Skip to main content
frontier

DHS contract turns 28-person Manifest into a federal SBOM bet

By Elena Petrova

The Federal Beachhead

The federal government buys more software than any other entity on the planet, and it has almost no idea what's inside it. That gap — between procurement volume and supply chain visibility — is where Manifest has spent two years building a business. Its contract wins trace the problem's outer edges: Air Force innovation units, the DOD Chief Information Officer's office, the Department of Homeland Security. Each deal expands the surface where Manifest's SBOM and AIBOM platform operates. The question now is whether that surface hardens into a defensible market position.

Manifest has secured a DHS contract to build the federal consumption layer for SBOM lifecycle management and reported $3.1 million in 2025 revenue on a 28-person team — a from-zero trajectory that has drawn competitor counter-moves and investor attention. The contracts form a sequence: Air Force innovation funding proves the AIBOM concept; the follow-on Air Force deal scales SBOM operations; the DOD CIO pilots embed the platform across branches; DHS builds the federal consumption layer; FedRAMP High removes the procurement ceiling. Each step compounds the last.

Manifest's federal trajectory began in the Air Force's innovation ecosystem. In December 2023, AFWERX awarded a Small Business Technology Transfer Phase II contract worth $1.8 million, Source 3 reported, partnered with Tufts University's Fletcher School, to tackle artificial intelligence bills of materials (AIBOMs) for the Department of the Air Force. "There are over 600 AI-enabled programs throughout DOD today, and we must ensure the continued security of these mission-critical applications," CEO Marc Frankel said at the time, according to Source 3. Josephine Wolff, associate professor of cybersecurity policy at the Fletcher School, called the work "pioneering" for AI supply chain security. Two months later, a second Air Force contract, another $1.8 million, Source 1's data shows, extended Manifest's SBOM platform into key user groups across the Department of the Air Force, focused on next-generation software supply chain security.

The DOD CIO office followed in September 2024 with a four-pilot award spanning three military branches. The pilots build directly on Executive Order 14028's SBOM mandates and the Federal Acquisition Regulation requirements that followed. They target concrete operational gaps: rapid assessment of vulnerabilities like Log4Shell, evaluation of vendor secure development practices, persistent monitoring for newly disclosed supply chain attacks, and inventorying open source components across DOD components. "Software runs the military," Frankel said. "It's the most valuable supply chain we have, and it's vital that we have clarity into where that software comes from."

DHS arrived with a different mandate: build tools that let federal agencies read, update, and study the SBOMs they create and collect from vendors. The contract positions Manifest as infrastructure for the government's own compliance machinery — not just a scanner but a platform for ongoing SBOM lifecycle management.

Then came the authorization that changes who can buy. In January 2025, Manifest achieved FedRAMP High authorization through Palantir Technologies' FedStart program. FedRAMP High is the federal cloud security baseline for systems handling the most sensitive unclassified data. It requires continuous monitoring and a third-party assessment organization's validation. Manifest inherited the baseline through Palantir's existing authorization, collapsing the timeline and unlocking the entire federal civilian market at IL5, self-hosted, and air-gapped deployment tiers. Carahsoft, the government IT reseller, now lists Manifest for deployment across SaaS, self-hosted, and disconnected environments.

Revenue and Headcount: The Inflection

Manifest's federal momentum shows up in the numbers. GetLatka tracks the company (listed as "Manifest AI") from founding in 2023 with zero revenue and zero reported headcount to an estimated $3.1 million in annual revenue and 28 employees by July 2025. The inflection is sharp: headcount sat at zero for both 2023 and 2024 before jumping to 28 in 2025, while revenue moved from $0 to $3.1 million in the same window.

These figures align with the contract timeline. The DHS contract, the Air Force engagements, and the FedRAMP High authorization, all secured in the 2024–2025 window, preceded the revenue jump. The authorization process typically requires a year to 18 months of audit work, meaning the process began well before the 2025 inflection. The headcount jump to 28 by mid-2025 suggests the company staffed up to deliver on awarded contracts, not speculatively.

