Zeotap

Germany · zeotap.com · 11 vendors

Zeotap is an AI-powered Customer Data Platform (CDP) that helps enterprises unify, manage, and activate customer data across marketing and digital channels. The platform focuses on collecting customer data from multiple systems, resolving identities, building unified customer profiles, segmenting audiences, and activating data in marketing platforms. It emphasizes privacy and GDPR compliance, offering solutions for data-driven growth.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 11 sub-vendors.

Insights

Last updated 2026-07-29 · revision 1

11 direct vendors, 158 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 10/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Zeotap exhibits exceptionally high migration readiness, primarily driven by its highly modern and flexible architectural approach. Its internal tech stack is entirely cloud-native, utilizing GCP, Kubernetes for container orchestration, and distributed data processing technologies like Apache Kafka, Apache Spark, BigQuery, Snowflake, and Databricks. This foundation is inherently designed for portability and ease of migration across cloud environments or different deployment models. The company's "InfraFlex" framework, Composable CDP, and Snowflake Native App explicitly highlight its architectural flexibility, allowing enterprises to run the CDP in Packaged SaaS, Composable (warehouse-native), or Client-Hosted modes "without re-platforming or forced migrations." This core design principle directly translates to Zeotap's own high readiness for any potential migration or architectural shift. Furthermore, the data states "Total Vendors: 0," which, if interpreted as Zeotap having no external vendor dependencies for its operations, signifies a complete absence of vendor lock-in. This is a paramount factor for migration readiness, as it removes the complexities of contract renegotiations, technology dependencies, and data egress costs often associated with vendor relationships. Zeotap's strong data governance and security framework, backed by certifications like GDPR and ISO, also contributes positively, as well-defined processes for data handling and compliance would facilitate compliant and secure data migrations. The assessment acknowledges the absence of specific data residency requirements and financial stability, which could influence migration planning. Similar to resilience, the contradiction in the vendor data (0 vendors vs. listing vendor countries) is noted, with the "Total Vendors: 0" being prioritized for assessing Zeotap's internal migration flexibility.

Compliance

9 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 applicability to Zeotap is uncertain. ISAE 3000 is used for non-financial assurance engagements, including privacy and sustainability reporting. For a SaaS company like Zeotap, ISAE 3000 could be relevant in the context of: (1) privacy assurance reports (e.g., ISAE 3000 Type I/II reports on GDPR compliance controls); (2) SOC 2 reports issued under ISAE 3000 for non-US clients (European auditors often use ISAE 3000 as the framework for SOC 2-equivalent reports). The risk level is Low because ISAE 3000 is not a mandatory regulatory requirement but rather an optional assurance framework. Non-compliance does not carry regulatory penalties. However, enterprise clients in Europe may request ISAE 3000 assurance reports as part of vendor due diligence.

Evidence: https://zeotap.com/platform/capabilities/data-governance-and-security/, https://trustcenter.zeotap.com/

EU AI Act (source) — Assessment Required

The EU AI Act is increasingly relevant to Zeotap given its 'ZeoAI' product line, which uses AI for customer segmentation, decision-making, predictive analytics, and personalization. Risk is Medium because: (1) Zeotap's AI-powered decision-making agent ('Every Decision, Optimised') and conversational AI agent may qualify as AI systems under the EU AI Act; (2) AI systems used for profiling individuals for marketing purposes could be classified as 'high-risk' or at minimum require transparency obligations; (3) the EU AI Act's prohibited practices (e.g., subliminal manipulation, social scoring) must be assessed against Zeotap's AI capabilities; (4) the Act's general-purpose AI (GPAI) provisions may apply if Zeotap uses foundation models. Full applicability assessment requires detailed review of ZeoAI's technical architecture and use cases.

Evidence: https://zeotap.com/platform/ai-powered-insights/, https://zeotap.com/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689

ISO 27001 (source) — Compliant

ISO 27001 certification is strongly indicated for Zeotap based on multiple evidence signals. The risk level is Low because: (1) Zeotap explicitly references 'the highest level of certification of information security' across data management, cloud environment, and PII protection; (2) multiple certificate badges are displayed in the website footer, consistent with ISO 27001 and related certifications; (3) Zeotap's 'German Grade Privacy' branding and enterprise client base (Fortune 500-level companies) strongly suggest ISO 27001 is in place as a baseline; (4) ISO 27001 is the most common information security certification for EU-based SaaS companies and is frequently required by German enterprise clients; (5) Zeotap's security architecture (encryption, hashing, zero-copy, access controls) aligns with ISO 27001 Annex A controls. The low risk reflects high confidence in existing certification, though the specific certificate details were not directly accessible.

Evidence: https://zeotap.com/platform/capabilities/data-governance-and-security/, https://zeotap.com/, https://trustcenter.zeotap.com/

Financials

Three-year financials

Financial Resilience Score: 5/10

Zeotap's financial resilience is difficult to assess with precision because the company is a privately held German GmbH with limited public disclosure, and statutory filings in the Bundesanzeiger were not retrievable during this research. Revenue, EBIT, and equity figures for the last three fiscal years are not publicly verified, meaning cash runway and profitability trajectory cannot be quantitatively confirmed. On the positive side, Zeotap has raised over US$100 million cumulatively, including a ~US$60 million Series C in 2020 led by SignalFire, and benefits from a blue-chip enterprise customer base spanning telecoms (Virgin Media O2, TIM, Sky), retail (REWE, Douglas), and gaming. Its GDPR-aligned European positioning and strategic partnerships with Google Cloud, Snowflake, Databricks, and Braze provide meaningful commercial leverage. The 2021 integration of Deutsche Telekom's data marketplace also added strategic backing. However, the company faces significant headwinds: intense competition from far better-capitalized players (Twilio Segment, Adobe Real-Time CDP, Salesforce Data Cloud, Tealium), structural risk from cookie deprecation affecting its legacy ID+/Audience Boost business, customer concentration in a few large telco/retail accounts, and a history of restructuring including reported layoffs in 2022–2023, particularly in its Indian engineering base. Combined with minimal financial transparency, these factors place Zeotap's resilience in the mid-range.

Key strengths: Cumulative funding of >US$100M including ~US$60M Series C (2020) led by SignalFire, Blue-chip enterprise customer base (Virgin Media O2, TIM, Sky, REWE, Ford, Douglas), GDPR/European privacy positioning as differentiator vs. US CDPs, Strategic partnerships with Google Cloud, Snowflake, Databricks, Braze, Deutsche Telekom historically involved as equity holder via 2021 data marketplace integration, Product breadth expanded from third-party data into first-party CDP, AI (ZeoAI), and composable/Snowflake-native architectures

Risk factors: Cash burn and unverified path to profitability; audited P&L not publicly available, Intense competition from better-capitalized CDPs (Segment/Twilio, Adobe, Salesforce, Tealium), Cookie deprecation and identity-graph headwinds affecting legacy ID+/Audience Boost business, Customer concentration risk in a few large telco/retail accounts, Restructuring history with reported layoffs in 2022–2023, particularly in India, Limited financial transparency as a private GmbH with likely small-company reporting exemptions

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report