Exiger
Exiger's supply-chain risk platform has real scale, but the public file still under-explains the economics behind its unicorn valuation.
Exiger has credible scale, strong federal-grade differentiation, and a plausible AI-led supply-chain workflow moat, but opaque financial disclosure and concentration risks keep the reported unicorn valuation from being fully underwritten.
Cover facts
Company profile
Exiger is a McLean, Virginia-based private software and workflow company that began in compliance and due-diligence work, then expanded into AI-led supply-chain visibility, procurement intelligence, and software-supply-chain risk management. Its current product narrative centers on 1ExigerAI, multi-tier supplier and part intelligence, and regulated enterprise/government deployments, with meaningful traction in federal, defense-industrial, financial-services, and large-enterprise accounts.
- Website
- www.exiger.com
- Founded
- 2013-01-01
- Founders
- Michael Cherkasky, Michael Beber, Brandon Daniels
- Headquarters
- McLean, Virginia, USA
- Product
- AI-powered platform for supplier and part intelligence, due diligence, sanctions and trade-compliance workflows, third-party risk management, and software-supply-chain security.
- Customers
- Government agencies, defense industrial base participants, Fortune 500 procurement teams, compliance teams, and regulated financial institutions.
- Business model
- Enterprise software and workflow subscriptions sold through direct sales, channel partners, and public-sector procurement vehicles.
- Stage
- Late-stage private / sponsor-backed unicorn
- Funding status
- 2018 $80M minority growth investment followed by a 2023 Carlyle/Insight majority investment at a third-party-reported roughly $1.2B valuation, plus 2024 acquisitions of Versed AI and XSB.
Executive summary
Top strengths
- Federal, defense-industrial, and enterprise customer footprint with workflow-embedded deployments
- Differentiated combination of supply-chain mapping, compliance intelligence, and AI decision support
- Sponsor-backed platform with acquisition-led data expansion and strong procurement visibility
Top risks
- Government and regulated-industry concentration can elongate sales cycles and amplify budget shocks
- Public data does not disclose current ARR, margins, burn, or post-2023 ownership economics
- AI/data-quality errors or acquisition-integration missteps could quickly compress trust and valuation support
Open gaps
- Current ARR, revenue growth, gross margin, NRR, and burn remain undisclosed in public sources
- Current board composition, sponsor control rights, and the primary-versus-secondary mix of the 2023 deal are not public
- Customer retention, segment revenue mix, and exact exposure to government budget concentration remain opaque
Contents
01Company Overview
1.1 Identity, Roots, and Platform Shift
Exiger’s company-overview story is strongest when read as a progression, not as a clean-sheet AI startup. Older official releases and partner case studies show a company built around regulatory, financial-crime, and due-diligence workflows for banks, corporations, and government agencies. DDIQ, Insight 3PM, and adjacent risk products created the data-ingestion, entity-resolution, and analyst-guided operating muscle that later made a supply-chain pivot believable. By September 2023, management had consolidated the public narrative around 1Exiger, and by 2026 the current website framed the business even more explicitly as an AI-native operating system for supply-chain execution, procurement acceleration, and compliance automation. That repositioning does not erase the company’s roots; it repackages them. The supportable through-line is that Exiger used compliance-grade information handling and risk judgment as the foundation for a broader platform that now promises multi-tier visibility, decision support, and workflow orchestration across supplier, product, and part data. The result is a business that still carries regtech DNA, but whose present-day go-to-market language is centered on supply-chain AI.[CO001, CO005, CO006, CO007, CO008, CO009]
Exiger’s current thesis links compliance roots, proprietary data, acquisitions, customers, and capital into one supply-chain AI operating platform.
[CO005, CO006, CO007, CO020, CO021, CO023]1.2 Leadership, Founder Attribution, and Governance
Leadership is clearer than founder attribution, and that distinction matters. Current public materials plainly identify Brandon Daniels as CEO and the main public voice for Exiger’s AI, defense, and growth agenda. But reviewed sources do not support the idea that Daniels co-founded the business in 2013. Instead, the strongest official record shows Michael Cherkasky and Michael Beber as founders, with Daniels joining in 2017 and taking the CEO role in 2022. That transition is important because it explains why current brand messaging can feel founder-light even though founder influence still appears to matter. Publicly visible operators such as Carrie Wibben, Cameron Holt, and Eli Cherkasky show that Exiger now runs with a more mature bench across product integration, federal delivery, and operations. What remains conspicuously thin is the current post-2023 governance file: public materials do not provide a full board roster, voting-right summary, or detailed control map after Carlyle and Insight’s majority investment. For diligence purposes, management quality looks strong, but the control structure behind that management team is still only partially visible.[CO002, CO003, CO004, CO010, CO011, CO015]
| Person | Role | Background / context | Functional coverage | Key-person dependency |
|---|---|---|---|---|
| Michael Cherkasky | Co-founder; former CEO; continuing influence | Named as co-founder in older official releases and remained CEO through the 2022 transition. | Founder vision, government/regulatory credibility, governance continuity | Medium |
| Michael Beber | Co-founder; board chair in 2022 release | Named as co-founder in official financing and CEO-transition disclosures. | Founder continuity, board oversight, investor/stakeholder bridge | Medium |
| Brandon Daniels | CEO | Joined Exiger in 2017 and became CEO in 2022 after leading product and growth expansion. | AI platform strategy, go-to-market, federal and enterprise narrative | High |
| Carrie Wibben | President | Quoted in the XSB acquisition release as the executive articulating customer demand and platform integration logic. | Commercial execution, product packaging, acquisition integration | Medium |
| Cameron Holt | President of Government Solutions | Former government contracting executive and public-sector voice for Exiger’s SaaS SCRM strategy. | Federal market execution, software supply-chain security, defense adoption | Medium |
| Eli Cherkasky | COO | Interviewed about operating transformation, profitability, and investment back into people and product. | Operations, cost discipline, scaling systems and talent | Medium |
Founder attribution is drawn from older official releases, while the current leadership bench is compiled from recent public profiles and interviews rather than a single full org chart.
[CO002, CO003, CO010, CO011, CO037]1.3 Capital Base, Scale Signals, and Customer Proof
Exiger’s capital and scale story is credible, but it is not equally transparent on every point. Public disclosures confirm an $80 million Carrick growth investment in 2018 and a Carlyle/Insight majority investment in December 2023. Independent coverage later described the latter transaction at roughly a $1.2 billion valuation, which is directionally consistent with Exiger’s current “unicorn” framing even though the company itself did not publicly spell out the exact valuation or investment amount. Customer traction is more supportable than economic detail. Current official materials repeatedly cite roughly 550-plus customers, 150 Fortune 500 relationships, and 60-plus government or Defense Industrial Base organizations. Named proof is also available: Oshkosh appears in supply-chain case work, SMBC is a documented bank customer for DDIQ, and the U.S. Army provides marquee federal validation. Scale metrics still require caution. Employee count lands in an 850-to-1000 range across official and independent sources, while a Forbes interview supplied a greater-than-$150 million revenue estimate for 2024 but not ARR. That means scale is real, but the economic precision still falls short of what a full underwriting process should demand.[CO012, CO013, CO014, CO016, CO017, CO018]
| Metric | Value / status | Date | Confidence | Gap / caveat |
|---|---|---|---|---|
| Founded | 2013 | 2013 | High | Founder attribution is clear in older official materials, but Daniels is not documented there as a co-founder. |
| Headquarters | McLean, Virginia | 2026 | Medium | Official press datelines and Wash100 support McLean, while some third-party metadata uses broader or conflicting labels. |
| Current CEO | Brandon Daniels (CEO since May 2022) | 2022-05 | High | Public sources support CEO status but not co-founder status. |
| Business roots | Regulatory / financial crime / due diligence compliance software and services | 2018-2020 | High | Current branding now deemphasizes legacy product names in favor of platform messaging. |
| Current platform | 1ExigerAI / 1Exiger with supply chain, due diligence, and risk-compliance workflows | 2023-2026 | High | Legacy brands such as ORCA and WorldCompliance are not clearly surfaced in reviewed current materials. |
| 2023 ownership event | Majority investment from Carlyle and Insight; valuation about $1.2B reported independently | 2023-12-19 | Medium | Official sources confirm the transaction but not the exact valuation or economics. |
| Customer footprint | 550+ customers; 150 Fortune 500; 60+ government / DIB organizations | 2025-2026 | Medium | Company-reported rather than audited. |
| Employee scale | Estimated 850-1000 employees | 2024-2026 | Medium | Public signals range from >850 to nearly 1,000, while Gartner buckets the company at 501-1000. |
| ARR / revenue disclosure | ARR not public; Forbes reported >$150M 2024 revenue expectation | 2024 | Low | Revenue estimate is interview-based and should not be treated as ARR. |
Snapshot rows combine official disclosures and independent coverage; current scale and valuation are directionally strong but still partly company-reported or estimate-based.
[CO001, CO003, CO004, CO005, CO007, CO014]| Stakeholder | Role | Control or economic importance | Public evidence | Diligence ask |
|---|---|---|---|---|
| Carlyle | Lead majority investor (2023) | Likely core control and governance influence after the 2023 majority investment. | Official Exiger and Carlyle announcements confirm majority investment. | Obtain board rights, ownership percentage, and transaction structure. |
| Insight Partners | Co-investor in 2023 majority deal | Software-growth investor backing the next scale phase and listed current portfolio owner. | Official Exiger and Carlyle releases plus Insight portfolio page. | Clarify ownership level, governance rights, and follow-on strategy. |
| Carrick Capital Partners | 2018 minority growth investor; reinvested in 2023 | Earliest disclosed outside capital in reviewed sources and a bridge from regtech roots to current platform. | 2018 Carrick investment release and 2023 reinvestment mention. | Confirm remaining ownership and any ongoing board rights. |
| Founders and management | Reinvesting insider group | Signals ongoing insider economic alignment despite the majority transaction. | 2023 investor releases mention management and founders reinvesting equity. | Map insider ownership, vesting, and any super-voting or consent rights. |
| U.S. Army / Army Materiel Command | Strategic government anchor customer | Mission-critical adopter that validates defense sustainment use cases and can influence federal credibility. | Official Army contract announcement and syndication. | Measure contract size, renewal path, and concentration risk. |
| SMBC | Named financial-institution customer | Demonstrates that legacy due-diligence and AML products still land major-bank workflows. | 2019 DDIQ customer announcement. | Test whether named financial-institution wins still convert into platform expansion. |
This map mixes investors with economically important stakeholders because public ownership data is thin while customer concentration and federal adoption are material to diligence.
[CO012, CO013, CO015, CO025, CO028, CO032]Current public KPIs show real scale and government traction, but some economics and exact scale points remain estimate-based.
Valuation and headcount are triangulated from independent coverage and review metadata, while customer and government counts are still company-reported; the revenue figure is not ARR.
[CO014, CO016, CO018, CO019, CO025, CO035]1.4 Milestones, Acquisitions, and Risk Signals
The milestone sequence is one of the clearest ways to understand Exiger’s current identity. After building its early compliance and diligence footprint, the company spent 2022 through 2024 stitching together a broader operating stack: Daniels’ CEO elevation in 2022, the 1Exiger launch in 2023, and the Versed AI and XSB acquisitions in 2024 all pushed the business toward deeper product-aware supply-chain intelligence. The 2025 Army award and 2026 Platform One marketplace status then reinforced that Exiger had crossed from compliance-adjacent tooling into mission-grade government supply-chain infrastructure. Those are real positives, but this chapter should not treat the public file as spotless. The most visible negative signal in the reviewed set is a 2026 Gartner Peer Insights review that praised visibility yet criticized workflow tuning, which implies implementation complexity at least some users feel. More importantly, the public file still leaves unresolved questions around ARR, board structure, exact 2023 economics, and whether legacy brands such as ORCA and WorldCompliance remain active products or are simply absorbed into broader platform messaging. That is not thesis-breaking opacity, but it is enough to keep diligence pressure on product clarity and governance.[CO023, CO024, CO025, CO026, CO027, CO036]
| Date | Event | Type | Amount / valuation / status | Participants | Implication |
|---|---|---|---|---|---|
| 2013 | Exiger founded | founding | Company formation | Michael Cherkasky; Michael Beber | Establishes the original compliance and risk-management mission. |
| 2018-07-09 | Carrick invests in Exiger | financing | $80M minority growth capital | Carrick Capital Partners; Exiger founders and management | Scaled DDIQ and other compliance technology before the current supply-chain platform push. |
| 2019-08-20 | SMBC selects DDIQ | partnership | Named AML / KYC deployment | SMBC; Exiger | Shows real bank-customer adoption of the due-diligence product line. |
| 2022-04-19 | Brandon Daniels named CEO | governance | Leadership transition effective May 2022 | Brandon Daniels; Michael Cherkasky; Michael Beber | Marks the operating shift toward the current AI and supply-chain growth phase. |
| 2023-09-19 | 1Exiger launched | product | Unified platform / UX release | Exiger | Centralized DDIQ, Insight 3PM, Ion Channel, SDX, and Supply Chain Explorer. |
| 2023-12-19 | Carlyle and Insight majority investment announced | financing | Majority investment; ~$1.2B valuation reported independently | Carlyle; Insight Partners; Exiger; Carrick | Rebases Exiger from growth software company to unicorn-scale platform story. |
| 2024-07-08 | Versed AI acquired | product | Acquisition | Exiger; Versed AI | Added automated bill-of-material mapping and AI-driven multi-tier visibility. |
| 2024-08-07 | XSB acquired | product | Acquisition | Exiger; XSB | Added parts, logistics, sustainment, and engineering intelligence for government-heavy use cases. |
| 2025-11-14 | U.S. Army licenses 1Exiger | scale | Multi-million-dollar contract | U.S. Army AMC; Exiger Government Solutions | Provides marquee defense validation and deeper government entrenchment. |
| 2026-04 | Platform One Solutions Marketplace awardable status | regulatory | Awardable procurement channel | Exiger Cyber; Department of Defense ecosystem | Shortens a path for defense buyers to procure Exiger cyber and software-supply-chain capabilities. |
| 2026-05-30 | Critical Gartner review flags workflow-tuning challenge | adverse | Critical product-feedback signal | Gartner Peer Insights reviewer | Reminds investors that implementation friction can coexist with strong visibility claims. |
The chronology tracks Exiger’s move from compliance roots to integrated supply-chain AI and flags the one public adverse signal surfaced in this review set; several rows rely on company-issued announcements, so economics remain partially opaque.
[CO001, CO012, CO013, CO023, CO024, CO025]Key public milestones show Exiger evolving from compliance-regtech roots into a unicorn-valued supply-chain AI platform with deeper federal penetration.
