Manifest
Software supply chain security startup founded by former CISA and DoD veterans, operationalizing SBOMs and AIBOMs to secure the software and AI supply chain.
Visit Website ↗ + Add to CompareOverview
Manifest was built in direct response to the Log4Shell crisis, when major institutions discovered they had no reliable way to know which open-source components were actually running in the software they built or bought. The platform automates SBOM (Software Bill of Materials) generation across multiple formats, assesses vulnerability and third-party risk, and extends the same governance model to AI model risk as AI components increasingly enter the software supply chain alongside open source.
Founded in December 2021 by CEO Daniel Bardenstein and co-founder Marc Frankel, both with backgrounds in CISA and the Department of Defense, Manifest is backed by venture firms including XYZ Venture Capital, Box Group, First Round Capital, and Homebrew. Its government-security pedigree gives it credibility in federal and regulated markets, though as a young company it competes against a growing field of SBOM and software supply chain security vendors.
Innovation Matrix Assessment
Extended SBOM automation into AIBOM/AI supply chain risk relatively early in the AI adoption curve.
Operationalizes SBOM data into actionable vulnerability and third-party risk management rather than static compliance documents.
Solid seed-stage venture backing and a credible federal-security founding team, but still an early-stage company without disclosed large-scale customer figures. Recognized in Cyber Defense Media Group's 2026 Global InfoSec Awards (1 award), independently juried industry validation of market traction.
A genuine extension of SBOM tooling into AI supply chain governance, in an increasingly crowded post-Log4Shell software supply chain security category.
Founding team's CISA/DoD background lends credibility, though independent efficacy validation was not found.
Software and AI supply chain governance will keep growing in importance as SBOM mandates expand and AI components proliferate.
Why CISOs Should Care
Turns SBOM data from a static compliance artifact into an operational tool for tracking open-source and AI component risk.
What Makes It Different
Founding team's direct CISA/DoD experience with federal supply chain security requirements, plus early extension into AIBOM governance.
The Matrix Verdict
63/100 — INCREMENTAL INNOVATOR
A credible, mission-driven early-stage SBOM/supply chain security company with strong founder pedigree; still building market scale.
Editorial Note: Claims vs. Verified Findings
Company background and founding narrative are self-reported; customer scale and funding totals beyond the seed round were not independently confirmed.
Sources
Alternatives to Manifest
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…