ZeroTier

zerotier.com · 27 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 27 sub-vendors.

Insights

Last updated 2026-07-30 · revision 5

27 direct vendors, 318 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

ZeroTier exhibits a high migration readiness, scoring 80 out of 100. This is largely due to its highly modern and flexible technology stack, which is well-suited for cloud-native adoption and migration. The internal tech stack includes contemporary languages (Rust, Go, Python, TypeScript), infrastructure-as-code tools (Terraform), and observability platforms (OpenTelemetry), alongside a distributed architecture and REST API for programmable network management. The availability of both SaaS tiers and self-hosted deployment options (including air-gapped environments for ZeroTier Quantum) provides significant flexibility for customers to choose their desired operational model and data residency, easing migration pathways. ZeroTier's strong financial position, bolstered by Series A funding and consistent growth, provides the necessary resources to fund strategic migration initiatives. The vendor landscape, assuming the 'Total Vendors: 0' is an anomaly and considering the 39 services across 8 diverse vendor HQ countries, suggests a healthy level of vendor diversity, which generally reduces vendor lock-in risks and simplifies transitions to new environments. Existing compliance with major privacy regulations (GDPR, CCPA, LGPD) also provides a solid foundation for managing data during any migration process. However, several challenges could complicate migration efforts. ZeroTier's global operations and the presence of ZeroTier Europe B.V. as an EU Data Controller create a complex data residency landscape, requiring meticulous planning for data transfers and storage during migration to ensure ongoing compliance. More critically, the numerous 'Assessment Required' or 'Unknown' regulatory statuses (NIS2, HIPAA, ITAR/EAR, FedRAMP, ISO 27001) introduce potential complexities, costs, or delays. For instance, migrating government or defense-related workloads would necessitate addressing FedRAMP or ITAR/EAR requirements, which are lengthy and expensive processes. The 'Unknown' status for vendor lock-in risk, despite the apparent diversity, means a thorough assessment of specific vendor dependencies and contract complexities would be crucial before undertaking any major migration. These regulatory and data residency complexities, while manageable, require significant attention and could impact the speed and cost of migration.

Compliance

10 in-scope frameworks identified; showing 3.

LGPD — Compliant

ZeroTier has explicitly addressed LGPD compliance in its privacy policy with a dedicated section for Brazilian users. The company identifies lawful bases for processing under LGPD, provides Brazilian data subject rights, and addresses cross-border data transfer requirements. The risk level is Low because the compliance framework is documented, though the depth of operational LGPD compliance (e.g., ANPD registration, DPO appointment for Brazil) is not fully confirmed publicly.

Evidence: https://www.zerotier.com/privacy-policy/, https://www.zerotier.com

GDPR (source) — Compliant

ZeroTier has taken demonstrably proactive steps to achieve GDPR compliance. The company has established a dedicated EU legal entity (ZeroTier Europe B.V., Utrecht, Netherlands) that acts as the EU Data Controller and GDPR Representative, satisfying the Article 27 representative requirement for non-EU controllers. The privacy policy explicitly addresses GDPR rights (access, erasure, rectification, portability, objection), identifies lawful bases for processing, references the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) as the competent supervisory authority, and confirms Data Processing Agreements (DPAs) are in place with all third-party processors. A dedicated Trust Center (trust.zerotier.com, powered by Vanta) publicly documents compliance controls. The risk level is Low because the company has clearly invested in structural GDPR compliance infrastructure, though full audit evidence of the DPA contents and internal processing records is not publicly available.

Evidence: https://www.zerotier.com/privacy-policy/, https://trust.zerotier.com, https://www.zerotier.com

Swiss Federal Act on Data Protection — Compliant

ZeroTier has explicitly addressed Swiss data protection law compliance in its privacy policy. The revised Swiss Federal Act on Data Protection (nFADP), which entered into force September 1, 2023, applies to ZeroTier as it processes personal data of Swiss residents. The risk level is Low because ZeroTier has proactively included Swiss-specific provisions in its privacy policy.

Evidence: https://www.zerotier.com/privacy-policy/

Financials

Three-year financials

Financial Resilience Score: 7/10

ZeroTier is a credible mid-stage venture-backed US cybersecurity / SDN company with institutional VC backing from credible firms (Battery Ventures, Bonfire Ventures, Anorak Ventures), suggesting reasonable runway and validation after a Series A round in approximately 2023. The company has a strong, sticky enterprise customer base in regulated and critical industries, including disclosed customer logos such as Thales, Leidos, NTT Data, Volvo, Keysight, MikroTik, Teltonika, Advantech, Mediapro, BTG Pactual, and Superbet. Many are large multi-year industrial accounts that typically deliver predictable recurring revenue. The company benefits from a defensible technical moat including open-source heritage since 2013, patented/peer-reviewed protocol, and a differentiated post-quantum offering (ZeroTier Quantum, launched at RSAC 2026; CNSA 2.0 compliant). Its capital-light, software-only model should drive high gross margins typical of SaaS networking, and SOC 2 Type II and GDPR compliance reduce sales friction in enterprise deals. Diversified end-markets spanning defense, government, manufacturing, IoT, hospitality, healthcare, and finance reduce single-sector cyclical risk. However, no audited financials are publicly available, making external assessment of burn, runway, or profitability impossible. The secure-connectivity / ZTNA / mesh-VPN space is crowded with better-capitalized competitors such as Tailscale, Cloudflare, Twingate, Cisco, Palo Alto, and Zscaler. As a Series A-stage company, ZeroTier is likely still cash-burning and dependent on venture capital rather than self-sustaining operations.

Key strengths: Institutional VC backing from Battery Ventures, Bonfire Ventures, and Anorak Ventures, Blue-chip enterprise customer base (Thales, Leidos, NTT Data, Volvo, Keysight), Defensible technical moat with open-source heritage and patented protocol, Differentiated post-quantum offering (ZeroTier Quantum, CNSA 2.0 compliant), Capital-light, software-only SaaS model with likely high gross margins, SOC 2 Type II and GDPR compliance, Diversified end-markets across defense, government, manufacturing, IoT, finance, 3M+ devices connected worldwide demonstrating scale milestone, Successful leadership transition with experienced CEO Andrew Gault (2024)

Risk factors: No public financial disclosure - opacity on burn, runway, profitability, Crowded competitive landscape with better-capitalized rivals (Tailscale, Cloudflare, Cisco, Palo Alto, Zscaler), Open-source cannibalization risk as technical users can self-host, Quantum bet timing uncertainty - market adoption may lag revenue, Likely still cash-burning, dependent on venture capital, Recent executive ramp risk following 2024 leadership transition, Founder health challenge (cancer recovery) during 2021-2022 period

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report