Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Manifest Raises $15 Million Series A for SBOM and AI Supply-Chain Platform

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Manifest raised $15 million in a Series A announced April 25, 2025. Ensemble VC led the round, which brought the Connecticut-based company’s reported total funding to $23 million. Manifest says it will use the financing partly to expand into Europe as it develops software-bill-of-materials (SBOM) and AI-bill-of-materials (AIBOM) management for enterprise and government customers.

The funding at a glance

Item Reported detail
Announcement April 25, 2025
Round $15 million Series A
Lead investor Ensemble VC
Other investors AE Ventures, First Round Capital, Homebrew, Leap435, Overmatch VC and XYZ
Reported total funding $23 million
Company Founded in 2022; based in Connecticut

Manifest’s funding announcement and SecurityWeek’s report do not disclose a valuation, revenue, customer-count breakdown, debt, secondary transactions or a detailed allocation of the capital. The announced expansion target was Europe; any broader assumptions about hiring, acquisitions or infrastructure spending remain analysis rather than disclosed facts.

What Manifest’s platform is designed to do

An SBOM is an inventory of the components inside a software product, including open-source packages, commercial dependencies and proprietary elements. Manifest’s pitch is that generating a file is only the beginning. Organizations also need to collect supplier-provided inventories, normalize identities, track versions, connect components to products and deployments, assess vulnerabilities, assign remediation work and preserve evidence for audits or incident response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

According to SecurityWeek, Manifest says its platform can:

#1 Best Overall
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
  • Generate, ingest, analyze and track SBOMs throughout their lifecycle.
  • Visualize dependencies and identify previously hidden risks.
  • Share supply-chain information with relevant stakeholders.
  • Connect findings to ticketing and remediation workflows.
  • Support procurement, policy enforcement and threat response.

Those are vendor and publication-reported capabilities, not independent measurements of accuracy, coverage or remediation speed. A buyer should test how the product handles incomplete inventories, conflicting supplier data and components that change after deployment.

Why Manifest adds AIBOMs

Manifest also positions its product around AIBOMs—inventories for artificial-intelligence systems. The company describes coverage for models, datasets, dependencies and deployments, alongside monitoring claims involving tampering and malformed inputs.

This extends the conventional SBOM problem to questions such as which model is in production, which dataset or fine-tune it uses, what version is deployed, which supplier is responsible, and whether a deployment changed. The financing announcement does not establish AIBOM as a universally settled standard, nor does it independently validate Manifest’s monitoring. Prospective customers should ask whether each AI feature is generally available, limited release or roadmap, and whether it records model provenance, prompts, inference services and deployment history separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reported customers and target sectors

SecurityWeek reported that Manifest said its platform was being used by the U.S. Air Force, the Department of Homeland Security, various Fortune 500 companies, and organizations in automotive, defense and financial services. These statements should be read as company-reported adoption claims. The available coverage does not provide contract values, deployment size, retention rates or a complete named-customer list, and an agency reference does not by itself establish department-wide deployment.

Rank #2
SecuX PUFido® Drive Clife Key USB C Security Key with PUF Technology and Built in Flash Drive, FIDO2 U2F Certified Hardware Rooted Unclonable Security for Passwordless Login and 2FA Authentication (1)
  • Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
  • FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
  • Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
  • Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
  • Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.

Why the 2025 round mattered

Software suppliers and their customers face growing pressure to document third-party and open-source dependencies. Government and regulated-industry procurement can require software-composition information, while security teams increasingly need to turn vulnerability data into prioritized remediation and audit evidence. In practice, an SBOM program has several distinct stages:

  1. Generate: Create an inventory from source, binaries, containers, firmware or build artifacts.
  2. Collect: Ingest SBOMs from suppliers and internal teams.
  3. Normalize: Resolve package names, versions, suppliers, PURLs, CPEs and hashes.
  4. Analyze: Map components to vulnerabilities, licenses and policy requirements.
  5. Contextualize: Link findings to actual products, environments, reachability and business criticality.
  6. Act: Open tickets, apply fixes or compensating controls, record exceptions and retain evidence.
  7. Maintain: Detect drift between builds, releases and production deployments.

Manifest is seeking to occupy this system-of-record and workflow layer rather than be viewed only as an SBOM generator. The $15 million round gave it capital to expand that proposition commercially, including in Europe, but the announcement does not prove that it displaces established software-composition-analysis tools.

