WPDrift

Denmark · wpdrift.dk · 9 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 9 sub-vendors.

Insights

Last updated 2026-07-19 · revision 2

9 direct vendors, 153 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

WPDrift exhibits high migration readiness. A primary strength is its existing heavy reliance on cloud infrastructure, specifically Amazon Web Services (AWS) and Cloudflare CDN, indicating a mature understanding and operational experience with cloud environments. Their internal tech stack, featuring NGINX, Redis, and MariaDB, is modern and generally compatible with various cloud platforms, facilitating portability. A key indicator of high readiness is their offering of a 'Website Migration Service' to clients, which strongly suggests internal expertise, tools, and processes for executing migrations effectively. Furthermore, the absence of specified data residency requirements or complex regulatory environments (based on available data) simplifies potential migration efforts. While their reliance on AWS and Cloudflare provides a solid cloud foundation, it also implies a degree of vendor lock-in. Migrating away from these specific platforms to entirely different cloud ecosystems would require effort to re-platform or re-configure services, even if the underlying technologies are portable. The lack of financial stability data prevents an assessment of their capacity to fund a significant internal migration project. There is no explicit mention of containerization or microservices architecture, which, if adopted, would further enhance their migration flexibility and readiness.

Compliance

8 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

WPDrift is a cloud/managed hosting service provider — the exact type of organization for which SOC 2 (Type I or Type II) reports are most relevant. SOC 2 is not a legal requirement but is increasingly demanded by enterprise customers as evidence of security, availability, processing integrity, confidentiality, and privacy controls. WPDrift's clients include businesses (Everfuel, Rockwool Foundation, BTX Group, F.C. Midtjylland) that may require SOC 2 assurance from their hosting providers. No SOC 2 report was found. Risk is MEDIUM because: (1) absence of SOC 2 may limit WPDrift's ability to win enterprise contracts; (2) as a data processor under GDPR, WPDrift must demonstrate 'sufficient guarantees' of technical and organizational security measures (Art. 28 GDPR) — SOC 2 is a common mechanism for this; (3) without SOC 2, clients cannot independently verify security controls.

Evidence: https://www.wpdrift.dk, https://www.wpdrift.dk/service-level-agreement/, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy

Danish Data Protection Act — Partially Compliant

The Danish Data Protection Act (Lov nr. 502 af 23/05/2018, as amended) supplements GDPR with Danish-specific provisions, including stricter rules on processing of sensitive data, criminal records data, and specific sectoral requirements. As a Danish company, WPDrift is directly subject to this law. Risk is HIGH for the same reasons as GDPR — WPDrift processes personal data as both controller and processor, and the same gaps identified under GDPR (no DPO, legacy privacy policy, AWS SES transfer mechanism) apply here. Datatilsynet actively enforces both GDPR and the Danish Data Protection Act.

Evidence: https://www.wpdrift.dk/privatlivspolitik/, https://www.datatilsynet.dk/, https://www.retsinformation.dk/eli/lta/2018/502, https://www.datatilsynet.dk/afgoerelser

NIS2 (source) — Assessment Required

WPDrift operates as a managed hosting and digital infrastructure provider in Denmark (EU). NIS2 Directive (EU 2022/2555), transposed into Danish law via 'Lov om net- og informationssikkerhed' (NIS2-loven), includes 'digital infrastructure' and 'managed service providers (MSPs)' / 'managed security service providers (MSSPs)' as covered entities. WPDrift provides fully managed WordPress hosting — a form of managed IT/cloud service — to Danish businesses including critical sectors (e.g., Everfuel, Rockwool Foundation, F.C. Midtjylland). The key threshold question is size: NIS2 applies to medium enterprises (50+ employees OR €10M+ annual turnover) or large enterprises. WPDrift's exact employee count and revenue are not publicly disclosed. As a small Danish hosting company, it may fall below the 50-employee / €10M threshold, which would exempt it from NIS2 as an 'Important Entity.' However, if it qualifies as a 'managed service provider' under Annex I or II regardless of size (some MSP categories have no size threshold under NIS2), it could still be in scope. Risk is MEDIUM because: if in scope, non-compliance with NIS2 security and incident reporting requirements carries fines up to €7M or 1.35% of global turnover for Important Entities; Danish NIS2 enforcement began in 2024; the managed hosting sector is explicitly referenced in NIS2 scope.

Evidence: https://www.wpdrift.dk, https://www.cfcs.dk/da/cybersikkerhed/nis2/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.retsinformation.dk/eli/lta/2023/1655

Financials

Three-year financials

Financial Resilience Score: 6/10

WP Drift ApS operates a subscription-based managed WordPress hosting business with recurring revenue streams and high customer stickiness, which provides good revenue visibility and operational predictability. The company has a diversified mid-market Danish customer base across multiple sectors including sports (F.C. Midtjylland), fashion (BTX Group), industrial, food & beverage, non-profit foundations (Rockwool Fonden), and energy (Everfuel), reducing single-customer concentration risk. Long-term customer relationships since at least 2019 and a low capex model (Cloud VPS infrastructure, no owned data center) support financial resilience. However, as a small Danish ApS, the company likely has a limited capital buffer, and its concentration in the Danish market and single technology stack (WordPress) exposes it to competitive pressure from global managed WP hosts like WP Engine, Kinsta, and Cloudways. Dependence on upstream infrastructure providers (Cloud VPS, AWS SES) exposes gross margins to third-party pricing and reliability. Key-person risk exists around Nicolai M. Olesen as Director/Partner, and the hosting business model carries elevated cyber/security incident risk where a major breach or extended outage could be materially damaging. Actual financial figures were not retrievable in this session, limiting the precision of this assessment.

Key strengths: Recurring subscription-based revenue model with high visibility, Sticky product with low customer churn due to switching costs, Diversified customer base across multiple sectors, Long-term customer relationships (F.C. Midtjylland since 2019), Partner/agency channel provides scalable acquisition, Low capex model using Cloud VPS infrastructure

Risk factors: Small ApS structure with limited capital buffer, Geographic concentration in Danish market, Single technology stack dependence (WordPress), Competitive pressure from global managed WP hosts (WP Engine, Kinsta, Cloudways), Dependence on upstream infrastructure providers (Cloud VPS, AWS SES), Key-person risk around Nicolai M. Olesen, Elevated cyber/security incident risk inherent to hosting business

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report