A tension exists in the public record. LeadIQ, as of July 2026, lists a "Manifest" with approximately 286 employees and an estimated annual revenue range of $100 million to $250 million. These figures correspond to a creative agency founded in 1981, not the SBOM-focused company founded in 2023. Philanthropy filings show a separate nonprofit, Manifest Creative Research Gallery, reporting $2.8 million in revenue for fiscal 2024. Pulse2 covered a $3.4 million seed raise for a consumer wellness app also named Manifest, backed by a16z Speedrun and HF0. The GetLatka data (founded 2023, 28 employees, $3.1 million revenue) is the only dataset matching the SBOM/AIBOM platform's timeline, federal customer base, and product launches, including Manifest AI Risk in August 2025. Third-party aggregators frequently conflate distinct entities sharing the Manifest name.

The $3.1 million figure, while modest in absolute terms, represents a from-zero trajectory compressed into roughly two years — a pace that reflects the contract-driven nature of federal sales cycles. Once a platform clears FedRAMP High and lands a DHS or DoD prime, revenue can step-function upward as task orders expand. The 28-person team implies a revenue-per-employee ratio of roughly $110,000, consistent with an early-stage, engineering-heavy shop still building core product rather than scaling go-to-market. The next inflection will come when the SBOM tooling developed under the DHS contract moves from pilot to production deployment across agencies, and when the FedRAMP High status unlocks broader civilian-agency procurement. Those milestones, not headcount alone, will determine whether the current trajectory compounds or plateaus.

Entity Category Amount Period / Date Context
Manifest (SBOM/AIBOM) Annual Revenue $3.1M 2025 (est. July) 28-person team; GetLatka
Manifest (SBOM/AIBOM) Series A $15M Spring 2025
Air Force (AFWERX) STTR Phase II Contract $1.8M Dec 2023 AIBOM pilot with Tufts Fletcher School
Air Force Follow-on SBOM Contract $1.8M Feb 2024 Scaling SBOM platform across DAF
Sonatype Total Funding (pre-acquisition) $148M Nov 2019 Acquired by Vista Equity Partners
Snyk Series G Funding $1.32B
Socket Series C Funding $125M
Jit Total Funding $38.5M Acquired

Hiring: Roles, Skills, and the Screening Funnel

Manifest's hiring surge is visible across its careers page, Greenhouse board, and third-party listings — all pointing to a deliberate expansion of its engineering and customer-facing teams. The company lists two open roles as of the latest Greenhouse feed: a Senior Backend Application Engineer (Product & Platform, Remote-US) and a Customer Success Engineer, Enterprise (Remote). The careers page mirrors the backend role and adds a standing invitation for unlisted talent: "Don't see a job that's a perfect match? We'd still love to hear from you. Reach out to [email protected] with a note about what you can bring to the team."

Federal-facing positions require citizenship due to contract and security requirements, with experience in aerospace and cloud-native security, software supply chain controls, and modern DevSecOps practices. That language aligns with Manifest's FedRAMP High authorization and its DHS, DoD, and Air Force contracts, which demand U.S. persons for classified or controlled unclassified work.

The skills profile extends beyond traditional backend chops. CEO Daniel Bardenstein described the three internal buyer personas Manifest serves: application/product security teams, third-party risk teams, and GRC teams. He noted the platform's workflows span SBOM generation, compliance automation, vendor management (C-SCRM), vulnerability management, open-source tracking, and AI risk governance. Candidates therefore need fluency in SBOM tooling (SPDX, CycloneDX), vulnerability databases (NVD, OSV), and emerging AI/ML model provenance standards. The launch of Manifest AI Risk in summer 2025 ("generally available and there's a lot more to build") adds demand for engineers who understand model cards, data lineage, and open-weight model licensing.

