Manifest Cyber Announces AI-Powered Exposure Analysis, Product-Level Risk Visibility, and Foreign Influence Detection
Manifest Cyber Announces AI-Powered Exposure Analysis, Product-Level Risk Visibility, and Foreign Influence Detection
WASHINGTON--(BUSINESS WIRE)--Manifest Cyber, the leading platform for software and AI supply chain security, today shipped three capabilities added to The Manifest Platform (Manifest Insights Agent (MIA), Foreign Risk, and Product Hierarchy) that give security teams contributor-level risk visibility, product-level exposure mapping, and seconds-fast blast radius analysis. The announcement comes ahead of Black Hat USA 2026.
Security teams have more software supply chain data today than at any point in the past decade. What they still lack is speed to an answer. Questions that decide an audit, a vendor review, or an active incident, who wrote this code, what product does it belong to, and are we exposed right now, still take hours or days to work out manually. The three capabilities announced today were each built to close one of those specific gaps.
- Manifest Insights Agent (MIA) is an AI-powered analyst built into the platform that takes any list of supply chain indicators, a component name, a version range, or a full advisory, and returns blast radius analysis against an organization's actual software inventory in seconds. MIA is available directly in the platform and as a Model Context Protocol (MCP) server for teams building exposure analysis into existing CI/CD pipelines and incident runbooks.
- Foreign Risk identifies open source contributors tied to sanctioned nations, foreign militaries, intelligence agencies, or state-controlled institutions, drawing on a database of 20 billion foreign risk records across 18 risk categories. The capability helps organizations demonstrate compliance with Department of War (DoW) Instruction 5205.87, which extends Foreign Ownership, Control, or Influence (FOCI) requirements to any company holding unclassified DoW contracts over $5 million.
- Product Hierarchy gives security teams a structured, drill-down view of risk from mission system to subsystem to individual component, with risk rolling up automatically at every layer. The latest release adds the ability to export a complete product hierarchy, including sub-products, assets, and vulnerability triage decisions, that re-imports on the receiving end without losing structure, identifiers, or disposition data.
The releases arrive as regulators move from component-level compliance toward product-level accountability. The FOCI mandate now applies to unclassified defense contracts, the Bureau of Industry and Security (BIS) Connected Vehicles rule prohibits vehicles with Chinese or Russian-linked software starting in Model Year 2027, and the FDA and Department of Defense increasingly expect evidence at the product and system level, not a flat list of components.
Daniel Bardenstein, CEO, Manifest, said: "Security teams have gotten good at finding risk. They still spend hours turning that into an answer they can act on. That gap is the transparency tax, and it shows up every time an advisory drops, a regulator asks a new question, or a vendor questionnaire lands on someone's desk. These three releases close that gap at three different moments: before code ships, once it is part of a shipped product, and the second an incident breaks. That is the platform security teams actually need walking into Black Hat this year."
Manifest will host one-on-one briefings in its cabana at Black Hat USA 2026 in Las Vegas rather than a traditional show floor booth. Security teams attending the conference can schedule time with the Manifest team to see Foreign Risk, Product Hierarchy, and MIA in action against their own software inventory.
About Manifest
Manifest Cyber is the leading platform securing the entire AI and software supply chain, from source code to models to third-party software. We empower product security and third-party risk teams to operate critical systems and applications with confidence by detecting and managing hidden software supply chain and AI risks at scale. The Manifest Platform provides end-to-end visibility and control across Product Security, AI Risk, and Supplier Risk, helping teams build secure, trusted software without losing velocity. Organizations across defense, healthcare, automotive, and other regulated industries trust us to strengthen product and AI security, reduce third-party risk, and support compliance. Learn more at www.manifestcyber.com.
Contacts
Media Contact for Manifest: marketing@manifestcyber.com
