Black Kite
Black Kite provides standards-based third-party cyber risk management software to enterprise security and GRC teams, delivering continuous external attack-surface monitoring across 250,000+ organizations, ransomware susceptibility prediction, Open FAIR-based financial risk quantification, and AI-driven vendor assessments.
- Company typePrivate
- Founded2016
- HeadquartersBoston, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Black Kite does
Black Kite (legal entity NormShield, Inc., founded 2016) is a Boston-based software company that provides a standards-based third-party cyber risk management platform to enterprise security, GRC, and procurement teams. Its core offering is a unified platform composed of three modules — Assess (vendor risk assessment), Monitor (continuous external attack-surface monitoring), and Extend (risk intelligence sharing and ecosystem visibility) — underpinned by a vendor inventory, vendor engagement workflow, and a vendor compliance module. The platform continuously monitors 250,000+ organizations using OSINT, processes the resulting telemetry through proprietary analytics such as the Ransomware Susceptibility Index (RSI), FocusTags real-time threat tagging, and the Adversary Susceptibility Index (ASI), and increasingly layers in AI capabilities through the BK-GA3 (Global Adaptive AI Assessment Framework) and an autonomous Black Kite AI Agent launched in November 2025. Distinctive features include Nth-party visibility (mapping fourth-, fifth-, and N-tier supply chain relationships), Black Kite Bridge for vendor remediation collaboration, and the first automated Open FAIR-based Cyber Risk Quantification offering for third-party risk management, released in March 2026. Customer concentration is intentionally diversified across manufacturing, financial services, healthcare, insurance, retail, technology, and public sector verticals, with named enterprise logos including Commerzbank, FINRA, BlueCross BlueShield, RWJBarnabas Health, G42, KION Group, and the University of Kansas Health System.
Black Kite makes money primarily through annual subscription licenses sold via a demo-led, quote-based enterprise sales motion targeting CISOs, TPRM teams, and GRC leaders, supplemented by a partner program of Managed Services Providers and Value Added Resellers, a Carahsoft-led U.S. public sector distribution channel, and premium access to its in-house Research Group's annual ransomware, third-party breach, and supply chain vulnerability reports. Pricing is not publicly disclosed; the company uses 'Book a Demo' and 'Talk to a Risk Expert' entry points, while offering a free Open FAIR report and the publicly available BK-GA3 standard as top-of-funnel demand-generation assets. The company reports serving over 3,000 customers, holds SOC 2 Type 2 and ISO 27001:2022 (October 2024) certifications, and discloses a five-year CAGR of 70% as of November 2025; total disclosed venture funding is $33.1 million, with the most recent round being a $22 million Series B led by Volition Capital in October 2021. The company is venture-backed, privately held, and operates with engineering and operations staff in Istanbul, Turkey alongside its Boston headquarters.
Black Kite firmographics
Firmographics- Name
- Black Kite
- Legal name
- NormShield, Inc.
- Website
- https://blackkite.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Black Kite provides standards-based third-party cyber risk management software to enterprise security and GRC teams, delivering continuous external attack-surface monitoring across 250,000+ organizations, ransomware susceptibility prediction, Open FAIR-based financial risk quantification, and AI-driven vendor assessments.
- Ownership category
- akta.pro rank
Black Kite industry classification
Industry- Product category
- Third-Party Cyber Risk Management Software
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- akta.pro primary industry
- Third-Party & Supply Chain Exposure Monitoring (HDADAHAJ)
- akta.pro secondary industry
- Spam, Fake Engagement & Content Abuse Prevention (HDADALAG)
Keywords
Where Black Kite is headquartered
LocationHeadquarters
- HQ city
- Boston
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Black Kite business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Subscription Platform Licenses: Recurring subscription revenue from enterprise customers licensing the Black Kite platform, including Black Kite Monitor, Assess, Extend, and Black Kite AI modules.
- Managed Services & Partner-Delivered Implementations: Revenue share with Managed Services Partners and Value Added Resellers who deliver ongoing third-party risk program operations and implementation services to end customers.
- Public Sector Distribution: Distribution-led revenue through Carahsoft as Master Government Aggregator for U.S. public sector customers (government agencies and federal entities).
- Research and Intelligence Subscriptions: Premium access to Black Kite Research Group™ outputs (annual Ransomware Report, Third-Party Breach Report, Supply Chain Vulnerability Report) and FocusTag® intelligence feeds for paying customers.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise quote-based subscription (Book a Demo) |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels10 records
Black Kite product offering
Product offeringCore offering
Black Kite provides a SaaS third-party cyber risk management platform that continuously monitors the external attack surface of 250,000+ organizations, scores vendors using standards-based ratings across 20 risk categories, predicts ransomware susceptibility via its proprietary Ransomware Susceptibility Index, and translates cyber exposure into financial loss estimates using Open FAIR-based Cyber Risk Quantification. The platform is sold as annual subscription licenses to enterprise security, GRC, and procurement teams, with distribution through direct sales, a partner program, and Carahsoft for U.S. public sector customers.