How Manifest compares with alternatives

Anchore Enterprise

Anchore Enterprise emphasizes SBOM-powered software-supply-chain security, including internally generated and externally supplied SBOMs, vulnerability analysis, policy enforcement and CI/CD or registry integrations. It is a natural comparison for organizations seeking a mature, software- and container-oriented lifecycle platform. Buyers whose primary need is AI inventory or broad supplier governance should verify fit rather than assume feature parity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Snyk

Snyk is broader developer-security tooling, covering open-source dependencies, code, containers and infrastructure as code. Its published pricing at the time reviewed listed a free tier, a Team plan at $25 per month per contributing developer, an Ignite plan at $1,260 per year per contributing developer, and Enterprise pricing by quote. Prices can change. Snyk may suit engineering-led teams, while per-developer pricing can be less attractive when the requirement is a centralized supplier-SBOM repository.

Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Cybellum

Cybellum focuses on product security for automotive, medical, industrial and connected-device manufacturers. Its positioning includes asset and SBOM management, validation, vulnerability and product-risk workflows, compliance evidence and incident response. It may be a stronger fit for firmware and product fleets than for a conventional SaaS company.

What buyers should verify before choosing Manifest

  • Coverage: Does it ingest CycloneDX and SPDX, supplier SBOMs, binaries, containers, firmware, models and datasets?
  • Identity: How are forks, vendored code, renamed packages, private components and conflicting metadata normalized?
  • Risk context: Does prioritization include reachability, runtime exposure, exploit status, business criticality and VEX statements—not just CVE matching?
  • Lifecycle: Can it track version history and SBOM drift, record exceptions and connect with Jira, ServiceNow or comparable systems?
  • Deployment: Can it distinguish development, staging and production across cloud, on-premises, edge and air-gapped environments?
  • Government controls: What hosting, data-residency, SSO, RBAC, logging, authorization and contractual security documentation are available?
  • AI scope: Does an AIBOM represent models, datasets, fine-tunes, prompts, libraries and inference services separately? Is deployment monitoring actually available in the purchased edition?
  • Economics: What are the subscription, onboarding, integration, data-cleanup and ongoing ownership costs?

Important limitations in the announcement

An SBOM can be stale or incomplete. It may omit dynamically loaded code, build tools, transitive dependencies, operating-system packages, embedded libraries, generated code or runtime components. A vulnerability match also does not automatically mean an application is exploitable. Supplier-provided inventories require provenance checks and version validation.

The available reporting leaves Manifest’s valuation, revenue, customer count, retention, pricing, independent accuracy results and deployment scale unknown. It also does not clarify whether the AI capabilities described on April 25, 2025 were generally available or still maturing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What happened after the financing

Manifest’s press archive lists announcements through March 2026, including a C/C++ SBOM generator, an AI-risk-transparency product, executive appointments and partnerships. Those later announcements provide follow-up context, but they should not be treated as products or capabilities that were necessarily available when the Series A was announced.

Rank #4
Thetis Pro FIDO2 Security Key Passkey with Complex Pin [PinPlex], Hardware Device Supports USB A, Type C &NFC, TOTP/HOTP Authenticator APP, PIV Certificates, FIDO 2.0 Two Factor Authentication 2FA MFA
  • Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
  • NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
  • FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
  • Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
  • Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.

Frequently Asked Questions

When did Manifest announce the funding?

Manifest announced its $15 million Series A on April 25, 2025.

Who led Manifest’s Series A?

Ensemble VC led the round. AE Ventures, First Round Capital, Homebrew, Leap435, Overmatch VC and XYZ also participated.

What is an SBOM management platform?

It maintains an inventory of software components and connects that data to vulnerability analysis, supplier information, deployments, remediation workflows and compliance evidence. Generating a single SBOM file is only one part of the lifecycle.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Did Manifest disclose a valuation or detailed use-of-funds plan?

The available announcement coverage reports neither a valuation nor a category-by-category allocation. It says the company intended to expand its market reach to Europe.

The Bottom Line

Manifest’s $15 million Series A is a significant 2025 financing for a company combining SBOM lifecycle management with AI supply-chain inventories. Its differentiation will depend less on producing another inventory file than on proving data quality, deployment context, workflow integration and mature AIBOM capabilities. Buyers should validate those points in a technical evaluation rather than infer them from the funding announcement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.