Kiteworks
United States · www.kiteworks.com · 30 vendors
Kiteworks provides a Private Data Network platform that unifies, tracks, controls, and secures sensitive data exchanges across channels such as email, file sharing, and APIs. The company helps organizations manage risk, ensure regulatory compliance, and prevent data breaches.
Resilience scores
- Digital Sovereignty: 77
- Digital Resilience: 8
- Financial Resilience: 7
Disruption prediction
Kiteworks has an estimated 11% probability of disruption in the next 6 months.
18 of Kiteworks's 30 vendors monitored for disruptions.
Technology vendors
- HubSpot, Inc. — Technology — United States
- NetSuite — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 28 more
Services catalogue
2 services in catalogue across 1 category; runs on 30 sub-vendors.
- File sharing / Managed file transfer services
- Platform / Accellion DNS
Insights
Last updated 2026-08-01 · revision 2
30 direct vendors, 276 subvendors
Direct vendors by controlling owner country (sample)
- United States: 23
- Australia: 1
- France: 1
Subvendors by controlling owner country (sample)
- Italy: 1
- Australia: 3
- Norway: 4
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Kiteworks exhibits high migration readiness, primarily driven by its architectural flexibility and modern integration capabilities. The 'Sovereign Access Suite' explicitly supports diverse deployment models including on-premises, private cloud, and hybrid, indicating that their solutions are designed for portability across different environments. The internal tech stack includes AWS, and uses modern protocols and APIs such as SAML 2.0, OAuth 2.0, SCIM for user provisioning, and a comprehensive REST API/SDK suite, which are crucial for seamless integration and automation during migration. Apache Airflow for MFT workflows is also a cloud-friendly technology. However, the core 'Private Data Network (PDN)' is described as a 'single-tenant-by-design virtual appliance' utilizing VMware infrastructure, which suggests a VM-centric rather than a fully cloud-native, containerized, or microservices-based architecture. This could introduce some complexity or require refactoring if migrating to a purely serverless or container-orchestrated cloud environment. Significant unknowns include 'Data Residency Requirements', which are not specified and can heavily influence migration strategy and compliance. The 'Vendor Lock-in Risk' is also unknown, and while 'Total Vendors: 0' is contradictory, the existence of 37 services implies potential dependencies that could impact migration. The lack of specific regulatory environment details beyond FedRAMP also limits a comprehensive assessment of compliance-related migration challenges.
Compliance
15 in-scope frameworks identified; showing 3.
FedRAMP — Compliant
Kiteworks prominently advertises FedRAMP Authorization on its homepage and compliance pages. FedRAMP (Federal Risk and Authorization Management Program) is one of the most rigorous cloud security authorization programs, requiring extensive third-party assessment by an accredited 3PAO (Third-Party Assessment Organization) and ongoing continuous monitoring. Risk is Low because: (1) FedRAMP authorization is independently verified by a 3PAO and approved by a federal agency ATO; (2) FedRAMP requirements exceed most other compliance frameworks including HIPAA and SOC 2; (3) the authorization is listed on the official FedRAMP marketplace. This is one of Kiteworks' strongest compliance credentials.
Evidence: https://www.kiteworks.com/platform/compliance/fedramp-authorization/, https://www.kiteworks.com/
CMMC 2.0 — Compliant
Kiteworks explicitly markets CMMC (Cybersecurity Maturity Model Certification) compliance as a core capability and serves the US Defense Industrial Base (DIB). CMMC 2.0 is based on NIST SP 800-171 controls. Risk is Low because Kiteworks has dedicated CMMC compliance infrastructure, FedRAMP authorization (which exceeds CMMC requirements), and FIPS 140-3 validated encryption — all prerequisites for CMMC compliance.
Evidence: https://www.kiteworks.com/platform/compliance/cmmc-compliance/, https://www.kiteworks.com/cmmc-preparedness-dib-report/
BSI C5 — Assessment Required
BSI C5 (Cloud Computing Compliance Criteria Catalogue) is a German Federal Office for Information Security standard for cloud services. Kiteworks explicitly lists BSI C5 as a supported compliance framework and has a German-language website, indicating active German market operations. Risk is Medium because: (1) BSI C5 attestation is required for cloud services used by German federal agencies; (2) German enterprise customers increasingly require BSI C5 compliance from cloud vendors; (3) BSI C5 requires independent third-party attestation. No publicly available BSI C5 attestation report was found.
Evidence: https://www.kiteworks.com/platform/compliance/bsi-c5/, https://www.kiteworks.com/de/
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Kiteworks is a well-funded private cybersecurity company backed by top-tier private equity investors including Insight Partners, Sixth Street Growth, and Baring Private Equity Asia. The most concrete public financial signal is the August 2024 $456M minority growth investment at a valuation exceeding $1B, providing substantial cash runway and de-risking near-term liquidity. The company benefits from a sticky enterprise and government customer base of 3,800+ customers, with FedRAMP, FIPS 140-3, and IRAP certifications creating high switching costs and long-term subscription-style revenue streams. Regulatory tailwinds such as CMMC 2.0 in the US defense industrial base, EU NIS2/DORA, and rising AI data-governance requirements expand its addressable market. The broad product footprint spanning MFT, secure file sharing, secure email, DRM, forms, and AI-agent governance reduces single-product concentration risk. However, financial opacity is a significant concern—no public financials mean external assessment of margins, burn, leverage, and cash generation is not possible. Additionally, the reputational legacy from the 2020-2021 Accellion FTA breach, competitive intensity from Progress Software, Fortra, Box, Egnyte, Microsoft, and Proofpoint, and PE ownership dynamics requiring an eventual exit path all present risks.
Key strengths: $456M growth investment in August 2024 at >$1B valuation, Top-tier PE backing (Insight Partners, Sixth Street Growth, Baring PE Asia), 3,800+ enterprise customers with high switching costs, FedRAMP Authorized, FIPS 140-3 validated, IRAP compliant certifications, Regulatory tailwinds from CMMC 2.0, NIS2, DORA, and AI governance, Broad unified platform spanning MFT, file sharing, email, DRM, and AI governance, Strategic tuck-in acquisitions (Totemo 2022, Maytech 2023, 123Formbuilder 2024)
Risk factors: No public financial disclosures; opacity on margins, burn, and leverage, Reputational legacy from 2020-2021 Accellion FTA breach, Intense competition from Progress Software (MOVEit), Fortra (GoAnywhere), Box, Egnyte, Microsoft Purview, and Proofpoint, PE ownership dynamics requiring eventual exit (IPO, strategic sale, or secondary), Potential shift toward margin/EBITDA optimization ahead of transaction, Private-credit or PE-loaded balance sheets may carry meaningful leverage
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.