Manifest
- Company typePrivate
- Founded2022
- HeadquartersNew York, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
Manifest firmographics
Firmographics- Name
- Manifest
- Legal name
- Manifest Cyber, Inc.
- Website
- https://manifestcyber.com
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
Manifest industry classification
Industry- Product category
- Software Supply Chain Security
- NAICS
- Software Publishers (513210), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industry
- DevSecOps & Supply Chain Security (DevOps toolchain security) (BPAEAKAI)
Keywords
Where Manifest is headquartered
LocationHeadquarters
- HQ city
- New York
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Manifest business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Platform Subscription: Manifest operates as a SaaS platform providing SBOM and AIBOM management capabilities on a subscription basis. The Terms of Service reference subscription-based access, and the CRO appointment indicates a sales-led revenue motion targeting enterprise customers in regulated industries.
Go-to-market motion2 records
Distribution channels3 records
Marketing channels7 records
Manifest product offering
Product offeringCore offering
Manifest Cyber provides a unified SaaS platform that automates the generation, management, and analysis of Software Bills of Materials (SBOMs) and AI Bills of Materials (AIBOMs) across the entire software and AI supply chain. The platform supports SPDX, CycloneDX, and VEX formats, performs binary and firmware analysis, matches vulnerabilities against industry databases with exploitability scoring (EPSS/KEV), and tracks foreign ownership risk. It serves highly regulated organizations in defense, government, healthcare, medical devices, automotive, and financial services with FedRAMP High Authorization and DoD IL5 compliance.
Product overview
Manifest offers a unified software and AI supply chain security platform called The Manifest Platform. The platform consists of three core integrated modules: Product Security (for internal software SBOM generation and vulnerability management), Supplier Risk (for third-party/vendor risk assessment), and AI Risk (for AI model governance and AIBOM management). These modules are supported by platform features including SBOM Generation & Management, AIBOM capabilities, Binary Analysis (Beta), Foreign Risk analysis, Vulnerability Management, C-SCRM workflows, and a Developer CLI tool. The platform automates the entire SBOM and AIBOM lifecycle from generation through ingestion, analysis, vulnerability matching, and compliance reporting, targeting highly regulated industries including automotive, defense, government, healthcare, medical devices, and financial services.
Differentiator
Problem solved
Functional benefit
Products and services
- The Manifest Platform Unified software and AI supply chain security platform that automates SBOM and AIBOM generation, ingestion, vulnerability assessment, and compliance management across the entire software and AI lifecycle, targeting highly regulated industries.
- Product Security Module Platform module enabling Product Security, DevSecOps, and AppSec teams to identify and resolve software supply chain risks early, including SBOM generation, vulnerability management, and product hierarchy modeling.
- Supplier Risk Module Third-party risk management module providing real-time risk insights, full visibility into how supplier products are built, and continuous SBOM and binary analysis to catch vulnerabilities early and hold vendors accountable.
- AI Risk Module Module for AI supply chain security that continuously monitors GenAI models and data, enforces governance policies, and tracks model provenance from development through deployment, including AIBOM generation and AI model vulnerability assessment.
- Manifest AI Risk (Continuous AI Model Monitoring) Standalone AI risk product module that continuously monitors GenAI models and data, enforces AI governance policies, and tracks model provenance from development through deployment, including AIBOM generation.
- C/C++ SBOM Generator SBOM generator for unmanaged C and C++ programming languages that addresses long-standing visibility gaps in software supply chain security for critical systems.
- Product Hierarchy Capability that allows security teams to model products as systems made up of subsystems and components, with vulnerabilities in a component automatically surfacing on every parent product for blast radius visibility.
- Foreign Risk Capability analyzing contributors behind open source components to surface potential foreign ownership, control, or influence (FOCI) exposure across 18 risk categories for defense and regulated environments.
- Binary Analysis (Beta) Beta capability to analyze compiled software artifacts directly, generating SBOMs from binaries and detecting newly disclosed vulnerabilities in deployed components.
- Manifest CLI Command-line interface tool for automated SBOM generation, asset management, and CLI-based analysis, supporting CI/CD pipeline integration with Jenkins and Azure DevOps.