Screening criteria are implied by the company's messaging and contract obligations. The careers page leads with culture: "We're looking for good human beings with the skills and the drive to protect the world's most critical institutions from software supply chain threats." Benefits (fully remote, unlimited PTO, 100% medical/dental/vision for employee and dependents, competitive salary with meaningful stock options, 401(k)) signal a talent market that competes with Series A peers. The Series A close ($15M, spring 2025) and the AI risk product launch provide the runway and product momentum to justify rapid headcount growth.

LinkedIn data shows a company of 11–50 employees as of the latest snapshot, with key hires including a VP of Engineering (Doug Heydt), a Head of Customer Success (Kari Powell), and a Principal Researcher (Gopinath Sundaramurthy, Ph.D.). That composition suggests the next hiring wave will fill out senior IC tracks in backend, platform, and applied research, plus federal program managers who can navigate ATO processes.

The "direct input on the future of the product and the company" promise indicates a flat, high-agency environment where engineers ship to production daily. New postings in federal sales engineering, compliance automation, and AI safety will appear as Manifest converts its DHS SBOM tooling contract into recurring revenue.

Competitors React, Investors Lean In

The federal contract wins and FedRAMP High authorization have not gone unnoticed. CB Insights ranks Manifest among the top ten alternatives to Sonatype: a list that also includes Snyk, Socket, Chainguard, Black Duck, and Jit. Sonatype, the category incumbent acquired by Vista Equity Partners in November 2019 after raising $148 million, has responded with a product cadence that reads like a defensive sprint. Since late 2025 it has launched Nexus One, an AI-native DevSecOps platform; introduced Guide, an intelligent solution for accessibility and secure agentic development; opened an India Innovation Center in Hyderabad for global R&D and AI; and named three industry veterans to its executive team to lead what CEO Bhagwat Swaroop calls "the next chapter of agentic development." Sonatype's own research claims enterprise application creation has accelerated nearly fivefold in the AI era, while modern applications carry over four times more critical and high-severity vulnerabilities — a threat landscape that plays directly to Manifest's SBOM and AIBOM lifecycle focus.

Snyk, sitting on $1.32 billion in Series G funding, has doubled down on its AI security platform that integrates into developer and security workflows, though Sonatype's comparative marketing argues Snyk's SBOM capabilities remain partial, lacking continuous monitoring, auditing, cataloging, VEX support, and distribution, and that Snyk offers no AI model management at all. Black Duck, another top-ten rival, similarly shows no AI model management and only partial support for AI/ML, end-of-life tracking, and popularity metrics. Socket, with $125 million in Series C funding, focuses on JavaScript security solutions. Jit, at $38.5 million raised, has already been acquired. The competitive set is crowded, Sonatype tracks 223 active competitors, 27 of them funded, but the federal procurement signal creates a natural filter: FedRAMP High and a DHS contract to develop tools for agencies to read, update, and study SBOMs are credentials that cannot be bought, only earned.

Investor attention tracks the same signal. Alumni Ventures, an early backer of Manifest, has a portfolio that includes 40 unicorns, 19 IPOs, and 199 acquisitions: Circle, Carta, and Compass among them. The firm's participation in a December 2026 AV Foundation Fund round suggests continued conviction. The broader market math reinforces the thesis: the software supply chain security market is growing rapidly, while the AI security tools market is forecast to grow significantly over the same decade. Hugging Face reported a substantial increase in machine learning models, a data point Sonatype's Brian Fox cites when he says "we're building more software, faster, but we're also introducing risk faster than traditional security processes can absorb it."

Gartner's 2026 Magic Quadrant named Sonatype a Leader for completeness of vision and ability to execute; Forrester's 2024 Wave for SCA Software gave Sonatype the highest possible scores. Those validations confirm the category's maturity — and the room for a federal-first entrant with AIBOM depth to carve a distinct lane. Manifest's capital efficiency on a 28-person team implies the discipline seed-stage investors prize, especially when paired with a contract vehicle that scales across DoD, DHS, and the Air Force. The next funding conversation will likely center on whether Manifest can convert federal beachhead into multi-agency platform adoption before the incumbents close the AIBOM gap.