[CO001, CO012, CO013, CO023, CO024, CO025]1.5 Exhibits
02Market Analysis
2.1 Market boundary and included spend
The cleanest way to define Exiger’s market is not “all compliance software” or “all supply chain software,” but the narrower set of workflows where an organization must know who a supplier, counterparty, product, part, component, or software dependency really is; what legal or operational risk it creates; and what action should follow. Exiger’s own platform positioning is unusually broad across that problem set: it joins supplier, product, part, component, and risk data; explicitly spans both physical and software supply chains; and sells risk-and-compliance modules for trade compliance, supplier risk management, enhanced due diligence, third-party risk management, and know-your-customer work. That means the included spend starts with third-party and supplier diligence, sanctions and trade screening, multi-tier supply-chain mapping, and software provenance or SBOM-informed visibility. It does not extend to generic ERP, payments processing, standalone cybersecurity point tools, or logistics execution software when those tools are not resolving supplier, ownership, provenance, or compliance risk. The serviceable wedge is therefore the overlap between regulated compliance work and high-stakes procurement visibility, not every dollar touching procurement or risk.[CM001, CM002, CM004, CM005, CM007, CM008]
| Segment / category | Included spend | Excluded spend | Buyer / payer | Relevance |
|---|---|---|---|---|
| Third-party risk intelligence and due diligence | Vendor onboarding, due diligence, continuous monitoring, adverse media, ownership and relationship checks | Generic GRC modules with no third-party data or monitoring depth | Compliance, legal, risk, internal audit | Core Exiger wedge through TPRM, EDD, and supplier risk |
| Trade compliance, sanctions, and KYC screening | Sanctions screening, export-control and debarment checks, KYC/KYB, transaction and counterparty screening | Payments processing, core banking, or transaction systems that do not provide compliance intelligence | Compliance, financial-crime, legal, trade-compliance teams | Important because Exiger explicitly packages screening and network analysis for regulated buyers |
| Physical supply-chain risk management | Multi-tier supplier mapping, part and component provenance, disruption alerts, alternative sourcing, supplier resilience analysis | Pure logistics execution, warehouse management, freight marketplaces | Procurement, supply chain, operations, supplier quality | Important because Exiger sells part-level and supplier-level visibility rather than only entity scoring |
| Defense-industrial supply-chain visibility | Adversarial supplier exposure, FOCI-related diligence, cyber and provenance checks for defense suppliers and components | General defense IT modernization spend with no supplier or provenance lens | Defense acquisition, program, cyber, industrial-base leaders | Strategic wedge because regulations and national-security policy make visibility mission-critical |
| Software supply-chain security | SBOM analysis, provenance, open-source and firmware dependency visibility, software supplier assurance | Standalone application-security testing with no upstream component or supplier visibility | Cybersecurity, engineering, platform security | Included because Exiger markets software-supply-chain security as part of the same visibility problem |
| Excluded adjacencies and status quo substitutes | N/A | ERP, payments, generic cybersecurity tools, logistics execution, manual spreadsheets, and one-time consultative reviews with no monitoring layer | Existing internal operations or incumbent point vendors | These are substitutes or neighboring budgets, not additive TAM unless they overlap with Exiger’s risk workflow |
Boundary is intentionally workflow-based rather than category-label based. Spend is included only when it resolves supplier, counterparty, provenance, or compliance risk inside an auditable operating workflow.
[CM001, CM002, CM005, CM007, CM008, CM010]2.2 Buyers, workflows, and budget owners
Exiger’s buyer map is broader than a classic bank-compliance story, but the spending logic is still concentrated in teams that own procurement, compliance, legal exposure, supply continuity, and mission assurance. In financial institutions, the relevant buyers are compliance, financial-crime, legal, and risk teams that need KYC, sanctions screening, investigations, and third-party controls in one auditable workflow. In large industrials and critical-infrastructure companies, the economic buyer shifts toward procurement, supply-chain risk, supplier-quality, and trade-compliance leaders who need visibility below tier-one suppliers and across parts, materials, and jurisdictions. In defense, acquisition, program, cyber, and industrial-base teams are buying against contract eligibility, adversarial supplier exposure, and provenance risk rather than only against generic efficiency goals. The adoption path is therefore workflow-led: onboarding and screening first, then continuous monitoring, then remediation, re-sourcing, and resilience management. This multi-function ownership matters for valuation because it makes Exiger’s revenue opportunity depend on whether risk tools can embed into operational decision-making, not just whether a compliance department budgets for another watchlist feed.[CM003, CM006, CM007, CM041, CM042, CM043]
| Segment | Buyer | User | Payer | Workflow | Budget owner | Adoption trigger |
|---|---|---|---|---|---|---|
| Financial institutions | Chief compliance officer, financial-crime lead, legal or enterprise-risk leader | KYC/EDD analysts, investigations teams, sanctions ops, supplier-risk analysts | Bank or financial institution | KYC/KYB onboarding, sanctions screening, transaction monitoring, third-party diligence | Compliance and risk budget, sometimes legal co-sponsor | Regulatory change, sanctions volatility, cyber risk, need for auditable monitoring |
| Large industrials and manufacturers | Chief procurement officer, supply-chain resilience leader, trade-compliance leader | Procurement, supplier quality, logistics, legal, ESG or forced-labor teams | Industrial enterprise | Multi-tier supplier mapping, UFLPA and export-control checks, alternative sourcing | Procurement or operations budget with compliance support | Geopolitical disruption, cost and lead-time shocks, forced-labor exposure |
| Defense primes and lower-tier suppliers | Program executive, chief information security officer, contracts/compliance leader | Procurement, engineering, cyber, program-management, industrial-security teams | Program office or defense contractor | CMMC readiness, supplier provenance, FOCI and adversarial-supplier de-risking, secure sourcing | Program, cyber, and compliance budgets | Contract eligibility, mission assurance, ownership-disclosure requirements |
| Federal agencies | Acquisition lead, mission owner, CIO, inspector-general or program-integrity team | Acquisition staff, investigators, logistics and mission-support teams | Agency or program | Supplier vetting, mission supply assurance, trade and human-rights compliance | Mission or acquisition budget | Policy mandates, resilience programs, accountability requirements |
| Critical infrastructure and healthcare operators | Chief supply-chain officer, compliance leader, operational-resilience leader | Supplier-risk analysts, OT/cyber teams, sourcing managers | Enterprise operator | Supplier continuity, cyber-linked product assurance, substitute sourcing | Operations and resilience budget | Need to secure critical systems and avoid single-point failures |
| Multinational legal and compliance teams | General counsel, chief ethics and compliance officer | EDD analysts, ABAC teams, external-investigations staff | Corporate center | Third-party onboarding, anti-bribery diligence, sanctions and debarment checks | Legal and compliance budget | Expanded regulatory perimeter and board-level accountability for third parties |
The buyer map is organized around who pays for risk outcomes, not who merely consumes a dashboard. In Exiger’s market, operational buyers and compliance buyers usually have to buy together.
[CM003, CM006, CM007, CM041, CM042, CM043]Exiger’s buyer map is multi-functional: distinct verticals route different pain points into one visibility-and-compliance operating layer.
This is a workflow-ownership map rather than a revenue-share chart. It emphasizes why Exiger is bought by mixed buying centers, not one isolated risk function.
[CM041, CM042, CM043, CM044, CM052]2.3 Sizing lenses and contradictory estimates
The public evidence supports a real and growing market around Exiger’s workflows, but not a clean single-number TAM. The third-party risk management category alone ranges from about $8.09 billion to $9.34 billion in retained 2026 estimates, while a broader Grand View lens emphasizes North American concentration and long-run growth rather than a directly comparable 2026 point. Supply-chain risk management is even more dispersed: retained 2026 values run from $3.73 billion to $6.91 billion depending on whether the publisher emphasizes core software-and-services spend or a wider solution perimeter. Sanctions screening is the clearest warning against false precision, because the retained 2026 market can be as small as roughly $587 million for software-only screening or as large as $4.2 billion for broader screening solutions. Those numbers are useful only if they stay separate. They should not be summed into a single Exiger TAM because categories overlap in buyer, workflow, and product scope. The most defensible conclusion is that Exiger sits at the intersection of several mid-sized and fast-growing categories, with the defense-industrial visibility wedge especially important strategically but not cleanly isolated in public market-size data.[CM011, CM012, CM013, CM015, CM016, CM017]
| Publisher | Year | Geography | Value | CAGR / growth | Methodology / lens | Confidence | Limitation |
|---|---|---|---|---|---|---|---|
| Research and Markets | 2026 | Global | 8.09 | 17.6% to 2030 | Third-party risk management market value | medium | Broad TPRM category, not Exiger-specific overlap-adjusted SAM |
| Polaris Market Research | 2026 | Global | 9.34 | 15.59% to 2034 | Third-party risk management market value | medium | Broad TPRM definition with multiple verticals and deployment models |
| Grand View Research | 2023 to 2030 | Global | 7.42 in 2023 to 20.59 in 2030 | 15.7% from 2024 to 2030 | TPRM growth and regional-concentration lens | medium | Useful for trend and North America share, not a direct 2026 point estimate |
| The Business Research Company | 2026 | Global | 3.73 | 8.0% to 2035 | Supply chain risk management market value | medium | Lower estimate focused on core SCRM market |
| Fortune Business Insights | 2026 | Global | 5.85 | 14.21% to 2034 | Supply chain risk management market value | medium | Broader solution perimeter than the lowest retained estimate |
| Coherent Market Insights | 2026 | Global | 6.9126 | 11.6% to 2033 | Supply chain risk management market value | medium | Highest retained SCRM estimate; category scope appears broader |
| Industry Research | 2026 | Global | 0.58671 | 9.9% to 2035 | Sanctions screening software market value | low | Software-only lens likely excludes broader compliance workflow spend |
| GII / Stratistics MRC | 2026 | Global | 4.2 | 14.9% to 2034 | Sanctions screening solutions market value | medium | Broader solution lens includes more than software-only screening |
| Official DIB policy sources | 2024 to 2026 | U.S. defense industrial base | N/A | Strategic-demand lens only | low | No retained public source isolates a standalone defense-supply-chain-visibility TAM or SOM |
The sizing evidence is intentionally multi-lens and non-additive. Public categories overlap in buyer and workflow, so contradictory estimates are preserved instead of blended into a synthetic Exiger TAM.
[CM011, CM012, CM013, CM015, CM016, CM017]Exiger’s monetizable wedge narrows from several adjacent risk categories into a regulated visibility layer where supplier, compliance, and national-security workflows overlap.
This figure is qualitative by design. Retained public sources do not provide a clean, non-overlapping TAM/SAM/SOM stack for Exiger, so the layers represent narrowing serviceability rather than additive dollar buckets.
[CM001, CM008, CM031, CM032, CM045, CM046]Supply-chain risk management is the only retained adjacent category with three directly comparable 2026 estimates, making it the best public range visualization for Exiger’s market context.
The figure visualizes only the SCRM range because it has three directly retained 2026 values in one unit. TPRM and sanctions estimates remain in the table because their retained public lenses are less directly comparable.
[CM015, CM016, CM017, CM018]2.4 Regulatory drivers, constraints, and diligence gaps
Exiger’s market is being pulled forward by hard regulation, industrial policy, and the availability of AI-based automation. In defense, CMMC and DFARS contract clauses turn cybersecurity assurance into a contract-gating requirement, while the DoD’s industrial strategy and proposed ownership-disclosure expansion deepen demand for sub-tier visibility. In trade and human-rights compliance, UFLPA enforcement has become more transaction-specific and data-intensive, and OFAC plus BIS rules keep sanctions and export-control screening continuously current rather than episodic. EO 14017 and CHIPS-related policy extend the logic beyond compliance into national-security resilience and upstream component traceability. The constraints are just as real. Buyers still face integration and data-quality burdens, false-positive review load, slow budget cycles, and incumbent workflows that are hard to replace. Defense use cases add sensitive-data and auditability constraints that limit simple plug-and-play deployment assumptions. The practical takeaway is that Exiger’s market has strong external drivers, but monetization depends on whether customers can operationalize the data with acceptable implementation effort and enough precision to avoid drowning analysts in noise.[CM009, CM022, CM023, CM024, CM025, CM026]
| Driver / constraint | Direction | Timing | Implication | Diligence ask |
|---|---|---|---|---|
| CMMC Phase 1 and DFARS contract clauses | Driver | Current / multi-year | Turns cybersecurity assurance into a contract-gating requirement for DIB participants and their suppliers | Ask management what share of pipeline is directly tied to CMMC or DFARS-driven demand |
| UFLPA enforcement and dashboard granularity | Driver | Current | Raises the value of item-level provenance, country-of-origin detail, and supplier traceability in import-heavy sectors | Request customer examples where CBP detention risk changed product demand or budget size |
| OFAC and BIS screening volatility | Driver | Current / structural | Pushes buyers from one-time onboarding checks toward continuous sanctions and export-control monitoring | Ask how often Exiger customers rerun screening and how remediation workflows are staffed |
| EO 14017, CHIPS, and national-security industrial policy | Driver | Structural | Legitimizes resilience, redundancy, and upstream component visibility as budget-worthy capabilities | Ask how much demand is traceable to resilience or reshoring programs versus pure compliance |
| NDIS priorities and FOCI-disclosure expansion | Driver | Current / near-term | Strengthens the defense-visibility wedge by requiring deeper supplier and ownership transparency | Request evidence of federal and prime-contractor adoption tied to ownership or sub-tier disclosures |
| AI-native automation and knowledge-graph workflows | Driver | Current / structural | Supports larger analyst throughput and faster remediation if accuracy is good enough | Ask for false-positive rates, analyst productivity lift, and time-to-remediation metrics |
| Integration and data-quality burden | Constraint | Current / structural | Value depends on normalizing supplier, party, and part data across messy internal systems | Request implementation timelines, customer data-prep effort, and system-integration dependencies |
| False positives and noisy screening outputs | Constraint | Current / structural | Manual review load can overwhelm compliance teams and reduce ROI even when coverage is broad | Request alert volumes, precision metrics, and tuning processes by workflow |
| Budget cycles and incumbent workflows | Constraint | Current / structural | Procurement, compliance, and defense buyers often buy only after a trigger and can move slowly across functions | Request sales-cycle length by vertical and replacement versus greenfield mix |
| Sensitive or classified defense data constraints | Constraint | Current / structural | Some deployment environments require auditable and carefully controlled data handling rather than simple SaaS rollout assumptions | Request architecture patterns, cleared-environment references, and evidence-handling controls |
The strongest drivers are rule changes that force ongoing evidence collection, while the hardest constraints are operational: integrating data, suppressing noise, and fitting into long enterprise or federal buying cycles.
[CM009, CM022, CM023, CM024, CM025, CM027]The market expands when buyers move from static screening into a continuous loop of data enrichment, regulatory checks, sub-tier mapping, and remediation.
The funnel is qualitative. It shows why buyer ROI depends on implementation quality, alert precision, and integration, not just on owning a list of regulations to screen against.