Quantifiable outcome
- 99% reduction in time spent managing third-party SBOMs
- +4 more outcomes
Companies that use Manifest
Customer profileNamed customers6 records
Segments5 records
Ideal customer profiles4 records
Manifest technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration7 records
AI capability6 records
Feature10 records
Manifest partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core and minor.
- ASRG (Automotive Security Research Group)coreManifest joined ASRG as a supporting partner to enhance cybersecurity and transparency in the automotive industry through shared tools and risk assessment capabilities. The partnership aims to develop new services that improve vehicle cybersecurity and build trust among consumers, researchers, and manufacturers. Manifest is building public-facing services for verifiable SBOMs, AIBOMs, and supply chain transparency to secure the next generation of vehicles.
- NetRisecoreStrategic partnership to provide comprehensive visibility of software and firmware risks from source code to device firmware. The integration enables organizations to generate SBOMs for firmware and embedded systems directly within the Manifest platform, addressing a security gap especially relevant for legacy systems in sectors like healthcare. This collaboration enhances risk assessment capabilities across the entire technology stack.
- DigiSaaS / ARGO EcosystemminorManifest joined DigiSaaS to enhance the ARGO ecosystem, indicating participation in an industry consortium focused on digital SaaS security.
- SolaSeccoreStrategic partnership announced in July 2024 between Manifest and SolaSec to advance software supply chain security capabilities.
- Advisory Board Members (Esteemed Industry Leaders)coreManifest appointed esteemed industry leaders to its advisory board, including Allan Friedman (former CISA strategist, 'godfather of SBOMs'), to provide strategic guidance on software supply chain and AI risk management. Allan Friedman joined as advisor in November 2025.
- The Fletcher School at Tufts UniversitycoreManifest's work with AFRL includes partnership with The Fletcher School at Tufts University, focusing on the feasibility of automatically generating AIBOMs at scale for Air Force components.
- CarahsoftcoreCarahsoft serves as a technology partner and government IT distributor, enabling Manifest's solutions to reach federal government customers through established procurement channels.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Manifest competitors and assessment
Company assessmentMarket position
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Manifest social profiles
Digital presenceManifest compliance and trust
Trust signalCompliance6 records
Manifest financial estimates
Financial estimateRevenue estimate
Valuation estimate
Manifest leadership team
Management profileNumber of profiles
Profiles5 records
Manifest funding detail
Funding detailFunding overview
Funding rounds2 records
Investors12 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Manifest M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Manifest
What does Manifest do?
Manifest Cyber provides a unified SaaS platform that automates the generation, management, and analysis of Software Bills of Materials (SBOMs) and AI Bills of Materials (AIBOMs) across the entire software and AI supply chain. The platform supports SPDX, CycloneDX, and VEX formats, performs binary and firmware analysis, matches vulnerabilities against industry databases with exploitability scoring (EPSS/KEV), and tracks foreign ownership risk. It serves highly regulated organizations in defense, government, healthcare, medical devices, automotive, and financial services with FedRAMP High Authorization and DoD IL5 compliance.
Is Manifest a public or private company?
Manifest is a private company. It is classified as venture growth investor backed and is currently operating.
When was Manifest founded?
Manifest was founded in 2022. It employs 11 to 50 people.
Where is Manifest based?
Manifest is headquartered in New York, United States, in the North America region.
How does Manifest make money?
One revenue line is on record: saaS Platform Subscription.
Does Manifest have an API?
Yes. Manifest offers a public API that enables programmatic access to the platform for SBOM management, vulnerability analysis, product hierarchy management, and AI model inventory. The API supports user tokens for authentication (org tokens deprecated as of April 2026), with various token scopes for different operations. Features include: generating SBOMs, uploading and managing assets, vulnerability analysis, AIBOM management, inventory management APIs for sub-products, and policy configuration. Available via API Docs at http://api-docs.manifestcyber.com/. Manifest also provides a CLI tool for automation. Developer documentation is at api-docs.manifestcyber.com.
What industry is Manifest in?
Manifest's product category is Software Supply Chain Security. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of BPAEAKAI, DevSecOps & Supply Chain Security (DevOps toolchain security). Its NAICS code is 513210 and its SIC code is 7372.