Black Kite
United States · owned by Independent (United States) · blackkite.com · 13 vendors
Black Kite is an AI-native third-party cyber risk management (TPCRM) platform that provides continuous cyber risk intelligence, standards-based assessments, and Open FAIR™-based financial impact quantification for vendor and supply chain risk. Founded in 2016 by certified ethical hacker Candan Bolukbas, the company helps security and business leaders identify, monitor, and manage cyber risks posed by third-party vendors and suppliers. Its platform covers vendor risk assessment, ransomware susceptibility indexing, nth-party visibility, and compliance monitoring.
Resilience scores
- Digital Sovereignty: 77
- Digital Resilience: 9
- Financial Resilience: 6
Disruption prediction
Black Kite has an estimated 17% probability of disruption in the next 6 months.
9 of Black Kite's 13 vendors monitored for disruptions.
Technology vendors
- Demandware — Technology — United States
- Netlify, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 10 more
Insights
Last updated 2026-07-22 · revision 4
13 direct vendors, 205 subvendors
Direct vendors by controlling owner country (sample)
- Singapore: 1
- Sweden: 1
- United States: 10
Subvendors by controlling owner country (sample)
- Spain: 1
- Romania: 1
- Norway: 5
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Black Kite exhibits high migration readiness, primarily driven by its highly modern and cloud-native internal tech stack. The extensive use of AWS, GCP, Azure, Docker, and Kubernetes, alongside technologies like Next.js and Vercel, indicates a distributed, containerized, and multi-cloud architecture that significantly streamlines potential migration efforts. The company's strong financial position, supported by $60M in Series C funding, provides ample resources to fund any necessary migration initiatives. A key challenge for migration will be navigating the robust regulatory environment, including GDPR compliance and NIS2 applicability, which necessitates careful planning for data residency and compliance throughout the migration process. However, Black Kite's existing certifications (SOC 2 Type II, ISO 27001) suggest a strong capability to manage such requirements. The ambiguity surrounding the total number of vendors ('Total Vendors: 0' contradicts other vendor data) makes it difficult to fully assess vendor lock-in risk, which could impact migration complexity. However, the geographic diversity of vendor HQs (Denmark, United States, Singapore) is a positive factor.
Compliance
7 in-scope frameworks identified; showing 3.
PIPEDA — Compliant
Black Kite explicitly addresses PIPEDA compliance in its Privacy Notice (Section 11.4), confirming it processes personal information of Canadian residents in accordance with PIPEDA and applicable provincial privacy laws. A designated privacy officer (Michael Sillanpaa, Director, GRC) is named. Risk is Low because the company has explicitly acknowledged PIPEDA obligations and designated a privacy officer as required.
Evidence: https://blackkite.com/privacy-policy
SOC 2 (source) — Compliant
Black Kite has explicitly confirmed SOC 2 Type 2 certification in its Privacy Notice (Section 12): 'SOC 2 Type 2 certification (available at https://trust.blackkite.com).' SOC 2 Type 2 is the most rigorous form of SOC 2 attestation, covering the operational effectiveness of security controls over a defined period (typically 6-12 months). As a cloud-based SaaS platform handling customer data, SOC 2 is directly applicable and the company has achieved certification. Risk is Low because: (1) certification is confirmed; (2) the report is available via the Trust Center; (3) annual third-party penetration testing is also conducted; (4) the company has a dedicated GRC function (Director of GRC: Michael Sillanpaa). The main residual risk is that SOC 2 reports require annual renewal and the current report's coverage period is not publicly specified.
Evidence: https://trust.blackkite.com, https://blackkite.com/privacy-policy
FedRAMP — Assessment Required
FedRAMP authorization is required for cloud service providers (CSPs) selling to US federal government agencies. Black Kite has a dedicated Public Sector/Federal vertical and a VP of Public Sector with extensive DoD/White House experience, strongly suggesting active federal government sales. If Black Kite's platform is sold to federal agencies as a cloud service, FedRAMP authorization would be required. Risk is Medium because: (1) federal sales are strongly implied by the company's organizational structure; (2) FedRAMP non-compliance could block federal contracts; (3) no FedRAMP authorization is publicly listed in the FedRAMP Marketplace. Missing information: confirmation of whether Black Kite has active federal agency contracts requiring FedRAMP.
Evidence: https://blackkite.com/industry/federal, https://blackkite.com/about
Financials
Three-year financials
- null:
- null:
- null:
Financial Resilience Score: 6/10
Black Kite is a privately held, venture-backed US cybersecurity SaaS company that does not disclose revenue, EBIT, or equity figures. Its financial resilience must therefore be assessed qualitatively. Positive indicators include institutional backing from investors such as Volition Capital (which reportedly led a ~USD 22M Series B in 2022) and Paladin Capital Group, a recurring SaaS revenue model, strong customer satisfaction (Gartner Peer Insights 4.8 across 162 reviews), a differentiated Open FAIR™-based methodology, and diversified vertical exposure across Manufacturing, Financial Services, Healthcare, Insurance, Retail, Technology, and Public Sector. Offsetting these strengths are several risks: complete lack of public financial transparency, a highly competitive TPCRM category with well-funded rivals (SecurityScorecard, Bitsight, UpGuard, SAFE Security, Panorays, Prevalent), dependence on continued external funding, compressed cybersecurity valuations since 2022, and the CFO's explicit 'liquidity event' objective signaling reliance on an M&A or IPO exit. Overall, the company appears to be in a growth/pre-exit phase typical of venture-backed private SaaS firms, warranting a moderate resilience score.
Key strengths: Venture backing from Volition Capital (Series B lead, ~USD 22M in 2022) and Paladin Capital Group, Recurring SaaS subscription revenue model with high visibility, Strong customer satisfaction: 4.8/5 Gartner Peer Insights rating across 162 reviews, Experienced leadership bench with 200+ years of combined cybersecurity experience, Defensible IP: Open FAIR™-based methodology and Ransomware Susceptibility Index® (RSI™), Diversified vertical exposure across seven industries, Multi-fold customer growth reported over three-year window
Risk factors: No public financial transparency; balance-sheet strength, burn rate, and profitability unknown, Highly competitive TPCRM category with well-funded rivals (SecurityScorecard, Bitsight, UpGuard, SAFE Security, Panorays, Prevalent), Dependence on continued VC/PE funding rounds, Cybersecurity valuations have compressed since 2022, Regulatory and methodology risk from cyber-rating pushback and evolving disclosure regimes (SEC, DORA), Concentration in enterprise TPRM buyers exposes the company to enterprise IT spending slowdowns, CFO's explicit 'liquidity event' objective indicates reliance on M&A or IPO exit assumptions
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.