Full-Time
Automates SBOM generation and risk assessment
$180k - $200k/yr
Remote in USA
Remote
| , |
See people who can refer or advise you
Manifest Cyber provides a platform for SBOM management that strengthens software supply chain security for large enterprises. It automatically generates SBOMs, including third-party and open-source components, with zero-click generation and secure storage. The platform detects vulnerabilities, assesses third-party risk, and supports regulatory compliance, offering enriched data to prioritize fixes. Its goal is to help customers quickly respond to threats and improve overall cybersecurity posture by simplifying SBOM generation, storage, and action.
Company Size
11-50
Company Stage
Series A
Total Funding
$21M
Headquarters
East Portal Distributed Camping Area, Colorado
Founded
2022
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Unlimited Paid Time Off
Remote Work Options
401(k) Retirement Plan
Stock Options
Manifest Cyber has launched three new capabilities for its software and AI supply chain security platform ahead of Black Hat USA 2026. The Manifest Insights Agent (MIA) uses AI to analyse blast radius against an organisation's software inventory in seconds. Foreign Risk identifies open source contributors linked to sanctioned nations or state-controlled institutions, using a database of 20 billion foreign risk records across 18 categories. Product Hierarchy provides drill-down visibility from mission system to component level, with automated risk rollup at each layer. The releases address regulatory shifts towards product-level accountability, including FOCI requirements for unclassified defence contracts over $5 million and Bureau of Industry and Security rules on connected vehicles. CEO Daniel Bardenstein said the updates close gaps in turning risk detection into actionable answers during incidents, product shipping, and regulatory queries.
Introducing manifestforeign risk. Kayleen Standridge June 4, 2026 Know who wrote the code in your software. Today, Manifest is launching Manifest Foreign Risk, a new generally available capability that gives security teams contributor-level visibility into the open source components inside their software. For the first time, organizations can systematically identify whether open source contributors are affiliated with sanctioned nations, foreign military organizations, intelligence agencies, or state-controlled institutions, and act on that information before software ships. Why Manifest built this. Government, defense, and enterprise customers have been asking Manifest the same question for years: how do Manifest know there is no foreign influence in the software Manifest build and buy? Until now, there was no good answer. Security teams could tell you what was in their software. They could tell you which components had known vulnerabilities, which licenses applied, and which vendors had passed a questionnaire. What they could not tell you was who wrote the code? Where those contributors were based. Who employed them? What institutions appeared in their professional history? That is the gap Manifest Foreign Risk closes. Why this matters. This launch is not happening in a vacuum. The regulatory environment has shifted in ways that make contributor provenance a business-critical concern, not just a security nicety. In May 2024, DoW issued Instruction 5205.87, extending Foreign Ownership, Control, or Influence (FOCI) requirements to any company holding unclassified DoW contracts over $5M. What was once limited to cleared contractors and classified programs now applies across a much broader slice of the defense industrial base, including commercial software vendors who have never considered FOCI their problem. DoW now has explicit authority to cancel contracts or require mitigation if FOCI is found. As Manifest explored in past blogs, this is part of a broader shift in how governments are thinking about software risk. It is no longer purely about vulnerabilities. It is about control, authorship, and provenance. Defense is not the only sector feeling this pressure. The BIS Connected Vehicles rule,, prohibits vehicles containing software tied to Chinese or Russian ownership or control starting in Model Year 2027. The pattern is clear. Regulators across sectors are deciding that knowing what is in your software is no longer enough. You need to know who shaped it. What Manifest Foreign Risk does. Manifest Foreign Risk analyzes the contributors behind open source components in any software bill of materials (SBOM). It draws on a database of 20 billion foreign risk records across 18 risk categories, including government affiliation, military ties, security and intelligence associations, defense university connections, restricted entity links, and more. All sourced from public records, corporate filings, sanctions lists, and open source intelligence (OSINT). Every contributor surfaces with one of three risk signals. Banned Country. Commit metadata, residency, or organizational affiliation places this contributor in a country on your prohibited list. Institution Association. The contributor or their employer is institutionally linked to a foreign military, intelligence agency, or state-controlled lab. Unknown. The identity cannot be verified. Anonymized email, throwaway handle, or insufficient public footprint, flagged for human review before release. The capability is policy-driven. Every risk category can be enabled or disabled based on your organization's requirements. Findings are configurable to your thresholds, exportable as evidence, and traceable to a specific author or library. Who this is for. Manifest Foreign Risk is built for the teams that own software supply chain risk in practice. AppSec and product security teams can treat contributor flags the way they treat CVEs: severity, owner, review date, and a gate on future introductions. TPRM teams can surface findings in vendor assessments and require written responses that create accountability and an audit trail. GRC teams can map findings to NIST 800-53 SR-3 and SR-4 controls, support Cybersecurity Maturity Model Certification (CMMC) documentation requirements, and build a board-reportable metric from quarterly re-runs. For all three, the immediate value is the same: evidence you can bring to a program office, contracting officer, or auditor. Not a score. Not a report. A documented finding with a name, a source, and a severity behind it. What comes next. Manifest Foreign Risk is available now as part of The Manifest Platform. CVEs get triaged. Licenses get reviewed. Vendors get questionnaires. The contributor behind the code has been the missing piece. That changes today. "Manifest knows the AIBOM and cybersecurity space, sees the problems arising, and always has a solution to showcase." Manager of Global Technology Legal Compliance, Multinational Software Company Secure your software supply chain today.