[CM022, CM024, CM027, CM028, CM032, CM037]2.5 Exhibits
03Competitors
3.1 Landscape and Solution Classes
Exiger does not compete in one neat software box. Buyers can solve overlapping pieces of the job with data-led screening vendors, workflow-first TPRM suites, or graph-driven supply-chain intelligence platforms. Dun & Bradstreet, LSEG, LexisNexis Risk Solutions, Sayari, and K2 Integrity matter when the buying center wants sanctions, KYC, AML, or due-diligence intelligence. Coupa, ProcessUnity, Aravo, Ivalua, and Supply Wisdom matter when the buyer primarily needs onboarding, questionnaires, approvals, and continuous supplier monitoring inside an operating workflow. Sayari and Interos matter most when the buyer believes the real risk sits below tier 1 and wants network mapping, ownership resolution, or critical-node visibility. That split is why Exiger's pitch is broader than classic vendor-risk software. Its public materials frame one platform that mixes supply-chain intelligence with workflow execution and a federal or defense-grade deployment story. The competing substitute is not only another standalone vendor. It is also a composable stack where a buyer pairs a screening dataset with a procurement suite and accepts a narrower, but cheaper, operating model.[CP023, CP024, CP025, CP026, CP027, CP029]
| Competitor | Primary overlap | Scale / public signal | Target buyer | Differentiation | Key limitation |
|---|---|---|---|---|---|
| Exiger | Full-stack supply-chain intelligence + TPRM | 1/3 of Fortune 500; 60+ federal agencies and DIB members; FedRAMP authorized | Regulated enterprises, federal buyers, defense and critical supply chains | One platform spanning workflow, graph intelligence, critical-node analysis, and federal credibility | Public pricing and independent win-rate evidence are sparse |
| Dun & Bradstreet | Compliance data + due-diligence workflow | 10,000+ sources; 550M+ entities; 2026 agentic AI release | Compliance, onboarding, supplier and third-party risk teams | Verified business data plus automation for onboarding, screening, and due diligence | Less explicit public emphasis on component-level or multi-tier supply-chain mapping |
| LSEG Risk Intelligence | KYC and sanctions screening data | World-Check brand; API-first On Demand; points-based self-service packages | Financial-crime, onboarding, and sanctions-screening teams | Structured screening data with multiple delivery modes and transparent online package model | Narrower procurement workflow and weaker public supply-chain mapping story |
| LexisNexis Risk Solutions | Financial crime and customer-lifecycle compliance | Broad customer-lifecycle risk suite in retained set | Financial institutions, fintechs, insurers, retailers, and regulated enterprises | Layered financial-crime perspective across the customer lifecycle | Less explicit public evidence of deep multi-tier supplier mapping |
| Sayari | Trade and ownership intelligence for supply chains | 4B+ trade transactions; 500M+ entity profiles; 250+ jurisdictions | Compliance, procurement, trade, and supply-chain teams needing tier-N evidence | Combines trade, ownership, sanctions, export controls, and UFLPA or ESG workflows | Less full public TPRM workflow depth than broad supplier-risk suites |
| K2 Integrity | Expert-led financial-crime compliance | Global AML and sanctions advisory footprint across 100 countries in cited service page | Banks, fintechs, and regulated entities with complex program needs | Deep expert-led AML, sanctions, and regulatory remediation capability | Service-led positioning is less procurement-native and less graph-productized |
| Coupa | Procurement-native supplier risk workflow | Risk module embedded in a larger source-to-pay platform | Procurement organizations standardizing inside spend workflows | Onboarding, AI-driven monitoring, and alternative-supplier actions without leaving Coupa | Less public evidence of deep ownership, trade, or component-level intelligence |
| ProcessUnity | Configurable TPRM workflow platform | Forrester-recognized 2026 TPRM Leader in retained set | Enterprises prioritizing workflow maturity and questionnaire automation | Configurable workflows, real-time dashboards, external ratings, and AI-enabled scoping | Less public federal or graph-driven supply-chain differentiation |
| Aravo | Multi-domain TPRM platform | Enterprise TPRM platform with AI-enabled intelligence messaging | Large enterprises needing many third-party risk domains in one program | Centralized applications spanning multiple compliance and risk domains | Public materials emphasize workflow over trade or sanctions-data depth |
| Ivalua | Supplier risk inside procurement suite | Integrated supplier platform with sub-tier scorecards | Procurement-led enterprises wanting risk in supplier operations | 360-degree supplier view with external risk data and scorecards | Less explicit public AML or sanctions-data differentiation |
| Supply Wisdom | Continuous monitoring specialist | Supplier and location monitoring across many risk domains | Teams focused on real-time alerts and location-aware supplier exposure | Continuous monitoring, location risk, and look-back reporting | Public materials emphasize alerts more than ownership or trade provenance |
| Interos | Supplier resilience and mapping | Automated mapping platform plus ERP-linked iQ expansion | Enterprises and government buyers focused on resilience and disruption | Multi-tier mapping, predictive exposure, and alternative supplier suggestions | Less explicit AML, KYC, and onboarding workflow language than Exiger or screening incumbents |
Coverage is intentionally partial but broad: it follows the named competitive set in the brief plus the most relevant supply-chain intelligence peer, and it summarizes only the capabilities supported by retained public 2026 sources.
[CP004, CP005, CP006, CP008, CP010, CP011]Ordinal positioning shows Exiger between data incumbents, workflow suites, and graph specialists: stronger on full-stack overlap than any one narrow rival, but not unchallenged on any single axis.
Axes are author-assigned ordinal scores based on retained public product and partner materials rather than audited market-share data. Higher x means more embedded workflow or suite ownership; higher y means deeper external intelligence and multi-tier graph depth.
[CP023, CP024, CP025, CP026, CP027, CP041]3.2 Capability Overlap by Job
The overlap changes materially by capability. D&B and LSEG are strongest where verified entities, sanctions coverage, PEPs, adverse media, onboarding efficiency, and structured screening data matter more than deep supplier-network context. LexisNexis and K2 Integrity extend that same financial-crime lane, though K2 stays more services-led than platform-led in the retained set. Workflow specialists attack from another angle. Coupa, ProcessUnity, Aravo, and Ivalua all promise to speed onboarding, centralize risk decisions, and keep teams inside familiar approval paths. Supply Wisdom narrows further into continuous monitoring and location risk. Exiger looks most differentiated when the buyer wants those workflow benefits plus supply-chain graphing, critical-node analysis, and public federal credibility in one stack. Sayari and Interos are the most serious challenges to that graph side. Sayari argues questionnaires miss sub-tier sanctioned or forced-labor exposure and replaces them with trade and ownership evidence. Interos attacks the same blind spot through resilience mapping, automated monitoring, and ERP-linked suggestions. Hackett's public description of Exiger's component, hardware, and software-level analysis supports a real wedge, but not a monopoly wedge.[CP006, CP007, CP008, CP009, CP010, CP011]
| Capability | Exiger | D&B | LSEG | Sayari | Coupa | ProcessUnity | Ivalua | Interos |
|---|---|---|---|---|---|---|---|---|
| Sanctions / AML / KYC data | Yes — part of broader intelligence stack | Yes — core compliance dataset | Yes — core World-Check data | Yes — sanctions and beneficial-ownership screening | Partial — risk domain workflows depend on partner or external data | Partial — workflow can ingest ratings but public set is not data-led | Partial — external data aggregation rather than flagship data brand | No public evidence in retained set |
| Beneficial ownership / entity verification | Partial — due diligence and supplier intelligence positioning | Yes — entity identification and business-partner monitoring | Yes — entities and individuals screened through World-Check workflows | Yes — ownership intelligence is a core product claim | No public evidence in retained set | Unknown in retained set | Partial — external data and scorecards | No public evidence in retained set |
| Third-party onboarding workflow | Yes — onboarding and risk-ranking are explicit | Yes — onboarding and monitoring automation are explicit | Partial — screening data feeds workflows more than owns them | Partial — demo and workflow language exists but not full TPRM breadth | Yes — onboarding is a core claim | Yes — onboarding and post-contract workflow are core claims | Yes — supplier-risk workflow sits inside procurement | Partial — ERP-linked actions are emerging but not classic TPRM |
| Continuous monitoring alerts | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Multi-tier supplier mapping | Yes — AI Expo material highlights multi-tier mapping | Partial — third-party lifecycle visibility, not deep tier mapping | No public evidence in retained set | Yes — tier-1 to tier-N mapping is core | Partial — supplier health and alternatives, but not explicit tier-N mapping | No public evidence in retained set | Partial — sub-tier scorecards without public graph-depth detail | Yes — automated supply-chain mapping is core |
| Component / hardware / software-level analysis | Yes — Hackett cites this specifically | No public evidence in retained set | No public evidence in retained set | Partial — component and material sourcing visibility through trade data | No public evidence in retained set | No public evidence in retained set | No public evidence in retained set | No public evidence in retained set |
| Federal / defense channel credibility | Yes — FedRAMP and 60+ federal agencies or DIB | No public evidence in retained set | No public evidence in retained set | Partial — aerospace and defense markets are targeted but federal footprint is thinner in retained set | No public evidence in retained set | No public evidence in retained set | No public evidence in retained set | Partial — government buyers are named in iQ launch materials |
| Public self-serve or transparent packaging | No public evidence in retained set | No public evidence in retained set | Yes — points-based online packages are public | No public evidence in retained set | No public evidence in retained set | No public evidence in retained set | No public evidence in retained set | No public evidence in retained set |
Cells reflect only capabilities that could be supported from the retained public corpus. “No public evidence in retained set” means the reviewed sources did not support a stronger statement, not that the vendor lacks the capability.
[CP006, CP008, CP012, CP013, CP016, CP018]3.3 Packaging, Win-Loss Logic, and Bundle Pressure
Packaging is where the incumbent threat becomes concrete. LSEG publicly offers the easiest low-friction entry in the retained set through API-first World-Check On Demand and points-based World-Check One packages. D&B is more sales-led, but its 2026 agentic release shows the same strategic direction: wrap proprietary data in workflow automation rather than sell raw records alone. Coupa and Ivalua increase the pressure from the opposite side by selling supplier-risk functionality from inside an existing spend platform, which can let a procurement team satisfy a risk mandate without sponsoring another standalone purchase. ProcessUnity and Aravo are harder to dismiss in workflow-led evaluations because they specialize in configurable third-party programs, not just generic supplier master data. The win-loss logic therefore is fairly crisp. Exiger is advantaged when buyers care about federal or defense readiness, component-level supply-chain analysis, or multi-tier mapping with action workflows. It is disadvantaged when the account only needs a screening feed, only needs a procurement-native module, or is comfortable composing a narrower stack from multiple vendors.[CP009, CP016, CP017, CP019, CP020, CP030]
| Vendor / class | Public packaging signal | Entry motion | What is clearly public | Implication |
|---|---|---|---|---|
| Exiger | No public list pricing in retained set | Enterprise demo / sales cycle | Platform positioning, federal credibility, and product breadth are public; contract metric is not | Commercial friction likely higher than data-only or procurement-native substitutes |
| D&B | No public list pricing in retained set | Enterprise sales around data + workflow automation | 2026 agentic workflow expansion is public, but pricing is not | Can bundle data and workflow into existing compliance budgets |
| LSEG | Yes — points-based packages and API-first product are public | Self-service package or API-led deployment | World-Check One packages, up to three users, automated billing, and On Demand API are public | Easiest low-friction land motion among retained competitors |
| Coupa | No public list pricing in retained set | Module inside source-to-pay stack | Workflow capabilities and partner-embedded data are public | Bundling power rises sharply inside existing Coupa accounts |
| ProcessUnity | No public list pricing in retained set | Demo-led subscription sale | Workflow depth and Forrester recognition are public | Credible short-list option, but commercial transparency is low |
| Ivalua | No public list pricing in retained set | Suite sale inside procurement platform | Supplier-risk capabilities are public | Strong bundle threat where Ivalua already owns procurement operations |
| Sayari | No public list pricing in retained set | Enterprise demo with workflow integrations | Trade, ownership, sanctions, and procurement integrations are public | Strong specialist position, but still sales-led |
| Supply Wisdom | No public list pricing in retained set | Enterprise demo around continuous monitoring | Alerting and monitoring scope are public | Useful niche specialist, but opaque commercial model |
This table covers public packaging signals rather than private contract terms. “No public list pricing in retained set” means the retained sources did not disclose list prices, seat models, or ACV bands.
[CP009, CP017, CP030, CP031, CP036, CP038]| Buyer job | Exiger likely wins when… | Exiger likely loses to… | Why the outcome tilts that way | Evidence caveat |
|---|---|---|---|---|
| Federal or defense supply-chain risk | The account wants FedRAMP, defense relevance, and agentic multi-tier mapping in one platform | Sayari or Interos if the buyer wants a narrower graph or resilience specialist | Exiger's federal footprint and component-level analysis matter most here | Public sources do not disclose actual bid win rates |
| Pure sanctions or onboarding screening | The buyer still wants workflow and supply-chain context around screening | LSEG, D&B, or LexisNexis | Screening incumbents offer narrower entry points and stronger data-brand recognition | No public cost comparison is available for apples-to-apples deployments |
| Procurement-native supplier risk | The buyer accepts a separate risk platform to get deeper intelligence and federal or graph depth | Coupa or Ivalua | Installed procurement suites can satisfy many supplier-risk requirements inside existing approval flows | Public materials show capability overlap but not displacement rates |
| Multi-tier forced-labor or sanctions mapping | The buyer values workflow execution after graph discovery, not just map output | Sayari or Interos | Sayari and Interos both center the sale on tier-N visibility and data depth | Comparative precision and freshness benchmarks are not public |
| Configurable TPRM backlog relief | The buyer wants workflow plus supply-chain intelligence rather than workflow alone | ProcessUnity or Aravo | Workflow specialists market configurable questionnaires, dashboards, and program design depth | Public sources are richer on feature claims than on customer satisfaction data |
| Continuous monitoring only | The buyer wants risk context tied to broader procurement or federal workflows | Supply Wisdom or D&B | Monitoring specialists can be cheaper and simpler when graph depth is not required | No public commercial metric shows when Exiger becomes over-scoped |
| Expert-led AML remediation | The buyer still wants software and supply-chain intelligence as part of the answer | K2 Integrity | K2 is more naturally a services-led compliance partner than a platform-led procurement tool | Service attach rates and blended software-services terms are private |
Win and loss logic is inferred from public product positioning, partner material, and analyst-style commentary in the retained corpus. It should be treated as directional until validated by customer references or RFP history.
[CP026, CP027, CP029, CP030, CP031, CP037]Compact public signals explain why Exiger is credible in this category while still vulnerable to bundling and composable alternatives.
These are public product or scale signals, not audited commercial KPIs. They are directionally useful for competitive readiness but not substitutes for customer references or pricing diligence.
[CP004, CP006, CP009, CP012, CP041, CP042]3.4 Moat Durability and Adverse View
The durable part of Exiger's moat is the unusual combination of graph-driven supply-chain intelligence, workflow execution, and public federal credibility. Very few public peers market all three together. The adverse case is that each piece can still be attacked separately. D&B, LSEG, and Lexis can deepen workflow around data franchises that already sit inside compliance budgets. Coupa and Ivalua can deepen monitoring and decisioning from inside procurement suites that already own the user and approval layer. Sayari and Interos can outflank Exiger on the graph side by making sub-tier visibility or resilience mapping the main buying event rather than an add-on to TPRM. Public materials do not show decisive independent win-rate or precision benchmarks that would prove Exiger consistently displaces all of those alternatives. That leaves Exiger with a strong, but execution-dependent, moat: credible in regulated and defense-heavy accounts, more vulnerable when buyers want only one slice of the stack or can bundle the slices they need elsewhere.[CP027, CP028, CP029, CP037, CP038, CP039]
| Moat claim | Primary threat | Severity | Why the threat is real | Mitigation / diligence ask |
|---|---|---|---|---|
| Unified intelligence + workflow stack | Suite bundling by D&B, LSEG, Coupa, and Ivalua | High | Each incumbent already owns an adjacent budget line and can deepen the missing piece | Request actual displacement stories where Exiger replaced a suite incumbent end to end |
| Federal / defense deployment credibility | Graph specialists extend government relevance | Medium | Sayari and Interos both market government or defense-adjacent relevance from the graph side | Verify current federal renewal rates and relative authorization scope |
| Component-level supply-chain analysis | Peers extend graph depth downward into parts and facilities | Medium | Hackett called this an Exiger differentiator, but it is still a product feature that others can chase | Ask for customer examples where component-level analysis changed the buying decision |
| Agentic workflows tied to graph data | Data incumbents add workflow automation and AI agents | High | D&B's 2026 release shows the data side is already moving into execution | Benchmark analyst productivity and false positives against D&B and LSEG in live bake-offs |
| Procurement interoperability without losing depth | Procurement suites become good enough for supplier-risk operations | High | Coupa and Ivalua can meet many workflow needs without another platform sponsor | Test whether Exiger materially improves outcomes beyond what procurement teams can get in-suite |
| Multi-tier mapping as a core wedge | Sayari and Interos become the default graph specialists | High | Both rivals make tier-N visibility the main buying event rather than a supporting feature | Compare graph freshness, explainability, and actionability across the three platforms |
Severity is an author judgment from the retained public record rather than a numeric risk model. The diligence asks are the practical follow-ups needed to move from positioning claims to underwriting confidence.
