investment including recent AI features for coaches
Risk factors: High concentration risk tied to a single Swedish government programme (Rusta och Matcha), Exposure to changes in Arbetsförmedlingen procurement design, budgets, or scope, Single-country exposure to Sweden with no material foreign operations, Brand/entity discontinuity from Grade Matcha to Workbuster to Multisoft integration, Small company risk with likely thin margins and limited financial buffers
Revenue by geography
- Sweden: 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.