Black Kite provides AI-native third-party cyber risk management software that helps organizations identify, quantify, and act on cyber risk across vendors, suppliers, and broader supply chain relationships. Its platform is designed to move teams beyond point-in-time questionnaires and opaque scores by combining always-on monitoring, assessment automation, threat intelligence, and financially oriented risk analysis in a single operating environment.
Black Kite positions its platform around visibility and actionability across the extended ecosystem, from direct third parties to deeper downstream dependencies. The company serves more than 3,000 customers and applies its risk intelligence across a dataset spanning more than 40 million companies, supporting security and risk teams that need faster vendor evaluations, clearer prioritization, and stronger remediation workflows.
Offerings, Capabilities, and Integrations
Black Kite combines continuous cyber posture monitoring, AI-assisted assessment workflows, ransomware and vulnerability intelligence, cyber risk quantification, and downstream supply chain visibility. Its approach emphasizes standards-based, explainable risk intelligence rather than black-box scoring, giving teams a clearer view of why a vendor is risky and what actions to take next.
The platform supports operational workflows beyond monitoring alone. Black Kite enables document parsing, questionnaire mapping, gap analysis, vendor collaboration, and incident-driven outreach, while also extending analysis to concentration risk, geopolitical exposure, threat actor susceptibility, and product-level software supply chain risk.
Black Kite also integrates with a broad ecosystem of GRC, collaboration, analytics, and automation tools. Verified integrations include ServiceNow, OneTrust, Archer, LogicGate, Jira, Slack, Microsoft Teams, Power BI, Zapier, Tines, Securonix, Axonius, Coupa, MetricStream, and other workflow or risk-management platforms, alongside MCP-based connectivity for AI assistants and orchestration tools.
Products and Services
- Black Kite Monitor: Continuous third-party cyber risk monitoring that gives organizations real-time visibility into vendor, supplier, and partner exposure, with standards-based intelligence and alerting.
- Black Kite Assess: AI-powered vendor risk assessment capability that automates document review, control mapping, gap identification, and assessment workflows to speed onboarding and periodic reviews.
- Black Kite Extend: Supply chain and nth-party risk capability that maps fourth-, fifth-, and deeper-party dependencies to surface concentration risk, cascading exposure, geopolitical risk, and threat actor susceptibility.
- Black Kite AI Agent: Embedded AI agent that helps users investigate vendor risk, accelerate assessments, and generate reports through contextual Q&A, blueprints, and specialized sub-agents.
- Ransomware Susceptibility Index® (RSI™): Predictive ransomware risk model that estimates which vendors are most likely to be attacked next using real-time signals and threat-pattern analysis.
- ThreatTrace™: Threat detection capability that uses NetFlow and DNS telemetry to identify new indicators of compromise and strengthen third-party cyber risk monitoring.
- Black Kite Bridge™: Vendor engagement and remediation workspace that centralizes communications, evidence sharing, progress tracking, and response orchestration for cyber events and assessments.
- Product Analysis: Product-level software supply chain risk analysis that evaluates third-party software through CPE mapping, SaaS subdomain analysis, and SBOM analysis.
- Open FAIR™-Based Risk Assessments: Cyber risk quantification capability embedded in assessment workflows to estimate probable financial impact for breach, ransomware, and business disruption scenarios.
- Black Kite MCP Server: MCP-based integration layer that lets customers and service providers connect their own AI agents and orchestration tools to Black Kite data and workflows.
Target Customers
Black Kite targets organizations that manage large or business-critical third-party ecosystems and need a more scalable way to evaluate vendor and supply chain cyber risk. Its buyers typically include security, third-party risk management, cyber risk, procurement, compliance, and operational resilience teams that need faster assessments and continuous visibility after onboarding.
The platform is especially relevant for enterprises and public sector organizations operating in highly regulated or disruption-sensitive environments. Black Kite has dedicated industry positioning for financial services, healthcare, insurance, retail, technology, manufacturing, and public sector use cases, including federal supply chain risk management needs.
Black Kite is also suited to organizations that need to quantify cyber risk in business terms, monitor nth-party dependencies, and operationalize remediation with vendors rather than stop at scoring and reporting.
Cloud Integrations and Marketplace
- ServiceNow Store: Black Kite offers a verified ServiceNow TPRM integration that embeds Black Kite intelligence into ServiceNow workflows and is available through the ServiceNow Store.
- FedRAMP Marketplace: Black Kite’s Third-Party Risk Intelligence System is listed in the FedRAMP Marketplace, supporting its positioning for federal supply chain risk management use cases.
Key People
- Paul Paget: Chief Executive Officer
- Candan Bolukbas: Chief Technology Officer & Co-Founder
- Chris Bush: Chief Operating Officer
- Ed Pierce: Chief Financial Officer
- Eireann Connolly: Chief Revenue Officer
- Chuck Schauber: Chief Product Officer
- Bob Maley: Chief Security Officer
- Jessica Stanford: Chief Marketing Officer
- Ferhat Dikbiyik: Chief Research and Intelligence Officer
- Tony Monell: Vice President of Public Sector
- Kelly Houston: Vice President of Human Resources
Key Facts
- Headquarters: Boston, Massachusetts, United States
- Employees: Approximately 125 employees
- Annual Revenue: $20M-$25M
- Parent Company: None
- Subsidiaries: None
- Publicly Listed: No (privately held)
Analyst Recognitions
- Gartner: 2025 Gartner Hype Cycle for Cyber Risk Management – Sample Vendor in Third-Party Cyber Risk Management (TPCRM). 2023 Gartner Peer Insights Voice of the Customer: IT Vendor Risk Management Solutions – Strong Performer; Customers’ Choice in the North America segment.
- Forrester: 2024 The Forrester Wave: Cybersecurity Risk Ratings Platforms, Q2 2024 – Strong Performer.