Manifest, a software and AI supply chain security platform, has launched an SBOM generator for C and C++ programming languages, addressing long-standing visibility gaps in critical systems. The tool enables teams to generate, inventory and scan accurate software bills of materials for C/C++ code, which underpins vehicles, medical devices, defence platforms and industrial equipment. The generator provides visibility into low-level components, accelerates vulnerability response, and helps organisations meet regulatory requirements in sectors like medical devices. Manifest is also introducing enhancements including automated vulnerability mapping for Nix packages, binary analysis for third-party risk mitigation, and continuous AI model scanning. Founded in Washington, Manifest serves organisations across defence, healthcare, automotive and other regulated industries requiring software supply chain transparency and compliance.
Manifest, a platform for software and AI supply chain security, has appointed Greg Armor as chief revenue officer. Armor will lead global sales, revenue operations, partnerships and customer expansion as the company scales across commercial and public sectors. Armor brings 25 years of go-to-market leadership in cybersecurity. He previously served as CRO at Sycurio, where he transformed the company's go-to-market strategy, and held leadership positions at Appdome, Gryphon.ai and BitSight. At Manifest, Armor will focus on driving operational adoption, scaling revenue through integrated risk management, and strengthening ecosystem adoption across regulated sectors including federal, automotive, defence, healthcare, manufacturing and financial services. The appointment reflects Manifest's growth as software and AI supply chain risk becomes a board-level priority for organisations.
Welcoming allanfriedman to Manifest. Today I am thrilled to share that Allan Friedman is joining Manifest as a Strategic Advisor. Aside from being a good friend and former colleague of mine, Allan is known around the world as the 'godfather of SBOMs,' referring to the software bill of materials concept that he has been doggedly promoting for more than half a decade. He and I share a common outlook on the state of cybersecurity, the lack of transparency in technology, and the need to raise the bar on software suppliers to write more secure software. Without Allan's work, Manifest would not be in the strong position it is now. Why Allan. The story that I've heard is that the modern incarnation of SBOMs came up in conversation with Allan, and fellow cybersecurity + policy experts Josh Corman and Alex Romero. But an idea without motion or adoption is just that, an idea. Starting with his diligent work at NTIA, where he stood up the first SBOM working group, Allan and worked tirelessly to bring SBOMs to CISA, write SBOMs into major Executive Orders and US government policies, and align global regulators and lawmakers on the value and framing of SBOM policies. Allan possesses an invaluable wealth of knowledge and experience around software supply chain security, and how both industry leaders and global policymakers understand and act on that topic. He also knows the pain points that many security practitioners have in actually adopting SBOMs and implementing SBOM programs. It's not enough to just generate or store these machine-readable (i.e., not human-readable) bits of data. As Manifest continues to expand its customer base across different industries and engage with policymakers around the world, Allan's experience will go far to push Manifest to new heights. How its paths crossed. I first met Allan while researching medical device cybersecurity at the Aspen Institute. While I was learning about the gaps and pain points in healthcare security, Allan first introduced to me the concept of the SBOM, and explained why SBOMs matter for patient safety and critical systems. Manifest collaborated and stayed in touch during my time at CISA, where Manifest partnered on Secure by Design initiatives and he supported my work leading the Cross Sector Cybersecurity Performance Goals. After I co-founded Manifest, Manifest continued its professional collaboration, comparing notes on how to make SBOMs usable and easier to adopt. I'm proud that its friendship and partnership has spanned nearly half a decade. What Allan will help Manifest do. * Keep Manifest aligned with the various global SBOM community, including open source and standards bodies * Translate policy into product, so requirements become workflows that teams actually use * Grow partnerships that speed adoption across the public sector and critical infrastructure * Support Manifest's engagement with policymakers around the world, developing smart and aligned regulations for software and AI security * Partner on Manifest's long-term vision, especially as it pertains to hardware BOMs and hardware supply chains "Working with CISA and helping to build a global community around SBOM showed what's possible when we focus on transparency. As an advisor to Manifest, I'm excited to translate those lessons into products that help organizations have real visibility into the AI and software they rely on, so they can build, ship, and buy with confidence." - Dr. Allan Friedman, Former Technical Advisor & Strategist, CISA The Manifest roadmap. Manifest is building the central clearinghouse for software and AI supply chain risk. That starts with SBOMs and AIBOMs, and it extends to cryptography, binaries, firmware, AI components, and other software and AI artifacts. Manifest is laser focused on building intuitive, easy to deploy products that help its users identify risk, save time, and maintain a more secure enterprise. With Allan's help, Manifest is sure to continue that promise to its customers. If you want to see what Manifest is building, reach out. If you are part of the SBOM community, Manifest would love your feedback and your toughest test cases. Welcome aboard, Allan. Manifest is lucky to have you, and Manifest is ready to get to work.