[CP028, CP032, CP033, CP041, CP042, CP043]3.5 Exhibits
04Financials
4.1 Revenue Model, Pricing Opacity, and Distribution
The public evidence supports a software-led enterprise revenue model, but not a transparent pricing model. Exiger's homepage, products surface, and public-sector materials all describe a unified platform that maps supplier, product, part, component, and risk data for enterprise and government buyers. The company also describes itself in multiple releases as a SaaS or supply chain AI company rather than a consulting-led outsourcer, and the 2023 Capgemini divestiture sharpened that positioning by separating the legacy FCC advisory division from the core third-party risk and supply-chain technology business. At the same time, every reviewed commercial surface remains sales-led. There is no public list price, self-serve seat model, or disclosed usage meter for the core platform. The March 2026 AWS Marketplace launch matters because it shortens procurement friction and could widen channel-driven expansion, but it still does not reveal actual SKU pricing or realized contract terms. So the right financial reading is not that Exiger lacks monetization discipline; it is that the public file only shows the shape of the revenue engine—enterprise contracts, government procurement, and module expansion—not the realized economics that convert those motions into durable revenue quality.[CI001, CI002, CI003, CI013, CI024, CI030]
| Revenue stream | Mechanism | Unit | Current public status | Quality | Diligence ask |
|---|---|---|---|---|---|
| Enterprise supply-chain intelligence platform | Platform contracts for mapping suppliers, products, parts, components, and risk data | Enterprise contract | Core product family is clearly merchandised across commercial and public-sector pages | Medium | Provide ACV, renewal terms, and software versus services contribution |
| Third-party risk and compliance workflows | Programmatic risk, diligence, trade, and compliance workflows sold to large organizations | Workflow / program contract | Active product suite is public, but contract economics are not | Medium | Break out revenue by risk/compliance module and customer segment |
| Government and Defense Industrial Base deployments | FedRAMP-enabled public-sector and federal contract-vehicle selling | Agency / contract | 60+ government and DIB organizations are cited in 2026 materials | Medium-High | Disclose public-sector share of ARR, bookings, and renewals |
| Software supply chain and parts intelligence modules | Add-on data and AI modules expanded through XSB and related product lines | Module / platform add-on | Capability is visible, monetization is not separately disclosed | Low-Medium | Show attach rates and standalone pricing for parts and software-supply-chain modules |
| AWS Marketplace procurement channel | Cloud-marketplace procurement path for 1Exiger | Marketplace-facilitated contract | Launch is public as of March 2026, but pricing remains opaque | Medium | Disclose marketplace-sourced pipeline, bookings, and discount policy |
| Expert analysts and tech-enabled support | Analyst-led support embedded alongside federal and enterprise solutions | Service or bundled support | Operational role is visible in public-sector messaging, but billing treatment is unknown | Low | Quantify services revenue share and associated gross margin |
Public evidence identifies the main monetization lanes, but not realized pricing, ACV, renewal mechanics, or software-versus-services mix.
[CI001, CI002, CI003, CI013, CI024, CI027]| Surface / offer | Public price or contract signal | List vs. realized pricing | Unknowns | Implication | Source |
|---|---|---|---|---|---|
| Homepage and product pages | Contact-sales positioning; no public rate card | No list pricing disclosed | Seat model, usage meter, minimums, and term length are all undisclosed | Pricing is likely customized for enterprise complexity and data scope | Exiger homepage / products |
| Public-sector page | Federal solutions and contract vehicles are promoted, but no public fees are shown | No list pricing disclosed | Contract ceilings, task-order economics, and agency discounting are private | Government revenue likely flows through bespoke procurement vehicles | Exiger public-sector page |
| AWS Marketplace availability | Procurement channel became public in March 2026 | Channel availability, not list price | SKU pricing, private offers, and marketplace take rates are undisclosed | Marketplace can reduce buying friction without making realized pricing transparent | Exiger AWS Marketplace release |
| 1ExigerAI outcome examples | ROI is framed through operational outcomes rather than fee disclosure | Outcome proof, not price | No clue on what share of savings Exiger captures economically | Value-based selling may be stronger than visible price transparency | Exiger 1ExigerAI page |
| Analyst-validation surfaces | Gartner and Hackett validate category strength, not transactional pricing | Value validation only | No conversion from analyst praise to ACV or margin is public | Supports premium positioning without proving realized monetization | Exiger Gartner / Hackett 2026 releases |
| Capgemini divestiture focus | Management explicitly prioritized the technology business | Strategic mix signal, not price | Pre- and post-divest revenue composition is undisclosed | Software-mix ambitions are visible even though contract economics are not | Exiger Capgemini divestiture release |
This table separates procurement or ROI signals from actual price disclosure so channel availability and customer value are not mistaken for realized pricing.
[CI003, CI013, CI024, CI030, CI032, CI048]Public evidence suggests Exiger monetizes data-rich risk workflows through enterprise and government contracts, then expands through channels and add-on modules.
[CI001, CI002, CI003, CI013, CI027, CI030]4.2 Growth Signals and Unit-Economics Proxies
Exiger's public traction signals are substantial for a private company, but still proxy-level. The cleanest 2026 scale claims come from the company's own Gartner and Hackett announcements, which say Exiger serves 550+ global customers, including 150 Fortune 500 and 60+ government and Defense Industrial Base organizations. The World Economic Forum organization profile broadly corroborates that scale, while the 1ExigerAI page adds quantified operational outcomes such as 20,000+ hidden entities found, 45% signal-noise reduction, 40,000+ parts normalized, 10-20% forecasting accuracy improvement, and 80%+ country-of-origin coverage in a federal use case. The single most important top-line signal is still third-party rather than audited: Forbes reported management expected revenue to exceed $150 million by the end of 2024 and claimed a five-year CAGR above 80%. Those numbers are directionally strong and consistent with high-800s employee scale, but they are not substitutes for ARR, gross margin, CAC payback, or retention. Underwriting should therefore treat Exiger as a company with unusually visible customer-density and proof-of-value signals, yet still an opaque unit-economics file.[CI004, CI005, CI006, CI007, CI008, CI009]
| Metric | Public value / proxy | Confidence | Why it matters | Diligence ask |
|---|---|---|---|---|
| Revenue run-rate floor | >$150M by end of 2024 (Forbes-reported management claim) | Low | Best public top-line signal for valuation framing | Provide audited TTM revenue and current ARR by segment |
| Five-year growth rate | >80% CAGR (Forbes-reported management claim) | Low | Suggests unusually strong historical compounding if accurate | Provide audited annual revenue history and bridge |
| Employee scale | 850+ on official about page; 870 in March 2024 Forbes interview | Medium | Supports that revenue floor is not an implausible one-person metric artifact | Provide current headcount by function and revenue per employee |
| Global customers | 550+ | High | Shows broad installed base and commercial reach | Provide paying-customer definition and active versus legacy accounts |
| Fortune 500 penetration | 150 customers | High | Supports enterprise relevance and potential expansion density | Provide top-20 account mix and average wallet share |
| Government / DIB organizations | 60+ in 2026 materials; over 50 in earlier profiles | High | Useful proxy for public-sector depth but also for concentration risk | Break out government revenue, backlog, and renewal concentration |
| Operational proof points | 20,000+ entities found; 45% signal-noise reduction; 40,000+ parts normalized; 10-20% forecasting accuracy improvement; 80%+ origin coverage in one federal use case | Medium | Outcome proof can support pricing power and expansion even without published ACV | Provide cohort-level ROI and attach-rate data by module |
| Gross margin | Low | Core determinant of whether Exiger behaves like software, services, or a hybrid | Provide GAAP gross margin with cost buckets for data, labor, and cloud | |
| CAC payback / sales efficiency | Low | Needed to judge sponsor-backed growth efficiency | Provide fully loaded CAC, payback, and channel mix | |
| Net revenue retention / churn | Low | Determines whether customer breadth converts into durable compounding | Provide NRR, gross retention, churn, and upsell by segment |
Nulls reflect genuine public-data gaps; the usable public proxies are customer density, outcome metrics, and one third-party-reported revenue floor rather than audited unit economics.
[CI004, CI005, CI006, CI007, CI008, CI009]The public unit-economics story is built from customer density and outcome proof rather than from disclosed margins or retention.
This bridge is directional because the strongest public operating metrics are customer-outcome proxies and one third-party-reported revenue floor rather than audited unit economics.
[CI006, CI007, CI008, CI010, CI011, CI012]4.3 Capital Stack, Acquisitions, and Government Mix
Exiger's capital story is visible in milestones but not in current balance-sheet detail. The earliest clearly disclosed financing marker in the reviewed set is the July 2018 $80 million minority growth-capital investment from Carrick Capital Partners. Public sources then jump to the December 2023 majority investment agreement with Carlyle and Insight Partners, plus Carrick's reinvestment, but the company and Carlyle do not publicly disclose the size or valuation of that transaction in the retained materials. That opacity matters because Exiger was simultaneously reshaping its platform. Between 2022 and 2024 it acquired Supply Dynamics, XSB, and Versed AI, while selling the FCC advisory division to Capgemini to focus the business on technology. Strategically, that looks coherent: Supply Dynamics added item-level mapping, XSB added 100 million parts and 400 million federal-government attributes, and Versed AI added multi-tier visibility. Financially, however, the public file says nothing about acquired revenue, integration cost, overlap, or synergy capture. Government footprint is another dual-use fact. Exiger's 2026 materials emphasize 60+ government and Defense Industrial Base organizations plus FedRAMP authorization and federal leadership, which is commercially attractive but also raises concentration risk because no public source breaks out how much revenue actually comes from the public sector.[CI016, CI017, CI018, CI022, CI023, CI024]
| Capital / portfolio item | Public value / status | Confidence | Why it matters | Diligence ask |
|---|---|---|---|---|
| 2018 Carrick growth capital | +$80M minority investment | Medium | Earliest clearly disclosed outside capital event in the reviewed set | Confirm pre-2023 capitalization and liquidation preference stack |
| 2023 Carlyle / Insight transaction | Majority investment announced; amount undisclosed | High | Establishes current sponsor ownership but not entry value | Disclose transaction size, sponsor ownership, and enterprise value at close |
| Carrick reinvestment in 2023 | Existing investor reinvested alongside new sponsors | High | Suggests continuity of capital support, not a clean handoff | Clarify rollover amount and governance rights |
| 2022 Supply Dynamics acquisition | Closed; financial terms not disclosed | Medium | Likely expanded supply-chain revenue surface and integration needs | Provide acquired revenue, cost, and synergy milestones |
| 2024 XSB acquisition | Closed; financial terms not disclosed | Medium | Added federal parts-intelligence data assets with potential cross-sell value | Provide purchase price, revenue contribution, and integration spend |
| 2024 Versed AI acquisition | Closed; financial terms not disclosed | Medium | Added AI-driven multi-tier visibility and possibly more software leverage | Provide purchase price, retention, and roadmap integration status |
| 2023 FCC divestiture to Capgemini | Business sale signed to sharpen tech focus | Medium | Could improve software mix and reduce services intensity | Provide divested revenue, margin, and post-sale revenue composition |
| Cash on hand / burn / runway | Low | Core balance-sheet test for sponsor-backed scaling businesses | Provide current cash, monthly burn, debt, and 12-24 month runway plan |
Public capital signals show sponsor support and active portfolio shaping, but not present cash balance, leverage, or the size of the 2023 control transaction.
[CI016, CI017, CI018, CI022, CI023, CI024]Sponsor backing and portfolio reshaping are visible, but the cash conversion of Exiger’s acquisition-led scaling path remains opaque.
[CI016, CI017, CI018, CI022, CI023, CI024]4.4 Valuation Support, Investor Return Expectations, and Diligence Blockers
Public valuation support for Exiger exists only as a range anchored on incomplete inputs. On the positive side, the company has real scale claims, repeated product recognition, major-sponsor backing, and a software-led positioning that could justify a premium analytics multiple if margins and retention are strong. Public comps show the spread investors should keep in mind. Dun & Bradstreet's public data implies a much lower-growth data-and-analytics floor at roughly 3.2x revenue based on the reported Clearlake take-private, while Verisk's public market profile implies roughly 7.6x trailing revenue for a scaled, higher-quality analytics platform. Applying that public comp frame to Forbes's reported >$150 million revenue floor yields a rough implied support band of about $480 million to $1.14 billion. That is directionally useful but not conclusive because Exiger does not disclose margin profile, net retention, segment mix, burn, runway, or the entry valuation for Carlyle and Insight. Investor return expectations are therefore conditional, not verified: upside requires Exiger to look economically more like a software/analytics platform than a services-heavy compliance roll-up, while downside remains plausible if government concentration or acquisition integration prove more material than the public file currently reveals.[CI031, CI032, CI034, CI035, CI036, CI037]
| Missing metric / adverse check | Impact on underwriting | Exact diligence path |
|---|---|---|
| ARR and revenue mix by product / segment | Blocks clean valuation, growth-quality, and mix underwriting | Request monthly revenue bridge split across supply chain, TPRM, public sector, and acquired modules |
| Gross margin and cost structure | Prevents judgment on software-like economics versus labor/data-heavy delivery | Request GAAP gross margin and COGS split across data, cloud, labor, and support |
| Burn, cash, debt, and runway | Makes sponsor-return timing and dilution risk unknowable | Request current balance sheet, debt schedule, and 24-month operating plan |
| Realized pricing, ACV, and contract duration | Obscures revenue quality and sales efficiency | Review representative contracts, price books, and discount ladders across segments |
| Government versus commercial revenue concentration | Large federal footprint could be strength or concentration risk | Provide revenue, bookings, and renewal mix by public sector versus commercial customers |
| Acquisition integration economics | Roll-up strategy may add growth or hidden integration drag | Provide acquired ARR, overlap analysis, integration costs, and realized synergies for Supply Dynamics, XSB, and Versed AI |
| 2023 sponsor entry valuation and ownership | Without a public valuation mark, investor return expectations cannot be benchmarked | Disclose transaction enterprise value, sponsor ownership, option pool, and preference stack |
These are the minimum missing disclosures required to move from directional enthusiasm to an investable financial model and valuation view.
[CI018, CI031, CI032, CI038, CI039, CI040]Using public comp multiples on Forbes’s >$150M revenue floor produces a broad, only-directional support range rather than a reliable mark.
Low end applies D&B-like ~3.2x revenue support; high end applies Verisk-like ~7.6x revenue support; midpoint is the simple average of those public comp anchors. Exiger’s actual valuation, margin profile, and 2023 sponsor entry mark are undisclosed.