Product overview
Black Kite offers a single unified third-party cyber risk management platform with a platform-plus-modules architecture rather than a collection of standalone products. The Black Kite Platform is the umbrella offering and is composed of three core modules — Assess (point-in-time vendor risk assessment), Monitor (continuous external attack-surface monitoring), and Extend (risk intelligence sharing and ecosystem visibility) — supported by a Vendor Inventory, a Vendor Engagement workflow, and Vendor Compliance capabilities. On top of this foundation sits Black Kite AI, an AI layer powered by the proprietary BK-GA3 (Global Adaptive AI Assessment Framework) that delivers AI-Powered Cyber Assessments, AI Questionnaire Management, Custom Cyber Assessment Frameworks, and the autonomous Black Kite AI Agent. Adjacent modules and features include Black Kite Bridge for vendor risk response, Product Analysis for software-composition-level risk, Cloud Asset Mapping for cloud asset visibility, and analytics features such as the Ransomware Susceptibility Index (RSI), Adversary Susceptibility Index (ASI), Cyber Risk Quantification / Open FAIR-Based Risk Assessments, Risk Intelligence (FocusTags), IOC Detection (Black Kite ThreatTrace), Geopolitical Monitoring, and Threat Actor Monitoring, plus Nth-Party Visibility that ties the entire offering together.
Differentiator
Problem solved
Functional benefit
Brands
- Black Kite Monitor: Continuous monitoring module of the Black Kite platform for third-party cyber risk visibility.
- Black Kite Assess
- Black Kite Extend
- Black Kite AI
- Black Kite Bridge™
Products and services
- Black Kite Platform Unified third-party cyber risk management platform that delivers vendor inventory, monitoring, assessment, and engagement capabilities, surfaced through external attack-surface telemetry, standards-based questionnaires, and Open FAIR-based CRQ outputs for enterprise security, GRC, and procurement teams.
- Black Kite Monitor Continuous external attack-surface monitoring module that re-scores vendors over time, feeds the Ransomware Susceptibility Index and FocusTags, and emits alerts when a vendor's posture degrades, used by enterprise TPRM teams for ongoing vendor risk monitoring.
- Black Kite Assess Vendor risk assessment module that produces standards-based cyber ratings, Nth-party visibility, and AI-assisted questionnaire responses for onboarding and re-assessment workflows, used by enterprise GRC and TPRM teams.
- Black Kite Extend Extend module enabling risk intelligence sharing and ecosystem-wide visibility beyond the assessed vendor base, supporting Geopolitical and Threat Actor Monitoring use cases for enterprise TPRM teams.
- Black Kite AI AI layer of the Black Kite Platform, built on the BK-GA3 framework, that powers AI-Powered Cyber Assessments, AI Questionnaire Management, Custom Cyber Assessment Frameworks, and the Black Kite AI Agent for enterprise TPRM teams.
- Black Kite AI Agent Autonomous AI agent launched November 19, 2025 that orchestrates AI-powered cyber assessments, questionnaire automation, and remediation guidance on top of the BK-GA3 framework for security and vendor-risk teams.
- Black Kite Bridge Vendor risk response module launched September 17, 2024 that lets internal teams and third-party vendors collaborate on remediating findings surfaced by Black Kite Assess and Monitor, used by enterprise TPRM and GRC teams.
- BK-GA3 (Global Adaptive AI Assessment Framework) Proprietary AI framework announced November 12, 2025 and released GA November 18, 2025 that unifies over 50 international assessment frameworks (including ISO and NIST) into a single standard for AI-driven third-party vendor risk assessments, available as a free public standard with extended automation for platform customers.
- Product Analysis Module Module launched December 9, 2025 that identifies the third-party software components used inside each vendor product (SBOM-style product composition) and assesses cyber risk at the product level, used by enterprise TPRM and software supply chain security teams.
- Cloud Asset Mapping Capability launched November 19, 2024 that extends external attack-surface visibility into cloud-hosted assets, enriching vendor inventories with cloud asset context for enterprise TPRM teams.
- Open FAIR-Based Risk Assessments Risk assessment offering launched March 17, 2026 that applies the Open Factor Analysis of Information Risk (Open FAIR) standard to produce financial-loss-expectancy outputs for vendor portfolios, positioned as the industry's first automated Open FAIR-based CRQ for third-party risk management.
Quantifiable outcome
- Vendors with RSI > 0.8 are 96x more likely to be hit by ransomware than vendors with RSI < 0.2 (47.3% vs 0.5% attack rate)
- +8 more outcomes
Companies that use Black Kite
Customer profileNamed customers23 records
Segments2 records
Ideal customer profiles4 records
Black Kite technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
AI capability11 records
Feature12 records
Black Kite partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered flagship and core.
- SayariflagshipStrategic partnership and product integration announced April 29, 2026, combining Black Kite's continuous cyber risk ratings and real-time threat intelligence with Sayari's corporate ownership and trade data spanning over 250 jurisdictions. The combined solution supports enhanced due diligence, N-tier supply chain visibility, financial crime compliance, and M&A risk assessments, unifying cyber, supply chain, and corporate risk data.
