Zurb
United States · get.foundation · 6 vendors
Resilience scores
- Digital Sovereignty: 83
- Digital Resilience: 5
- Financial Resilience: 4
Technology vendors
- Fastmail Pty Ltd — Technology — Australia
- Google LLC — Technology — United States
- Netlify, Inc. — Technology — United States
- and 3 more
Services catalogue
1 service in catalogue across 1 category; runs on 6 sub-vendors.
- Foundation
Insights
Last updated 2026-08-02 · revision 2
6 direct vendors, 113 subvendors
Direct vendors by controlling owner country (sample)
- United States: 5
- Australia: 1
Subvendors by controlling owner country (sample)
- Sweden: 2
- Denmark: 3
- Norway: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Zurb demonstrates high migration readiness, largely driven by its modern and web-focused internal tech stack. The use of cloud-native services such as Netlify for hosting, GitHub Actions for CI/CD, and jsDelivr as a CDN indicates familiarity and integration with cloud environments. The company's primary products are front-end frameworks, which are generally less complex to migrate than extensive backend systems. A significant advantage is the absence of specified data residency requirements, removing a common and often complex barrier to cloud migration. However, the lack of explicit mention of containerization (e.g., Docker, Kubernetes) or a microservices architecture suggests that some refactoring might be necessary for a full cloud-native transformation. The absence of financial data (revenue, growth history) makes it difficult to assess the company's capacity to fund a potentially significant migration effort. The regulatory environment is also unknown, which could introduce unforeseen compliance challenges. While the overall vendor landscape and potential lock-in risks are not fully detailed, the nature of the services used suggests moderate rather than heavy vendor lock-in.
Compliance
6 in-scope frameworks identified; showing 3.
PCI DSS (source) — Assessment Required
ZURB University offers paid online courses and certifications, and ZURB provides enterprise consulting services — both of which likely involve payment card processing. PCI DSS applies to any organization that accepts, processes, stores, or transmits cardholder data. The risk is Medium because: (1) ZURB likely uses a third-party payment processor (e.g., Stripe, PayPal) which would reduce PCI DSS scope significantly; (2) if ZURB uses a fully hosted payment page (SAQ A), compliance requirements are minimal; (3) however, if ZURB stores any cardholder data or uses custom payment integrations, higher PCI DSS compliance tiers apply; (4) no PCI DSS compliance attestation was found publicly.
Evidence: https://zurb.com/university, https://get.foundation/learn/certification.html, https://www.pcisecuritystandards.org/
SOC 2 (source) — Assessment Required
ZURB operates the Notable Platform (a SaaS product for progressive design/product collaboration) and ZURB University (an online learning platform), both of which involve storing and processing customer data in the cloud. SOC2 (Service Organization Control 2) is relevant for any organization that stores, processes, or transmits customer data via cloud services. While ZURB is a small company (~25 employees), its SaaS offerings (Notable, ZURB University) create a reasonable expectation from enterprise clients (Samsung, eBay, Netflix, SAP) for SOC2 Type II assurance. The risk is Medium because: (1) enterprise clients increasingly require SOC2 reports from vendors; (2) no SOC2 certification was found publicly; (3) absence of SOC2 may limit ZURB's ability to serve regulated enterprise customers.
Evidence: https://get.foundation/showcase/about.html, https://zurb.com/notable, https://zurb.com/university, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
CAN-SPAM Act — Assessment Required
ZURB operates an email sponsorship program (get.foundation/email-sponsorships.html) and sends marketing communications via ZURB University and Foundation newsletters. The CAN-SPAM Act (15 U.S.C. §7701) applies to commercial email messages sent by US-based companies. Risk is Low because CAN-SPAM requirements are relatively straightforward (honest subject lines, physical address, opt-out mechanism) and ZURB's email marketing appears limited in scope. However, for EU recipients, GDPR's stricter consent requirements for email marketing also apply.
Evidence: https://get.foundation/email-sponsorships.html, https://get.foundation/get-involved/faq.html, https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 4/10
ZURB is a privately held, bootstrapped US product design consultancy founded in 1998 with 25+ years of operational longevity and no publicly known distress events. Its foundational open-source framework (Foundation) achieved substantial brand recognition, and the company has historically served blue-chip enterprise clients such as Samsung, eBay, McAfee, Mozilla, Netflix, and SAP, providing a diversified revenue mix across design consulting, the Notable SaaS platform, training/certification, and enterprise support subscriptions. However, multiple qualitative signals point to material business contraction. The website copyright has not been updated since 2021, blog and release cadence has slowed dramatically, and Foundation has lost significant market share to Bootstrap, Tailwind CSS, and modern React/Vue component ecosystems since around 2018. The framework is now largely community-maintained on GitHub rather than actively developed by ZURB. LinkedIn headcount appears to have declined to single/low double digits from a historical 20–50 employees, consistent with an apparent commercial wind-down. With no public financial disclosures (no SEC filings, no audited statements), counterparty due diligence is difficult, and third-party revenue estimates (~US$5–15M) are algorithmic and unverified. Combined with key-person risk typical of small design agencies, cyclicality of discretionary consulting revenue, and the apparent activity slowdown, financial resilience is assessed as below-average despite the company's long history.
Key strengths: 25+ years of continuous operation since 1998, Bootstrapped with no known VC debt overhang, Strong historical brand recognition through Foundation framework, Diversified revenue across consulting, SaaS, training, and enterprise support, Enterprise client roster including Samsung, eBay, Netflix, SAP, Mozilla
Risk factors: Foundation framework losing market share to Bootstrap, Tailwind, and React/Vue ecosystems, Apparent slowdown: website copyright stops at 2021, blog and release cadence stalled, Key-person / small-agency concentration risk, No public financial disclosures available for due diligence, Cyclical exposure via discretionary design consulting revenue, LinkedIn headcount appears materially reduced from historical levels
Workforce by country
- United States: 30
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.