[CI019, CI035, CI037, CI038, CI039, CI040]4.5 Exhibits
05Product & Technology
5.1 Platform Surface, Modules, and Workflow
Exiger’s product file now reads as a platform family rather than a single diligence database. The public packaging clusters around 1Exiger and 1ExigerAI for supply-chain execution, DDIQ for due diligence and compliance, and adjacent surfaces such as software supply chain security. DDIQ is still the cleanest evidence-backed workflow: it ingests watchlists, premium news, open web, and proprietary lists, then organizes the result with configurable risk rules and audit-ready profiles. 1ExigerAI pushes the story from analysis toward action by claiming human-plus-AI workflow routing, centralized case activity, and quantified operating outcomes such as signal-noise reduction, parts normalization, and country-of-origin mapping. OpenCorporates and WorldCompliance matter here because they show that Exiger is not only surfacing proprietary graphs; it also plugs external verification and sanctions data into the same motion. What the public file does not cleanly do is explain ORCA as a standalone surface, which leaves one branding thread unresolved for outside buyers.[CE001, CE002, CE003, CE004, CE005, CE006]
| Module / asset | Primary user | Status / maturity | Differentiation | Diligence gap |
|---|---|---|---|---|
| 1Exiger supply-chain workspace | Procurement, supply chain, compliance teams | Clearly merchandised and broadly evidenced | Unifies supplier, part, material, and risk views in one workspace rather than a point alert feed | Need public module-by-module architecture and SLA evidence |
| DDIQ due diligence engine | Risk, compliance, onboarding, KYC analysts | Mature legacy product surface | AI/NLP-driven diligence profiles aggregate watchlists, premium news, open web, and proprietary lists with configurable risk rules | Need public precision/recall and workflow-level benchmark disclosure |
| 1ExigerAI agentic execution layer | Supply chain, procurement, and operations leaders | Newer 2026 flagship narrative | Moves from insight to execution with human-plus-AI routing, centralized workflows, and quantified use-case claims | Need transparent governance metrics for explainability, drift, and approval thresholds |
| WorldCompliance-backed screening data | Compliance and sanctions teams | External data asset, not Exiger-owned IP | Structured sanctions, enforcement, adverse-media, and ownership data expands Exiger’s compliance breadth and lowers manual screening friction | Need contract-level visibility into how much workflow quality depends on external data freshness and licensing |
| XSB / Digital Thread & Parts Intelligence | Engineering, logistics, acquisition, sustainment teams | Strategic differentiator with specific data assets | Adds part-level and document-to-data intelligence, SWISS API potential, and 100M+ part coverage beyond entity-only risk tools | Need evidence of how deeply XSB stack is integrated into the core UI and data model |
| Supply Dynamics / SDX multi-tier mapping | Manufacturing, sourcing, and industrial-base teams | Strategic differentiator with older but concrete integration story | Adds real-time item-level visibility, tier-n mapping, and raw-material detail that strengthens Exiger’s digital-thread claim | Need current proof of commercial availability, performance, and adoption after the 2022 acquisition |
| Versed AI multi-tier visibility | Supply-chain strategy and resilience teams | Added capability with thinner public operational evidence | Adds AI-driven mapping of complex n-tier networks and automated BOM creation from public and open-source content | Need public benchmarks on mapping accuracy, refresh cadence, and false-positive rates |
| ORCA-branded surface | Current and prospective Exiger buyers | Publicly ambiguous in the 2026 file | If ORCA still exists, it is not surfaced as a clearly separate public product page in the reviewed materials, which suggests branding consolidation into broader 1Exiger language | Need product taxonomy clarification from Exiger to avoid over-claiming standalone capability |
Status reflects public evidence depth and commercialization clarity, not a private architecture review or customer-satisfaction audit.
[CE001, CE002, CE003, CE004, CE011, CE013]Exiger’s public architecture reads as a layered operating stack that starts with user workflows, passes through decisioning and proprietary graph assets, and depends on partner data plus secure deployment paths underneath.
[CE001, CE003, CE011, CE014, CE015, CE018]5.2 Data Engine, Integrations, and Operating Architecture
Exiger’s clearest technical differentiation is the combination of graph-scale data assets with enterprise workflow integration. The supply-chain product page says the company is API-first and combines open APIs, AI-driven ETL, and bidirectional ERP and PLM interoperability with a product-aware knowledge graph spanning 10 billion records, 400 million part attributes, and 6.5 million mapped relationships. The acquisition trail makes that claim more believable. Supply Dynamics added item-level and tier-n visibility, XSB added parts intelligence plus a knowledge-graph and API lineage, and Versed AI added automated n-tier mapping and BOM-generation language for customers that do not already have clean technical packages. Snowflake embedding and AWS marketplace distribution add another important clue: Exiger wants to sit inside existing enterprise data foundations rather than remain a disconnected dashboard. The technical picture is therefore of a data-heavy orchestration layer, not a simple screening feed, but one whose performance still depends on data quality, connector coverage, and explainable decisioning.[CE014, CE015, CE016, CE017, CE018, CE019]
| User job | Current workflow | Exiger solution | Measurable benefit | Limitation |
|---|---|---|---|---|
| Third-party onboarding and counterparty due diligence | Verify entity identity, screen adverse information, and document risk rationale | DDIQ plus OpenCorporates-backed verification and configurable risk rules | More consistent diligence files and an Exiger-claimed >80% reduction in downstream false positives from better verification | Public evidence is stronger on workflow narrative than on audited precision or recall |
| Continuous supplier and sanctions monitoring | Batch screen suppliers, customers, or agents against sanctions, enforcement, and adverse media | WorldCompliance-backed screening combined with Exiger monitoring and case workflows | Faster updates, more structured profiles, and lower manual review for large populations | Output quality still depends on third-party data quality and customer triage policy |
| Multi-tier supplier mapping and disruption response | Map dependencies, identify critical sub-tiers, and find alternates when disruption hits | 1Exiger plus Supply Dynamics, Versed AI, and XSB-derived data assets | Richer part-, material-, and supplier-level visibility with directed-buy or alternative-sourcing paths | Public materials do not disclose production latency, coverage error rates, or customer onboarding effort |
| Engineering-document and parts analysis | Extract part requirements from static PDFs and compare alternatives or obsolescence risk | Digital Thread and Parts Intelligence plus XSB graph assets | Turns dead-text engineering files into machine-readable data exportable to downstream systems | Need proof on throughput, accuracy, and how often humans must correct extracted data |
| Regulated public-sector supply-chain operations | Operate inside security-constrained federal workflows with procurement and compliance needs | FedRAMP-authorized Exiger Federal Cloud, Carahsoft channel, and AWS-enabled distribution | Supports secure deployment paths and broader federal interoperability claims | Public file does not provide agency-specific implementation timelines or reliability metrics |
Benefits combine official outcome claims with third-party corroboration; they should be read as workflow potential rather than audited ROI for every customer.
[CE004, CE005, CE007, CE008, CE011, CE012]| Layer / component | Role | Dependency | Risk |
|---|---|---|---|
| Data ingestion and integration layer | Ingest ERP, PLM, S2P, watchlist, news, and proprietary customer data through open APIs and AI-driven ETL | Customer system quality, connector coverage, and identity resolution across source systems | Messy source data or narrow connector coverage can raise implementation time and weaken output quality |
| Entity and compliance intelligence layer | Verify subjects and enrich them with company, sanctions, enforcement, ownership, and adverse-media records | OpenCorporates, WorldCompliance, and other external data providers | Incomplete, stale, or mis-matched external records can create false positives or false negatives |
| Supply-chain graph and parts-intelligence layer | Map suppliers, parts, materials, documents, and multi-tier relationships across engineering and procurement contexts | Exiger’s proprietary graph plus XSB, Supply Dynamics, and Versed AI data assets | Graph scale is a moat, but deep dependency on proprietary data curation can obscure explainability and refresh mechanics |
| Decisioning and workflow layer | Prioritize risks, recommend actions, route cases, and coordinate human or AI execution | 1ExigerAI rules, permissions, case activity, and customer operating playbooks | Agentic workflow claims outpace public governance detail on thresholds, override logic, and model monitoring |
| Deployment and security layer | Run commercial and public-sector environments across AWS, FedRAMP cloud, and embedded Snowflake contexts | AWS distribution, FedRAMP controls, customer cloud architecture, and secure interoperability | Secure deployment evidence is real, but public materials still lack detailed reference architectures and SLA history |
This is an operating-model reconstruction from public materials, not a packet capture or architecture review. It highlights where third-party dependencies and governance risk likely concentrate.
[CE003, CE011, CE014, CE015, CE016, CE018]The public workflow begins with data ingestion and verification, adds multi-tier mapping and scoring, and ends in human-plus-AI execution inside customer operating systems.
[CE003, CE004, CE005, CE020, CE021, CE023]Exiger’s workflow depends on a mix of proprietary graph assets, external data providers, customer systems, and secure cloud deployment nodes that all feed the same decision layer.
[CE011, CE015, CE018, CE020, CE022, CE023]5.3 Deployment, Trust, and Developer Signal
Exiger’s deployment evidence is stronger than its public model-governance evidence. The company has concrete channel and control markers: 1Exiger is generally available in AWS Marketplace, Exiger Federal Cloud appears as FedRAMP Certified Class C (Moderate) in the FedRAMP Marketplace, and Exiger says regulated integrations run in that authorized environment alongside ISO 27001 and SOC 2 Type II controls. Carahsoft gives additional public-sector distribution support. The developer signal is not open-source in the usual sense, but the hiring surface is still informative. Current roles point to Snowflake architecture, AWS, APIs and data pipelines, CI/CD, Kubernetes, AI and ML analytics, and implementation managers who coordinate complex client deployments. A Built In role tied to Exiger’s XSB surface adds Java web apps, RESTful services, relational databases, Docker, and NIST or FedRAMP experience. Taken together, that suggests a real secure SaaS and data-platform footprint—but also a product that is unlikely to be frictionless for buyers to deploy, tune, and govern without meaningful services and customer-operating alignment.[CE026, CE027, CE028, CE029, CE030, CE031]
| Control / quality signal | Status | Scope | What it supports | Gap |
|---|---|---|---|---|
| FedRAMP Moderate / FedRAMP Certified listing | Concrete and independently listed | Exiger Federal Cloud for government and DIB workflows | Secure deployment and interoperability claims for regulated programs | Need module-level boundary documentation and inherited-control detail |
| ISO 27001 and SOC 2 Type II claims | Company-claimed and current in public materials | Company-wide trust posture referenced in supply-chain and FedRAMP materials | Supports baseline security and control maturity narrative | Need public certificates, dates, and service-scope mapping per module |
| OpenCorporates provenance and audit trail | Concrete partner case-study evidence | Entity verification inside DDIQ with links back to official company registers | Reduces manual verification burden and supports defensible audit trails | Need current scale disclosure and regional coverage exceptions in 2026 |
| WorldCompliance structured profiles and update cadence | Concrete external technical-doc evidence | Sanctions, enforcement, ownership, PEP, and adverse-media data used in screening workflows | Improves structured screening breadth and timeliness for compliance use cases | Need clarity on how Exiger handles upstream source errors or conflicting records |
| Roles, permissions, and human-plus-AI routing | Company-claimed and visible in 1ExigerAI messaging | Workflow execution, case handling, and reviewer assignment | Suggests governance hooks exist beyond pure black-box automation | Need public evidence on explainability UX, override logging, and approval policies |
| Model governance metrics | Publicly incomplete | Would cover precision, recall, drift, fairness, and hallucination controls | Most important missing trust layer for underwriting agentic AI claims | Public materials reviewed do not disclose benchmark, red-team, or fairness dashboards |
Trust evidence is asymmetrical: deployment controls are more visible than model-governance metrics. The last row intentionally records that asymmetry as a diligence gap, not as a hidden assumption.
[CE011, CE012, CE023, CE027, CE028, CE029]5.4 Differentiation, Maturity, and Technical Risks
The moat case is strongest where incumbents stop at entity screening or generic supplier scores. Exiger now has a more granular story: engineering-document extraction, part-attribute intelligence, multi-tier mapping, embedded Snowflake workflows, and procurement-oriented execution paths such as alternative sourcing or directed-buy. That is a materially different technical proposition from a sanctions database or adverse-media feed alone. The risk is that Exiger’s public ambition around agentic and explainable AI outpaces the level of public engineering proof available for underwriting. The reviewed file does not publish precision and recall, false-negative rates, drift monitoring, fairness testing, or detailed override and audit logs for AI decisions. Pricing remains opaque, ORCA nomenclature is unresolved in public packaging, and the company does not publish the kind of reference architecture or SLA history that would simplify diligence on deployment effort. Exiger therefore looks like a differentiated, data-rich workflow platform, but one that still needs deeper diligence on black-box risk, upstream data quality, and implementation complexity before buyers should assume low-friction adoption.[CE013, CE025, CE033, CE034, CE036, CE037]
| Date / stage | Feature or milestone | Status | Implication | Source |
|---|---|---|---|---|
| 2022-08 | Supply Dynamics acquisition and SDX/PAC/ExplorerRX integration plan | Shipped acquisition milestone | Anchored Exiger’s move toward item-level visibility and multi-tier mapping before the 2024-2026 AI branding wave | Exiger Supply Dynamics release |
| 2024-08 | XSB acquisition | Shipped acquisition milestone | Added parts-intelligence depth, engineering analytics, and SWISS knowledge-graph/API potential for defense and logistics workflows | Exiger / XSB / Progress Partners |
| 2024 | Versed AI acquisition | Shipped acquisition milestone | Added AI-driven multi-tier mapping and automated BOM-generation language to the data moat story | Exiger Versed AI release |
| 2024-09 | Government-wide FedRAMP Moderate authorization refresh | Shipped trust milestone | Improved credibility for secure federal deployment and integrated workflows in controlled environments | Exiger FedRAMP release / FedRAMP Marketplace |
| 2026-03 | AWS Marketplace general availability for 1Exiger | Shipped distribution milestone | Shortens procurement friction and broadens cloud-channel reach without proving transparent pricing | Exiger / PR Newswire AWS launch |
| 2026 | Snowflake embedding for energy solutions | Active integration expansion | Shows Exiger trying to meet customers inside their existing data foundation rather than forcing a separate tool silo | Exiger Snowflake announcement |
| 2026 | 1ExigerAI Activation Series and AI+ Expo demos | Active go-to-market and roadmap signaling | Signals current strategic emphasis on agentic AI, multi-tier mapping, and execution workflows rather than legacy nomenclature | Exiger Activation Series / AI+ Expo materials |
Rows focus on milestones that materially changed the technical surface or deployment motion. They are not a complete release log, which Exiger does not publicly maintain in the reviewed file.
[CE020, CE022, CE025, CE026, CE027, CE033]Public evidence shows high maturity in core diligence and deployment channels, medium maturity in agentic execution messaging, and lower public visibility into model-governance detail and standalone ORCA positioning.