- CarahsoftcorePartnership announced November 17, 2025, designating Carahsoft as a distributor for Black Kite's third-party cyber risk management platform in the U.S. public sector. The platform delivers automated vulnerability scans, compliance management, and threat intelligence to government agencies through Carahsoft's public-sector contracts.
- Shared AssessmentscoreBlack Kite's Research Group developed the Global Adaptive AI Assessment Framework (BK-GA³™) in consultation with Shared Assessments LLC, synthesizing best practices from hundreds of unique requirements across more than 50 assessment frameworks into a unified standard for assessing AI risk in third-party vendor management.
Scale indicators15 records
Recent moves6 records
Expansion highlights6 records
Black Kite competitors and assessment
Company assessmentDirect peers
- SecurityScorecard: SecurityScorecard is a leading TPRM and cyber risk ratings provider, offering continuously updated A-F ratings across millions of companies. It is the most direct competitor to Black Kite in standards-based third-party cyber risk ratings and ratings-driven vendor risk workflows.
- Bitsight: Bitsight is a pioneer in security ratings and TPRM, offering continuous monitoring, vendor risk management, and now attack-surface management. It directly competes with Black Kite in cyber risk ratings and enterprise TPRM.
- Prevalent: Prevalent offers third-party risk management with vendor assessments, network and endpoint telemetry, and continuous monitoring. It competes with Black Kite in vendor risk assessment and monitoring for mid-market and enterprise customers.
- ProcessUnity: ProcessUnity provides a TPRM platform for vendor risk assessments, due diligence, and continuous monitoring, often integrated with cyber ratings providers. It is a direct competitor in TPRM workflow and risk assessment orchestration.
- UpGuard: UpGuard provides third-party risk management and attack-surface monitoring with continuous vendor ratings and questionnaires. It is a direct competitor in mid-market and enterprise TPRM with overlapping monitoring and questionnaire automation capabilities.
- Panorays: Panorays delivers automated third-party security risk management combining external attack-surface scans, questionnaires, and remediation. It competes directly with Black Kite in TPRM, particularly around AI-driven assessments and supplier onboarding.
Emerging players
- Sevco Security: Sevco provides an IT asset intelligence and attack-surface management platform that feeds into TPRM workflows. It is an emerging player with adjacent telemetry capabilities that increasingly overlap with continuous vendor monitoring.
- Whistic: Whistic is a TPRM platform focused on proactive vendor security assessments and a vendor security network, often used by mid-market buyers. It overlaps with Black Kite on vendor risk assessment and AI-assisted questionnaire workflows.
Broad incumbents
- RiskRecon (Mastercard): RiskRecon, now part of Mastercard, delivers cyber risk ratings and TPRM with a focus on continuous external telemetry. As an incumbent with the Mastercard distribution and data engine, it competes head-on with Black Kite in ratings-based TPRM.
- OneTrust: OneTrust is a broad GRC, privacy, and TPRM platform with vendor risk management as one of many modules. It is a larger incumbent that competes for TPRM wallet share, particularly with procurement and privacy buyers.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Black Kite social profiles
Digital presenceBlack Kite compliance and trust
Trust signalCompliance4 records
Black Kite financial estimates
Financial estimateRevenue estimate
Valuation estimate
Black Kite leadership team
Management profileNumber of profiles
Profiles8 records
Black Kite subsidiaries and ownership
Company hierarchySubsidiaries1 record
Black Kite funding detail
Funding detailFunding overview
Funding rounds4 records
Investors4 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Black Kite M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Black Kite
What does Black Kite do?
Black Kite provides a SaaS third-party cyber risk management platform that continuously monitors the external attack surface of 250,000+ organizations, scores vendors using standards-based ratings across 20 risk categories, predicts ransomware susceptibility via its proprietary Ransomware Susceptibility Index, and translates cyber exposure into financial loss estimates using Open FAIR-based Cyber Risk Quantification. The platform is sold as annual subscription licenses to enterprise security, GRC, and procurement teams, with distribution through direct sales, a partner program, and Carahsoft for U.S. public sector customers.
Is Black Kite a public or private company?
Black Kite is a private company. It is classified as venture growth investor backed and is currently operating.
When was Black Kite founded?
Black Kite was founded in 2016. It employs 11 to 50 people.
Where is Black Kite based?
Black Kite is headquartered in Boston, United States, in the North America region.
How does Black Kite make money?
Four revenue lines are on record. Subscription Platform Licenses are the primary driver. The others are managed Services & Partner-Delivered Implementations, public Sector Distribution and research and Intelligence Subscriptions.
Who are Black Kite's main competitors?
Direct peers on record are SecurityScorecard, Bitsight, Prevalent, ProcessUnity, UpGuard and Panorays. Emerging players are Sevco Security and Whistic. Broad incumbents are RiskRecon (Mastercard) and OneTrust.
Does Black Kite have an API?
No public API is recorded for Black Kite.
What industry is Black Kite in?
Black Kite's product category is Third-Party Cyber Risk Management Software. Its primary akta.pro industry code is HDADAHAJ, Third-Party & Supply Chain Exposure Monitoring, with a secondary code of HDADALAG, Spam, Fake Engagement & Content Abuse Prevention. Its NAICS code is 561621.