Automotive and Financial Services: The Regulated Pull

Manifest's federal traction is pulling regulated industries into its orbit. The clearest signal came in November 2025 when the company announced a partnership with the Automotive Security Research Group (ASRG), a global non-profit community of 20,000-plus professionals across 50 chapters. ASRG is not a vendor or regulator — it sits between researchers trying to disclose responsibly, engineers shipping on deadlines, OEMs and suppliers balancing transparency with IP protection, and practitioners who want safer vehicles. Manifest brings the platform; ASRG brings the ecosystem.

The partnership targets a problem that looks familiar to defense buyers. Modern vehicles run on layered software and AI stacks stitched from in-house code, open-source libraries, third-party vendors, and pre-trained models. Every connection (over-the-air updates, vehicle-to-everything communication, voice assistants, crash-detection models) expands an attack surface that regulations are only starting to map. ISO/SAE 21434, UNECE R155 and R156, and emerging guidance from the Commerce Department's Bureau of Industry and Security all demand verifiable transparency into software and AI origins across a vehicle lifecycle that spans a decade or more.

Provenance is the new perimeter. If you don't know where something came from or what's inside it, you can't reasonably call it secure.

The joint service will stand up a public-facing transparency layer that surfaces trustworthy SBOMs and AIBOMs for automotive components with verified provenance and integrity. Instead of raw dependency dumps, it delivers prioritized risk insights. It also provides cross-tier visibility into supplier and component-level risk without forcing OEMs or Tier 1s to reveal sensitive implementation details, a balance the industry has struggled to strike. Coordinated disclosure gets a structured rail: vulnerabilities tie to specific components, SBOM entries, and models with provenance context so the right supplier or model owner is contacted immediately.

This is not theoretical. Manifest's Supplier Risk product, already live, rolls risk up to the vendor level, ranks every supplier by risk score and exposure, and traces a vulnerability from supplier to product to the exact component that caused it. If a vendor won't share an SBOM, Manifest can generate one from a binary. The same architecture now serves automotive through ASRG's infrastructure.

The hiring implications follow the product. Automotive security teams need engineers who understand SBOM lifecycle management, AIBOM generation for ML models, and the regulatory vocabulary of ISO/SAE 21434 and UNECE R155/R156. They need people who can translate technical risk data into plain-language summaries for executives, regulators, and eventually drivers. Manifest's own blog frames it as "taking deeply technical risk data and translating it into something meaningful for engineers, executives, regulators, and eventually, drivers." That translation layer is a hiring category unto itself.

Financial services adoption appears earlier in its curve. Manifest's LinkedIn presence lists healthcare, automotive, and defense as the regulated verticals where its platform operates. A separate property, manifest.ly, publishes compliance checklists for financial services covering regulatory requirements, data analytics, and monitoring, but that product appears distinct from the SBOM/AIBOM platform driving federal revenue. The overlap is regulatory pressure: both sectors face mandates to prove software supply chain integrity, and both are moving from checkbox compliance to continuous monitoring. Where automotive has ASRG as a community anchor, financial services lacks an equivalent public partnership announced to date.

Over the coming months, ASRG and Manifest plan to onboard SBOMs and AIBOMs into a shared data environment for members, build supplier and component-level risk views across the vehicle lifecycle, and experiment with consumer-facing transparency features. Each milestone expands the surface area for hiring — not just in engineering but in regulatory affairs, technical product management, and community engagement roles that bridge the platform and the industry it serves.

The federal beachhead that began with an Air Force AIBOM pilot now stretches from DHS compliance infrastructure to automotive supply chains. Manifest's $3.1 million in 2025 revenue is the smallest number in this story — but it is the only one that proves the contracts are real, the platform ships, and the hiring surge has a payroll to meet.


Working in frontier tech? Zero G Talent tracks the openings: see every open ASML role, browse frontier tech jobs, openings at Stripe, and the people building the field.

Ready to Start Your Space Career?

Browse frontier jobs and find your next opportunity.

View frontier Jobs