[CE004, CE013, CE018, CE023, CE026, CE027]5.5 Exhibits
06Customers
6.1 Customer footprint and segment mix
Exiger’s customer base is broad in category but uneven in proof quality. Official and independent profile surfaces consistently describe a business that serves corporations, government agencies, and banks, with the sharpest documented use cases in procurement-led supply-chain intelligence, federal mission assurance, compliance, and third-party risk. The company’s repeated 2026 scale claims—550+ customers, 150+ Fortune 500 customers, and 60+ government or Defense Industrial Base organizations—show that Exiger is not a niche pilot vendor. But those counts say little about mix. Publicly named proof is strongest in defense, government, healthcare, and industrial manufacturing. Financial-services coverage is strategically important, yet the visible case studies stay anonymous, which weakens referenceability for marquee-bank claims. The practical read is that Exiger likely has a meaningful regulated-enterprise and government installed base, but the buyer surfaces most clearly where procurement, compliance, and mission readiness intersect.[CU001, CU002, CU003, CU004, CU005, CU006]
| Segment | Buyer / payer | Primary user | Representative use case | Public scale / proof | Strategic value / gap |
|---|---|---|---|---|---|
| Federal agencies / DoD | Acquisition, sustainment, or mission owners using federal contract vehicles | Supply-chain analysts, program offices, cyber and sourcing teams | Army sustainment, CBP transshipment detection, DDIQ vetting, Platform One access | Army AMC and CBP are named; OUSD/DDIQ, SCRIPTS, and Platform One widen access | Strongest named proof, but public-sector revenue share is undisclosed |
| Defense Industrial Base organizations | Prime contractors or mission-linked procurement groups | Supplier-risk, provenance, or compliance operators | Multi-tier risk, parts intelligence, SBOM, and mission-assurance workflows | Official materials cite 60+ government and DIB organizations but do not name most of them | Suggests defense adjacency, but customer-level concentration is opaque |
| Fortune 500 regulated enterprises | Procurement, compliance, legal, and risk leaders | Third-party risk, supplier-risk, and remediation teams | Large-enterprise supplier and third-party risk management | 150+ Fortune 500 customer claim is repeated across official 2026 surfaces | Scale claim is strong; named enterprise references are still limited |
| Financial institutions and fintechs | Compliance, legal, investigations, and financial-crime budgets | Transaction-monitoring, EDD, sanctions, and KYC operators | Alert lookbacks, new-product controls, and KYC remediation | Public proof is real but anonymized across a major investment bank, a top-10 regional bank, and a European fintech | No supportable named 2026 proof for Goldman Sachs or JPMorgan |
| Healthcare providers | Supply-chain leadership and vendor-risk ownership | Vendor-risk managers and supplier-monitoring teams | Northwell vendor-risk management and supply-chain monitoring | Northwell is a named enterprise healthcare reference with integration detail | Public corpus does not show broader healthcare account depth |
| Industrial / manufacturing OEMs | Supply-chain, sourcing, and operations leadership | Material planners, supplier teams, and fabricators | Oshkosh/JLG part, BOM, and material-sourcing visibility | Oshkosh/JLG is a named manufacturing reference with quantified outcomes | Named industrial proof is strong but narrow in count |
| Software / OT suppliers under customer or regulator pressure | Product-security and customer-assurance budgets | Cyber, engineering, and compliance users | SBOM generation, VEX support, and software-supply-chain monitoring | Visible proof comes from an unnamed food-and-beverage systems integrator and Platform One cyber messaging | Shows adjacency and demand pull, but name quality is limited |
Public evidence identifies real buyer and user segments, but only some segments have named customer proof; strategic-value language is analytical rather than disclosed revenue mix.
[CU001, CU002, CU003, CU006, CU022, CU028]| Date / stage | Public signal | Value | Source | Confidence | Implication | Missing denominator |
|---|---|---|---|---|---|---|
| 2023-11 | Independent customer-count corroboration | 550 customers served | Craft | Medium | Supports that Exiger already had meaningful commercial breadth before the 2025-2026 federal win cycle | No segment revenue mix or active-account definition |
| 2024-03 | Named enterprise healthcare win | Northwell selected Exiger after using multiple tools and evaluating multiple providers | Exiger / Northwell case study | Medium | Shows Exiger can displace fragmented incumbent workflows inside a large enterprise | No contract value or renewal term |
| 2025-04 | Government procurement expansion | $919M SCRIPTS BPA; highest-ranked unrestricted prime awardee | Exiger / GovCon | High | Moves Exiger from one-off federal wins toward programmatic governmentwide access | No disclosed task-order conversion or realized revenue |
| 2025-10 | Named federal customer expansion | Multi-million-dollar CBP contract | Exiger / WashingtonExec | High | Shows adoption in trade enforcement and customs workflows beyond defense sustainment | No disclosed annual contract value or renewal options |
| 2025-11 | Named defense deployment | Multi-million-dollar Army AMC software contract | Exiger / PR Newswire / HSToday | High | Confirms operational deployment in a marquee defense account | No disclosed rollout timeline by user count |
| 2026-03 | Commercial procurement channel launch | 1Exiger listed in AWS Marketplace | Exiger / AWS Marketplace | High | Shortens commercial buying friction and can widen channel-led expansion | No disclosed marketplace-originated bookings |
| 2026-04 | Additional government-access channel | Platform One awardable status for Exiger Cyber | Exiger / WashingtonExec | Medium | Adds another route into DoD and adjacent government customers | No public conversion data from marketplace views to awards |
This table tracks observable customer and procurement milestones, not recognized revenue. Missing denominators are explicit because Exiger does not disclose bookings mix, customer activity rates, or cohort-level deployment counts.
[CU004, CU006, CU010, CU011, CU012, CU013]Named proof density is overwhelmingly concentrated in government, defense, and a small number of enterprise lighthouse accounts.
Values count retained proof surfaces, not customers, revenue, or share of wallet. The figure is designed to show where named references are strongest and weakest.
[CU003, CU022, CU026, CU027, CU028, CU039]6.2 Named proof and procurement path
The strongest customer proof is public-sector procurement, not generic logo placement. Exiger’s retained corpus includes direct, operationally specific evidence for Army Materiel Command, CBP, Northwell Health, and Oshkosh/JLG. The Army and CBP wins matter because they are not just “strategic partnerships”; they are described as multi-million-dollar software or AI contracts with mission-specific workflows, while the Northwell and Oshkosh cases show enterprise deployments that touched ERP flows, supplier-monitoring processes, technical data packages, and large supplier networks. Procurement access is also unusually visible. Exiger has an OUSD-linked DDIQ contract history, the SCRIPTS BPA, Platform One marketplace exposure, and an AWS Marketplace route meant to reduce commercial friction. That combination suggests a company that can sell through both bespoke federal procurement and workflow-heavy enterprise evaluations. It also implies that customer acquisition is often tied to implementation depth and procurement infrastructure rather than lightweight self-serve software motion.[CU007, CU008, CU009, CU010, CU011, CU012]
| Customer / account | Segment | Deployment / use case | Production vs pilot | Outcome / proof quality | Limitation |
|---|---|---|---|---|---|
| U.S. Army Materiel Command | Federal / defense | 1Exiger software for multi-tier supply-chain illumination, orchestration, and monitoring across sustainment categories | Production deployment / licensed operational software | Named customer, contract scope, integration targets, and mission workflow are all explicit | No public user count, contract term, or renewal structure |
| U.S. Customs and Border Protection | Federal / trade enforcement | Trade AI for illicit transshipment detection and country-of-origin analysis | Production deployment / awarded contract | Named customer and specific enforcement workflow are explicit | No public value of annual recurring spend or expansion path |
| Northwell Health | Healthcare enterprise | Vendor-risk and supply-chain-risk platform with ERP and Service Desk integration | Production enterprise deployment | Named account, buyer pain, competitive evaluation, and integration detail are explicit | No public renewal, savings, or seat-count data |
| Oshkosh / JLG | Industrial manufacturing | SDX/PAC workflow for material visibility, supplier onboarding, and forecasting | Production manufacturing deployment | Named account with quantified operational outcomes and stated cross-business-unit expansion | All public detail is company-hosted; no independent customer case corroboration |
Rows are limited to clearly named external accounts with deployment detail. Anonymized bank, fintech, SBOM, microelectronics, and pharma-government cases are excluded here because they prove repeatability but not named reference quality.
[CU007, CU008, CU009, CU013, CU017, CU018]Exiger wins when a high-consequence buyer moves from compliance or supply-chain pain into a workflow-embedded deployment that is hard to unwind once data, integrations, and monitoring rules are live.
This is a structural journey derived from customer stories and review evidence, not a measured conversion funnel with account counts at each stage.
[CU010, CU015, CU016, CU018, CU019, CU034]Public evidence narrows sharply from broad customer-count claims to a small set of named, operationally specific deployments.
Values mix company-disclosed counts with retained-corpus proof counts. The point is evidence narrowing, not a literal sales conversion funnel.
[CU004, CU005, CU006, CU007, CU008, CU013]6.3 Durability, switching costs, and referenceability
Public durability evidence is directionally positive but incomplete. The best retention proxies are structural: Oshkosh expanded from one business unit into another, the regional-bank client extended Exiger’s engagement beyond the original alert lookback, and Northwell replaced a multi-tool setup with a single Exiger-led ecosystem. Independent sentiment is also better than average for a private vendor. Gartner’s accessible product page shows a meaningful visible review corpus and a favorable manufacturing review that praised implementation support and reduced false positives. But the same page also surfaces a critical review that says the platform can be complex to tune and heavier than needed for simple use cases. That combination matters: Exiger appears most durable when customers need deep workflow integration, not when they want a light monitoring overlay. Public satisfaction and switching-cost signals are therefore real, yet still weaker than a disclosed NRR or renewal cohort. Referenceability is similarly mixed because large sectors, especially financial services, are represented more by anonymous cases than by named customer champions.[CU023, CU024, CU025, CU027, CU029, CU030]
| Metric | Value / signal | Segment | Confidence | Diligence ask |
|---|---|---|---|---|
| Classical retention metrics | Entire customer base | High that disclosure is absent | Request NRR, GRR, logo churn, contract duration, and renewal rate by segment | |
| Independent review corpus | Gartner product page references 69 reviews | Cross-segment product users | Medium | Obtain full review export and segment the feedback by industry and product module |
| Positive implementation / partnership proxy | Visible Jan-2026 favorable Gartner review praises false-positive reduction and exceptional implementation support | Manufacturing reviewer | Medium | Request blind references on implementation support, false-positive reduction, and time-to-value |
| Adverse implementation proxy | Visible May-2026 critical Gartner review says the platform can be complex to implement and tune | Cross-segment product users | Medium | Request onboarding timeline data, escalation rates, and common deployment blockers |
| Observable expansion signal | Oshkosh expanded from Access to Commercial and planned further rollout into Fire & Emergency and Defense | Industrial manufacturing | Medium | Request expansion-revenue bridge and timing of follow-on modules by account |
| Observable repeat / extension signal | Top-10 regional bank extended Exiger for five more months after the initial lookback | Financial services | Medium | Request conversion rates from project-based work into ongoing managed or software subscriptions |
Null means not publicly disclosed, not zero. The table separates visible repeat-usage proxies from the hard retention metrics still missing from the public file.
[CU023, CU029, CU030, CU031, CU032, CU033]Government and named enterprise cases score highest on deployment specificity, while financial-services proof is real but structurally less referenceable because it stays anonymous.
Matrix scores are analytical judgments based on whether the retained public evidence names the account, explains the workflow, and discloses follow-through beyond the initial deployment story.
[CU007, CU017, CU019, CU022, CU028, CU040]6.4 Concentration and diligence risks
The customer-risk picture is less about whether Exiger has customers and more about where the economic weight sits. Public proof strongly suggests defense and government matter disproportionately: the company highlights Army, CBP, federal contract vehicles, Platform One, SCRIPTS, and 60+ government/DIB organizations far more than it discloses enterprise renewal cohorts or top-bank references. That asymmetry creates two diligence risks. First, concentration could be higher than investors expect if public-sector bookings and renewals are a large share of the business. Second, reference inflation is possible because headline customer counts are supported by only a small set of named external accounts in the retained corpus. Financial-services concentration is plausible, but without named Goldman Sachs or JPMorgan proof, it is not underwritten. The sales-cycle implication is also important: long, regulated procurement paths can be sticky once won, but they can also slow net-new growth and make implementations resource intensive. Exiger therefore looks more like a high-touch, workflow-embedded platform vendor than a low-friction horizontal SaaS subscription.[CU026, CU027, CU028, CU033, CU037, CU038]
| Expansion driver / concentration risk | Evidence | Impact | Diligence path |
|---|---|---|---|
| Federal procurement lattice | DDIQ, SCRIPTS, Army, CBP, and Platform One together create multiple paths into government accounts | Positive for expansion; also raises public-sector concentration sensitivity | Request bookings, renewal, and revenue split by federal customer and contract vehicle |
| AWS Marketplace channel | 2026 launch explicitly aims to cut procurement friction for commercial and international customers | Positive for top-of-funnel and channel-led conversion | Request marketplace-originated pipeline, win rate, and average discounting |
| Named bank-reference gap | Financial-services case studies are anonymous and do not support Goldman Sachs or JPMorgan specifically | Adverse for referenceability in a thesis that depends on marquee banks | Request named reference customers or blind calls with large-bank users |
| Reference inflation risk | Customer stories page showcases many themes but only a small number of clearly named external accounts in the retained corpus | Adverse because counts and logos can overstate usable proof | Request a customer-reference matrix sorted by segment, maturity, and outcome specificity |
| Implementation heaviness | Gartner critical review plus Northwell/Oshkosh integration detail imply non-trivial onboarding and workflow tuning | Adverse for sales-cycle length and deployment cost | Request median time-to-go-live, services attach, and implementation FTE burden |
| Embedded-workflow switching cost | ERP/API/PLM/technical-data integration and supplier onboarding make displacement harder once deployed | Positive for durability if customer satisfaction stays high | Request module attach, renewal rates, and migration-loss reasons |
| Segment-mix opacity | Public sources disclose customer counts but not revenue concentration by government, enterprise, or financial services | Adverse because concentration cannot be sized from the public file | Request segment ARR, top-customer share, and public-sector share of renewals |
The same evidence can drive upside and risk. Expansion drivers are visible, but the missing denominator is always economic concentration and renewal behavior.
[CU015, CU027, CU033, CU034, CU035, CU036]6.5 Exhibits
07Risks
7.1 Risk Overview and Prioritization
Exiger’s public risk stack is not dominated by a single existential problem but by a cluster of linked exposures that can compound. The highest-probability commercial risks are competitive bundle pressure from larger platforms, procurement slippage in government and regulated enterprise accounts, and integration drag as multiple acquired data or mapping assets are absorbed into one operating platform. The highest-severity risks are different: a material error in sanctions, export-control, forced-labor, or privacy-sensitive screening can create direct customer liability and reputational damage, while hidden government concentration could make growth look more diversified than it really is. The retained sources also show real mitigation. FedRAMP authorization, a public DPA, contract-vehicle access, AWS Marketplace availability, and sponsor capital all indicate Exiger is not improvising its way through regulated markets. But those same signals show why the file needs caution: federal channels lengthen sales cycles, AI-led claims raise precision expectations, and sponsor ownership makes timing and exit conditions relevant before public metrics are fully disclosed.[CR001, CR003, CR005, CR007, CR012, CR020]
| Risk | Jurisdiction / rule | Current status | Likelihood | Severity | Mitigation | Residual exposure | Diligence path |
|---|---|---|---|---|---|---|---|
| Privacy and controller/processor liability | Exiger DPA + GDPR-linked transfer clauses | Public DPA confirms processor obligations, breach-response process, and regional appendices | Medium | High | Contractual DPA, security safeguards, and jurisdiction-specific appendices | MEDIUM | Verify sub-processor list, breach-notice SLA, and third-party audit pack. |
| Sanctions / export-control screening error | OFAC sanctions lists + BIS EAR / screening resources | Regulator datasets and legal references change over time; customers rely on accurate entity resolution | High | High | Frequent list refreshes, legal-review escalation, and explainable exception handling | HIGH | Request false-positive/false-negative metrics, override workflow, and source-refresh cadence. |
| Forced-labor / UFLPA evidence failure | CBP UFLPA and forced-labor enforcement | Entity-list and origin evidence can create shipment detention or import prohibition | Medium-High | High | Tier-N mapping, provenance trails, and human review for China-linked exposures | HIGH | Review detained-shipment case studies, supplier trace files, and confidence thresholds. |
| Litigation / enforcement visibility gap | Federal court records and paid docket systems | No adverse federal case surfaced in free-web discovery, but authoritative search requires PACER or clerk access | Medium | Medium | Counsel-led quarterly docket scans and management representations | MEDIUM | Run PACER plus key state-court searches before closing; confirm any threatened claims with counsel. |
Partial enumeration of the highest-consequence public legal and regulatory exposures visible in retained 2026 materials; it is not an exhaustive litigation docket or full statutory inventory.
