Manifest

Manifest is a software and AI supply chain security company focused on helping organizations understand and govern the software and AI they build and buy. Its platform turns SBOMs and AIBOMs into operational workflows for risk analysis, supplier oversight, and compliance, giving teams a clearer view of dependencies, provenance, licensing, and exposure.

Manifest organizes its offering around Manifest Platform, Manifest Product Security, Manifest Supplier Risk, and Manifest AI Risk, with added capabilities for binary inspection, C/C++ SBOM generation, and contributor-level foreign risk analysis. The company is positioned for regulated and security-sensitive environments where software transparency, auditability, and continuous monitoring directly affect product delivery, procurement, and trust.

Offerings, Capabilities, and Integrations

Manifest combines inventorying, enrichment, monitoring, and workflow automation across software and AI supply chains. Its capabilities span SBOM and AIBOM creation and management, vulnerability and license analysis, policy-based alerting, supplier evidence collection, risk reporting, and structured sharing of security artifacts such as VEX and VDR documents.

Manifest supports both cloud-hosted and self-hosted deployment models for organizations with stricter security requirements. It also provides REST API access, CLI-based automation, CI/CD workflow support, and documented integrations with tools such as GitHub, JIRA, ServiceNow, and Linear, alongside support for environments including Azure DevOps, Databricks, and Google Colab.

Products and Services

  • Manifest Platform: Unified platform for managing software and AI supply chain risk across internally developed products, third-party software, and AI systems.
  • Manifest Product Security: First-party software supply chain security module for SBOM and VEX management, open-source risk evaluation, product-level visibility, vulnerability prioritization, and compliance workflows.
  • Manifest Supplier Risk: Third-party software risk management module that helps teams collect supplier SBOMs, analyze vendor software, monitor vulnerabilities continuously, and support C-SCRM processes.
  • Manifest AI Risk: AI supply chain risk and governance module for assessing models, datasets, licenses, dependencies, and provenance, with inventory, policy enforcement, and monitoring workflows.
  • Binary Analysis: Binary inspection capability for compiled software when source code or supplier-provided SBOMs are unavailable, enabling SBOM generation, risk analysis, and ongoing monitoring.
  • Manifest C/C++ SBOM Generator: SBOM generation capability for unmanaged C and C++ software that extends software transparency into embedded, low-level, and device-oriented environments.
  • Manifest Foreign Risk: Contributor-level foreign ownership, control, or influence analysis for open-source components, designed to surface geopolitical and policy exposure in software dependencies.
  • Manifest API: Programmatic API for uploading and managing SBOMs, enriching vulnerability data, generating reports, and integrating Manifest workflows into existing systems.
  • Self-Hosted Deployments: Single-tenant deployment option for organizations that cannot use the Manifest Cloud Platform and need tighter infrastructure control.

Target Customers

Manifest targets enterprise and government organizations that need deeper visibility into the software and AI they develop, acquire, or operate. Its buyers and users include product security, AppSec, DevSecOps, software supply chain, third-party risk, procurement, GRC, and compliance teams.

The company is especially relevant for regulated and security-sensitive sectors such as defense and government, automotive, medical devices, healthcare, financial services, manufacturing, and other critical infrastructure environments. It also fits organizations managing complex vendor ecosystems, embedded software, compiled binaries, or rapidly growing AI adoption programs that require stronger governance and auditability.

Cloud Integrations and Marketplace

  • Azure DevOps: Manifest documents CLI-based SBOM generation and publishing workflows for Azure DevOps pipelines.
  • Databricks: Manifest’s Python plugin supports Databricks notebook workflows for AI policy enforcement, model registration, and AIBOM generation.
  • Google Colab: Manifest’s Python plugin supports Google Colab notebooks for scanning code before execution and applying AI governance controls.

Key People

  • Daniel Bardenstein: CEO & Co-Founder
  • Greg Armor: Chief Revenue Officer
  • Marc Frankel: Co-Founder, Board Member, & Strategic Advisor
  • Mike McDonel: Director of Business Operations

Key Facts

  • Headquarters: New Castle, Delaware, United States
  • Employees: Approximately 31-37 employees
  • Annual Revenue: Undisclosed
  • Parent Company: None
  • Subsidiaries: None
  • Publicly Listed: No (privately held)
Manifest

Enter a search