How this works

Where the data comes from, what it does and does not cover, and how to read it.

What is this?

A record of which companies the software industry depends on. Every SaaS product runs on other companies’ products — hosting, payments, email, support, analytics — and VendorDb collects those relationships into one place so you can look at them from either end: everything a company uses, or everyone a vendor serves.

Where does the data come from?

From the companies themselves. European data protection law requires a company processing personal data to name the third parties it passes that data to — its subprocessors — and to keep the list current. So most SaaS companies publish one, usually on a legal page or a trust center.

Those pages are the entire source. Nothing here is inferred from job postings, DNS records, or technology-detection scripts. Every company page links to the document its rows came from, so you can check any of it.

What counts as a vendor?

Whatever the company discloses. If a company lists a sales-intelligence tool or a consultancy alongside its cloud provider, all of them appear — the disclosure is the evidence, not our view of what belongs on it. Two things are left out: a company’s own subsidiaries, which are not third parties, and the tracking scripts named in cookie-consent widgets, which sit on the same pages but are not part of the disclosure.

Why does a company show no vendors?

Because we have not found a published list for it. That can mean the company does not publish one, that it is behind a login or an NDA, or that its page blocks automated readers. A zero says something about what is public, not about how many vendors the company uses.

Why do some names read “Salesforce (+Heroku, Slack)”?

Because one company bought another. When a vendor is acquired, its customers keep naming it by the old name for years, and counting those separately would split one company into two entries and understate both. So the acquirer’s entry carries the brands it absorbed. A company that merely changed its name reads Luciq (fka Instabug) instead — one company, one entry, a new name.

How current is it?

Pages are re-read on a rolling basis, and a company’s row changes when its published list changes. Disclosures move at the speed of legal pages, which is to say slowly — but an acquisition or a switched cloud provider can take months to show up in the source document itself, and we can only be as current as what the company prints.

Something here is wrong.

Likely, in a dataset this size. The most useful thing you can send is the URL of the disclosure you are looking at — a page we read incorrectly and a page we never found are different problems, and the link tells them apart.