[CR003, CR013, CR014, CR015, CR016, CR017]Likelihood-versus-impact view of Exiger’s most material risks using evidence from government, legal, and integration sources.
Probability and impact ratings are author judgments constrained by retained public evidence; they are not management guidance or incident statistics.
[CR003, CR005, CR007, CR020, CR024, CR026]7.2 Government Concentration, Procurement, and Dependency Risks
Exiger’s public-sector credibility is simultaneously a moat and a concentration risk. The evidence set shows a meaningful federal footprint: FedRAMP Moderate authorization, contract-vehicle access, Carahsoft channel distribution, and a multi-million Army Materiel Command deployment. That profile should help Exiger win in defense, public-sector, and critical-supply-chain use cases, but it also means a non-trivial portion of pipeline quality is likely tied to budget timing, task-order mechanics, contracting officers, reseller throughput, and compliance sign-off. AWS Marketplace improves discoverability and may shorten some buying steps, yet it does not convert Exiger into a frictionless self-serve product. SAM.gov and USAspending both reinforce that federal procurement remains a formal, searchable, multi-step process. The underwriting problem is that none of the retained public sources disclose what share of revenue, bookings, or retention comes from public-sector or government-adjacent customers. That pushes the probability of concentration risk into the medium-to-high range even without proof of a current problem, because investors can verify footprint but not revenue mix. Any slowdown in agency budgets, reseller execution, or contracting throughput would transmit first into bookings timing and then into valuation.[CR001, CR002, CR005, CR006, CR007, CR009]
| Dependency | Counterparty / concentration | Role | Failure scenario | Severity | Mitigation | Residual exposure |
|---|---|---|---|---|---|---|
| Federal agencies / DIB customers | Army, agency buyers, public-sector accounts | Anchor customers and reference set for national-security and regulated use cases | Budget delays, task-order slippage, or agency concentration weakens bookings quality | HIGH | Commercial customer mix, AWS procurement route, and broader enterprise base | HIGH |
| Contract-vehicle and reseller ecosystem | GSA-assisted vehicle + Carahsoft | Enables procurement access and buying convenience for government customers | Vehicle change, reseller underperformance, or contracting bottlenecks stall deals | MEDIUM-HIGH | Maintain direct relationships and multiple procurement paths | MEDIUM-HIGH |
| Cloud procurement / marketplace route | AWS Marketplace and related cloud procurement motions | Improves discoverability and may shorten some purchase steps | Marketplace presence fails to translate into materially faster close times or favorable economics | MEDIUM | Use marketplace as a channel, not the only route to close | MEDIUM |
| Regulatory data and rules inputs | OFAC, BIS, CBP and related legal resources | Reference layer for sanctions, export-control, and forced-labor use cases | Stale rules, broken mappings, or poor provenance undermine product trust and customer compliance | HIGH | Frequent refreshes, legal-review escalation, and source governance | HIGH |
This register focuses on external dependencies that can slow revenue conversion or amplify customer-liability risk even when product demand remains intact.
[CR001, CR003, CR005, CR006, CR007, CR009]Map of the external channels, regulators, and acquired assets that sit between Exiger’s platform and realized revenue.
The map shows structural dependencies evidenced in public materials; it does not imply exclusivity or quantify contractual exposure.
[CR003, CR005, CR006, CR007, CR011, CR024]7.3 AI/Data Accuracy, Compliance, Cyber, and Geopolitical Risks
This is the chapter’s core skeptical lens. Exiger markets predictive, AI-enabled mapping and risk detection, which is commercially powerful but also raises the cost of being wrong. The public DPA allocates some responsibility back to customers by requiring them to provide accurate data, yet Exiger still accepts processor, security, sub-processor, and breach-response obligations. That means contractual drafting does not eliminate operational liability. The regulatory stack that customers rely on is also dynamic rather than static. OFAC distributes continuously updated sanctions datasets, BIS pushes exporters toward EAR and screening resources while warning users to confirm legal research against official publications, and CBP’s UFLPA regime can detain shipments based on entity-list and origin evidence. In other words, Exiger’s value proposition depends on handling data that changes, crosses jurisdictions, and can become legally consequential when stale or incomplete. Add FTC privacy expectations, GDPR obligations, the AI Act’s staged compliance timeline, and rising cyber or product-assurance scrutiny, and the result is a business where model quality, entity resolution, source provenance, and security controls deserve the same diligence weight as top-line growth.[CR013, CR014, CR015, CR016, CR017, CR018]
| Failure mode | Likelihood | Severity | Mitigation maturity | Residual exposure | Unresolved gap |
|---|---|---|---|---|---|
| AI/entity-resolution false positives or false negatives in screening and mapping outputs | High | High | Medium — public AI positioning exists, but quality metrics are undisclosed | HIGH | No public precision, recall, or exception-rate evidence. |
| Cyber/privacy incident affecting customer or third-party data | Medium | High | Medium — FedRAMP and DPA safeguards exist, but incident history and broader control stack are private | MEDIUM-HIGH | No public incident log, SOC report, or detailed control evidence beyond retained materials. |
| Procurement-cycle slippage in regulated or federal accounts | High | Medium-High | Medium — AWS Marketplace and contract vehicles help, but multi-step buying remains visible | HIGH | No public data on cycle length, conversion, or task-order timing. |
| Integration regressions across Supply Dynamics, XSB, and Versed AI assets | Medium-High | High | Low-Medium — acquisitions are public, but integration milestones and overlap costs are undisclosed | HIGH | No public integration roadmap, SKU rationalization, or post-acquisition churn metrics. |
Ratings emphasize operational failure modes where public positioning is strong but precision, incident, or integration metrics are still private.
[CR007, CR008, CR020, CR021, CR022, CR023]Directed map showing how concentration, accuracy, integration, and exit risks flow into bookings quality, compliance cost, and valuation pressure.
Edges represent likely causal pathways based on the retained evidence set; they are directional rather than quantified elasticities.
[CR020, CR022, CR024, CR026, CR032, CR042]7.4 Acquisition Integration, Sponsor Ownership, and Exit Risks
Exiger’s acquisition history strengthens the product story but complicates execution. Supply Dynamics added item-level visibility and multi-tier mapping, XSB added large parts and attributes data sets, and Versed AI added product-breakdown and multi-tier visibility tooling. Each asset helps the platform become more defensible, but each also creates integration, roadmap, and go-to-market harmonization work that the public file does not quantify. Sponsor ownership adds another layer. Carlyle and Insight’s majority investment is strategically supportive, yet it also means exit discipline matters before investors have public visibility into concentration, margins, or quality metrics. The SEC’s 2026 offering-reform proposal is useful context here: if regulators are still trying to simplify the path to public-market issuance, the practical message is that exit windows remain sensitive to disclosure quality and market structure. Legal diligence has a similar shape. No adverse federal case surfaced in the free-web search pack, but PACER and clerk-office checks remain the authoritative route. The right mitigation posture is therefore escalation-driven: treat concentration, accuracy, cyber, integration, and sponsor-timing signals as board-level or investment-committee triggers rather than background noise.[CR012, CR024, CR025, CR026, CR027, CR028]
| Role / function | Dependency or gap | Likelihood | Severity | Mitigation | Diligence path |
|---|---|---|---|---|---|
| Sponsor-governed growth planning | Majority ownership by Carlyle and Insight can sharpen growth and exit expectations | Medium | High | Deep-capital sponsors and management rollover reduce near-term financing stress | Ask for board cadence, sponsor hold horizon, and financing trigger framework. |
| Product and data integration leadership | Three acquisitions add different data, mapping, and workflow layers that must be harmonized | Medium-High | High | Prior integration announcements and shared supply-chain focus | Request post-merger roadmap, SKU rationalization, and platform consolidation milestones. |
| Security/privacy/compliance operations depth | Public file shows DPA and FedRAMP but not the full operating bench behind them | Medium | Medium-High | Formal legal and security documents exist | Request org chart for CISO, privacy, product-risk, and legal operations ownership. |
| Federal sales and program execution bandwidth | Visible federal footprint can create servicing complexity beyond logo counts | Medium | Medium-High | Carahsoft, contract vehicles, and Army proof indicate some scale | Request pipeline mix, program staffing ratios, and service-level metrics for public-sector accounts. |
Execution risk is less about founder charisma and more about whether sponsor-backed growth, compliance operations, and acquired product lines are being integrated at the same speed.
[CR005, CR006, CR011, CR012, CR024, CR025]| Risk | Monitorable trigger | Threshold / event | Escalation path | Action implication |
|---|---|---|---|---|
| Government concentration / procurement delay | Federal bookings mix, slipped task orders, delayed agency conversions | >35% of new bookings tied to top three public-sector accounts or two consecutive quarters of material slippage | CRO -> CFO -> board -> investment committee | Lower growth assumptions, demand concentration disclosure, or pause conviction until mix is transparent. |
| AI / data accuracy liability | Customer escalation volume, adverse audit results, regulator inquiry | Any material enforcement inquiry or more than one major customer challenge to screening accuracy | CPO / CISO / GC -> CEO -> investment committee | Require QA metrics, indemnity posture, and remediation evidence before underwriting premium multiples. |
| Acquisition integration drag | Missed integration milestones, duplicated SKUs, release regressions | Two missed roadmap milestones or a major rollback tied to acquired capability integration | CTO / COO -> CEO -> board | Haircut synergy assumptions and increase execution discount in valuation. |
| Cyber/privacy control failure | Notifiable breach, FedRAMP impairment, DPA breach notice | Any customer-notifiable incident or change in FedRAMP standing | CISO / GC / CEO -> board -> investment committee | Stop process until RCA, remediation plan, and customer impact assessment are complete. |
| Public-market / sponsor exit risk | Recap activity, financing delay, or weak public issue conditions | Sponsor-led liquidity action before disclosure readiness or soft growth into financing window | CFO / board -> investment committee | Widen required return, favor structured terms, or avoid if disclosure remains opaque. |
Kill criteria are framed as monitorable events rather than broad concerns so the chapter distinguishes probability, severity, mitigation, and escalation responsibility.
[CR007, CR012, CR037, CR038, CR042, CR043]08Valuation
8.1 Price Support Versus Disclosure Quality
The public record establishes that Carlyle and Insight bought into Exiger in late 2023 and that independent deal coverage put the valuation at about $1.2 billion, but the official sponsor and company releases still do not disclose the price, ownership split, leverage, or preference structure. That matters because the most important denominator is still a third-party-reported management claim: Forbes wrote in March 2024 that Exiger expected revenue to exceed $150 million by the end of 2024 and had compounded above 80% annually over the prior five years. Against that floor, the reported $1.2 billion value implies about 8.0x revenue, which is not obviously unreasonable for a differentiated risk-data platform but is clearly not cheap either. The 2026 AWS and Hackett materials strengthen the quality story by showing 550+ customers, 150 Fortune 500 relationships, 60+ government and Defense Industrial Base organizations, and procurement relevance. But they still leave ARR, gross margin, retention, services mix, cash-flow profile, and public-sector concentration unreported. So the core valuation judgment is evidence-sensitive rather than company-quality-sensitive: Exiger may deserve a premium mark, but the current public file does not prove it.[CV001, CV003, CV004, CV005, CV006, CV007]
| Frame | Recommendation | Confidence | Risk rating | Valuation stance | Decision implication |
|---|---|---|---|---|---|
| Current public-file view | research-more | Medium | High | Stretched | Do not underwrite the reported $1.2B mark without a management package on current revenue, mix, margin, retention, and sponsor terms. |
| Upgrade condition | track-to-buy | Medium | Medium | Fair | A better view requires current revenue materially above the 2024 floor plus software-like unit economics and manageable government concentration. |
This summary is price-sensitive rather than company-quality-sensitive; the recommendation can improve if denominator and economics evidence improves.
[CV031, CV032, CV040, CV041, CV042, CV046]| Frame | Evidence | Why it supports or pressures $1.2B | What would change the view |
|---|---|---|---|
| Thesis | 550+ customers, 150 Fortune 500 relationships, and 60+ government and DIB organizations in 2026 materials | Scale is real enough that Exiger is not a concept-stage AI story. | Show paying-customer definition, logo retention, and revenue concentration by top accounts. |
| Thesis | AWS Marketplace launch and Hackett recognition reinforce procurement relevance and product maturity | Premium positioning is easier to defend when the platform is becoming easier to buy and is analyst-recognized. | Show how much of pipeline or bookings now flow through channels and how recognition maps to ACV expansion. |
| Thesis | Forbes-reported >$150M revenue floor and >80% five-year CAGR imply meaningful historic compounding | If current revenue is already far above that floor, the entry multiple can compress into a more supportable range. | Provide audited 2025 and TTM revenue plus ARR bridge. |
| Anti-thesis | Official sources still do not disclose valuation, ARR, gross margin, NRR, services mix, burn, or sponsor terms | Premium multiples without premium disclosure raise underwriting error risk. | Release a management data pack with current economics and cap-table terms. |
| Anti-thesis | Exiger's implied 8.0x floor multiple is already above D&B, NICE, and TransUnion and near Verisk | The price assumes premium quality before the public record proves premium economics. | Prove that Exiger's current revenue and margins sit much closer to premium analytics peers than to lower-band workflow vendors. |
| Anti-thesis | Government footprint is clearly large, but public-sector revenue concentration is still unquantified | Federal strength can be a moat, but it can also amplify budget, procurement, and renewal volatility. | Provide public-sector share of ARR, bookings, gross profit, and top-program renewal schedule. |
Thesis rows isolate what helps the valuation case; anti-thesis rows isolate what can break it. The table intentionally separates business quality from valuation support.
[CV006, CV007, CV008, CV009, CV010, CV012]Exiger's public valuation case is a chain in which real scale and category proof are partially offset by economics opacity and a higher 2026 exit hurdle.
This figure is decision logic, not a process map; it visualizes the evidence chain that moves the recommendation from investable company to conditional valuation support.
[CV006, CV007, CV009, CV010, CV012, CV013]Exiger scores well on market need and proof, but poorly on the public evidence quality required to defend a premium valuation.
These are underwriting-readiness scores synthesized from retained public evidence, not management or board metrics.
[CV009, CV010, CV031, CV039, CV040, CV041]8.2 Public and Private Comparable Frame
Public comps provide a usable range, but they are imperfect and should be read as valuation anchors rather than literal peers. Dun & Bradstreet, NICE, and TransUnion sit in the lower band of adjacent data or workflow vendors at roughly 1.7x to 3.0x trailing revenue on public market-cap-to-revenue proxies. Verisk and Moody's occupy the premium end at roughly 7.8x and 10.1x respectively, reflecting stronger disclosure, high-margin analytics economics, and more mature data-network advantages. Exiger's implied 8.0x floor multiple therefore lands much closer to premium analytics names than to the lower-growth or workflow-heavy names. That can be defensible only if current revenue is already comfortably above the 2024 floor and if Exiger's economics look more like scaled software and analytics than like a services-heavy compliance platform. Private and M&A references reinforce strategic appetite for intelligence assets, but they do not cleanly solve valuation support. Chainalysis reached an $8.6 billion valuation, Interos crossed $1 billion, Sayari attracted a $235 million strategic majority investment, and Mastercard agreed to buy Recorded Future for $2.65 billion. Those examples show sponsor and strategic demand for networked risk-data assets, but each sits in a different end market, disclosure regime, and margin profile. The comp set is therefore helpful, but only with explicit caveats.[CV016, CV017, CV018, CV019, CV020, CV021]
| Comparable | Public/private status | Revenue or valuation metric | Implied multiple / valuation / status | Relevance to Exiger | Key limitation |
|---|---|---|---|---|---|
| Dun & Bradstreet | Public through Aug. 2025 take-private | $4.08B last known market cap on $2.40B TTM revenue | ~1.7x market-cap / revenue proxy | Large-scale risk and business-data platform provides a lower-growth floor for data-analytics valuation. | Mature, slower-growth asset with different margin and services profile; take-private mechanics are not identical to a sponsor growth deal. |
| NICE | Public | $5.58B market cap on $2.94B TTM revenue | ~1.9x market-cap / revenue proxy | Adjacent workflow and compliance software vendor illustrates lower-band workflow pricing. | Customer-experience and contact-center exposure makes it only partially comparable. |
| TransUnion | Public | $14.06B market cap on $4.72B TTM revenue | ~3.0x market-cap / revenue proxy | Scaled data and risk decisioning vendor offers a middle-band public benchmark. | Credit-bureau economics and consumer-data mix differ from Exiger's supply-chain workflow orientation. |
| Verisk | Public | $24.06B market cap on $3.10B TTM revenue | ~7.8x market-cap / revenue proxy | Premium analytics and risk-data company is the clearest public premium-end analogue. | Stronger disclosure, margin quality, and insurance-data history likely deserve a premium versus Exiger today. |
| Moody's | Public | $79.76B market cap on $7.87B TTM revenue | ~10.1x market-cap / revenue proxy | Demonstrates what markets pay for elite information-services economics and durable data moats. | Ratings and benchmark data are structurally more entrenched and profitable than Exiger's current disclosed profile. |
| Chainalysis | Private | $170M Series F financing | $8.6B valuation in 2022 | Shows investor appetite for compliance-heavy data platforms with government and financial-institution relevance. | Crypto exposure, category heat, and different customer mix make the valuation non-transferable without a discount. |
| Interos | Private | $100M Series C financing | >$1B valuation in 2021 | Useful supply-chain-risk adjacency for a graph-centric resilience platform. | Dated, smaller scale, and no retained public revenue disclosure. |
| Sayari | Private | $235M strategic majority investment from TPG | Valuation undisclosed in retained public release | Confirms sponsor appetite for government-linked counterparty and supply-chain risk intelligence. | No public valuation or revenue denominator in the retained materials. |
| Recorded Future | M&A | Mastercard acquisition announcement | $2.65B agreed acquisition value in 2024 | Demonstrates strategic willingness to pay for scaled intelligence assets with government and enterprise relevance. | Cyber threat-intelligence end market and undisclosed retained revenue limit direct multiple transfer. |
Public company rows use simple market-cap-to-trailing-revenue proxies from retained market-data pages, not fully adjusted enterprise values. Private and M&A rows are included as strategic reference points even when retained public sources do not disclose revenue.
[CV016, CV017, CV018, CV019, CV020, CV021]8.3 Bull, Base, Bear, and Exit Math
The scenario work argues for discipline. In the bull case, Exiger is already materially above the reported 2024 revenue floor, sustains software-led growth, shows strong retention, and exits into a market that still pays premium analytics multiples for defensible risk data. That can produce a sponsor-acceptable 2x-plus outcome. In the base case, however, Exiger grows well enough to be valuable but not well enough to overcome today's entry price with robust excess return; a mid-single-digit exit multiple on a sub-$300 million revenue base only produces a modest uplift over the reported mark. In the bear case, a combination of public-sector concentration, acquisition-integration drag, services mix, or multiple compression can leave the company worth below cost. The 2026 private-equity exit backdrop raises the hurdle further, because buyers are more selective, software multiples have compressed versus peak years, and longer hold periods reduce sponsor IRR even when gross MOIC remains positive. Put simply, Exiger does not need to be a bad business for the valuation to disappoint; it only needs to be a good business that is not quite premium enough.[CV031, CV032, CV033, CV034, CV039, CV042]
| Case | Revenue assumption (USD M) | Exit multiple | Exit value (USD M) | Gross MOIC vs. $1.2B | Probability signal / trigger |
|---|---|---|---|---|---|
| Bull | 350 | 7.5x | 2625 | 2.2x | Current revenue is already >$200M, software mix and retention are strong, and the exit market still pays premium analytics multiples. |
| Base | 275 | 5.5x | 1513 | 1.3x | Revenue compounds, but disclosed economics land in the solid-not-elite range and buyer discipline caps multiple expansion. |
| Bear | 200 | 3.5x | 700 | 0.6x | Government concentration, services mix, or integration drag meet a selective exit market and multiple compression persists. |
Scenario math is illustrative and uses gross enterprise-value-style output against the reported $1.2B valuation reference. It does not model leverage, dilution, earn-outs, taxes, or exact sponsor hold periods.
[CV031, CV032, CV039, CV042, CV043, CV044]The biggest underwriting sensitivities are denominator and mix, not top-of-funnel demand.
Bars are ordinal 0-10 sensitivity scores synthesized from the retained evidence set. They show which missing facts move valuation most, not measured operating KPIs.
[CV031, CV032, CV039, CV040, CV041, CV046]Sponsor return math becomes acceptable only if Exiger exits from a meaningfully larger revenue base and still holds a premium multiple.
Ranges are illustrative exit-value bands tied to the bull, base, and bear cases rather than point estimates. They are meant to show how little room there is for error around a $1.2B starting point.
[CV031, CV032, CV042, CV043, CV044, CV045]8.4 Decision, Kill Triggers, and Final Diligence
The right call on the public record is research-more rather than buy. Exiger has enough scale, sponsor quality, and category relevance to stay investable, but not enough disclosed economics to underwrite a $1.2 billion entry with conviction. The cleanest anti-thesis is not that demand is fake; it is that valuation support depends on opaque private revenue, unknown software-versus- services mix, unclear government concentration, and sponsor ownership dynamics that remain hidden from the public file. That means the diligence plan should focus less on broad market validation and more on denominator proof: current TTM revenue, ARR, growth by segment, gross margin, NRR, federal concentration, customer concentration, and exact sponsor terms. Kill triggers are also concrete. If current revenue is still near the 2024 floor, if public-sector revenue is highly concentrated, if services make up a meaningful share of gross profit, or if the capital structure gives new money limited upside, the valuation quickly looks stretched. If the company can instead prove materially higher current revenue, premium software-like economics, and a credible strategic or IPO path, the same public evidence can move from stretched to fair.[CV040, CV041, CV042, CV043, CV044, CV045]
| Trigger | Threshold / event | Transmission to thesis | Action implication |
|---|---|---|---|
| Revenue denominator disappoints | Current TTM revenue is still near the >$150M 2024 floor | The reported $1.2B mark stays near an 8x floor multiple rather than compressing into a fairer range. | Treat valuation as stretched and require repricing or a stronger structured upside case. |
| Software mix disappoints | Services or analyst-led support account for a material share of gross profit | Exiger starts to look more like a tech-enabled services platform than a premium analytics platform. | Lower the comparable band toward workflow or services-heavy vendors. |
| Government concentration is high | Public sector or a few federal programs make up a large share of ARR or gross profit | Renewal volatility and procurement timing become first-order valuation drivers. | Apply concentration discount and require contract-level renewal visibility. |
| Sponsor terms cap upside | Leverage, liquidation preferences, or ownership structure skew economics away from new-money equity | Gross enterprise value can look acceptable while equity returns still disappoint. | Rework return math on a fully diluted equity basis before advancing. |
| Exit market remains selective | Buyers still prefer profitability and discount generic growth in 2026-2027 | Even a solid business can miss sponsor return targets if exit multiples stay compressed. | Underwrite longer hold periods and a lower exit multiple range. |
Kill triggers focus on valuation transmission rather than operating noise; each one can break return math without disproving that Exiger has a relevant product.
[CV031, CV039, CV040, CV041, CV044, CV045]| Topic | Missing evidence | Why it matters | Owner / diligence path |
|---|---|---|---|
| Current revenue and ARR | Audited 2025 revenue, current TTM revenue, current ARR, and segment bridge | This is the denominator for every valuation and return conclusion. | CFO pack and quality-of-revenue bridge. |
| Gross margin and software mix | Gross margin by segment plus software versus services revenue and gross profit mix | Determines whether premium analytics comps are appropriate. | Finance diligence and product-line P&L review. |
| Retention and concentration | Gross and net retention, top-20 customer concentration, and public-sector concentration | Clarifies durability and whether government depth is moat or concentration risk. | Revenue-operations pack and cohort analysis. |
| Sponsor terms and cap table | Entry valuation, ownership split, leverage, liquidation preferences, and employee option overhang | Gross value support can still fail to produce acceptable equity returns. | Legal and cap-table diligence with sponsor side letter review. |
| Acquisition integration | Revenue retention and synergy realization for Supply Dynamics, XSB, and Versed AI | Integration success determines whether scale translates into durable economics. | M&A diligence with acquired product and customer bridge. |
| Exit path evidence | Strategic-buyer map, IPO readiness view, and likely buyer objections | Sponsor return expectations depend on a credible liquidity path, not just growth. | Board materials, banker perspectives, and buyer-call plan. |
Each ask is aimed at moving a valuation decision, not just enriching the narrative. The public record is already strong enough on market relevance and weak exactly where underwriting needs precision.
[CV040, CV041, CV042, CV043, CV045, CV046]8.5 Exhibits
Disclaimer
Analysis is based on publicly accessible materials retrieved as of 2026-07-01; undisclosed private-company financial and governance information materially limits precision.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Current official and independent profile materials consistently date Exiger to 2013. | High | SO002, SO012, SO026 |
| CO002 | Reviewed official materials identify Michael Cherkasky and Michael Beber as Exiger’s co-founders. | High | SO008, SO011, SO012 |
| CO003 | Reviewed sources do not support Brandon Daniels as a 2013 co-founder; they instead show that he joined Exiger in early 2017 and became CEO in 2022. | Medium | SO003, SO012, SO026 |
| CO004 | McLean, Virginia is the most supportable headquarters reference in public materials, although some third-party metadata uses broader or inconsistent labels. | Medium | SO008, SO026, SO031 |
| CO005 | Exiger’s roots were in regulatory, financial crime, due-diligence, and broader risk-and-compliance services for banks, corporations, and government agencies. | High | SO011, SO016, SO021 |
| CO006 | DDIQ was one of Exiger’s signature early regtech products for KYC, AML, and due-diligence workflows. | High | SO011, SO016, SO018, SO012 |
| CO007 | By September 2023 Exiger had repositioned its portfolio around 1Exiger, which unified DDIQ, Insight 3PM, Ion Channel, SDX, and Supply Chain Explorer into one platform. | Medium | SO007 |
| CO008 | Current product pages present Exiger primarily as an AI-native 1ExigerAI, supply-chain, risk-and-compliance, and software-supply-chain platform rather than as a long list of standalone legacy tools. | High | SO001, SO004, SO005, SO006 |
| CO009 | OpenCorporates says over a million DDIQ reports have been driven in part by its data and that the workflow helped cut false positives by more than 80 percent. | Medium | SO016 |
| CO010 | Daniels’ profile and current publicity position him as Exiger’s CEO and public face for AI-led growth and government expansion. | Medium | SO003, SO025, SO026 |
| CO011 | Publicly visible non-founder leaders include Carrie Wibben, Cameron Holt, and Eli Cherkasky across president, government solutions, and operations roles. | Medium | SO014, SO028, SO032 |
| CO012 | Exiger disclosed an $80 million minority growth investment from Carrick Capital Partners in July 2018 to scale its compliance technology and regtech products. | Medium | SO011 |
| CO013 | On December 19, 2023 Exiger announced a majority investment from Carlyle and Insight Partners, with management, founders, and Carrick reinvesting equity. | High | SO008, SO009 |
| CO014 | Independent coverage later described the 2023 Carlyle/Insight transaction as valuing Exiger at about $1.2 billion. | Medium | SO022, SO030 |
| CO015 | Reviewed public materials do not disclose the exact 2023 investment amount, the primary-versus-secondary mix, or the current post-deal ownership split. | Medium | SO008, SO009, SO010 |
| CO016 | Current company-reported scale claims cluster around 550+ global customers, 150 Fortune 500 customers, and 60+ government or Defense Industrial Base organizations. | High | SO004, SO023, SO025, SO029 |
| CO017 | Exiger’s current about page says the company has more than 850 employees across 10 global offices. | Medium | SO002 |
| CO018 | Independent and review sources triangulate headcount into an approximate 850-1000 range: Forbes reported 870 employees in 2024, Gartner lists 501-1000 employees, and Aerospace Defense Review says nearly 1,000. | Medium | SO022, SO030, SO031 |
| CO019 | Forbes reported that Daniels expected Exiger to exceed $150 million of revenue by the end of 2024, but that source does not establish ARR. | Medium | SO022 |
| CO020 | Exiger markets 1ExigerAI as an AI-native platform that combines intelligence, decision support, and execution across risk, compliance, procurement, and supply-chain operations. | High | SO001, SO006 |
| CO021 | Exiger says its supply-chain knowledge asset includes 10 billion supply-chain records, 400 million part attributes, and 6.5 million mapped relationships across 200+ countries. | Medium | SO004 |
| CO022 | Exiger says it reinvests more than 30 percent of annual revenue into generating proprietary, product-aware data. | Medium | SO004 |
| CO023 | The July 2024 Versed AI acquisition added automated bill-of-material mapping and multi-tier visibility from a Cambridge University spinout. | Medium | SO013 |
| CO024 | The August 2024 XSB acquisition added logistics, design, sustainment, and parts-intelligence data used across government platforms and combatant commands. | Medium | SO014 |
| CO025 | Exiger’s 2025 U.S. Army contract licensed 1Exiger to Army Materiel Command for multi-tier illumination, orchestration, and monitoring across major sustainment categories. | High | SO015, SO023, SO024 |
| CO026 | WashingtonExec reported that Exiger later earned Awardable status on the Platform One Solutions Marketplace, expanding direct procurement access for Defense Department buyers to Exiger Cyber capabilities. | Medium | SO027 |
| CO027 | Federal News Network reported that Exiger had also deepened software-supply-chain security through its Ion Channel acquisition and broader SaaS-based SCRM push inside government. | Medium | SO028 |
| CO028 | Named customer proof is public in both enterprise and financial services: Oshkosh used SDX to normalize 40,000+ parts and improve forecasting by 10-20 percent, while SMBC selected DDIQ for KYC and AML onboarding and monitoring. | Medium | SO017, SO018 |
| CO029 | Additional public case studies show Exiger supporting anonymized Fortune 500, top-10 U.S. regional bank, and major investment bank workflows, reinforcing big-bank and enterprise penetration even when client names are withheld. | Medium | SO019, SO020, SO021 |
| CO030 | The Exiger page whose slug references Goldman Sachs resolves to a generic major-investment-bank case study rather than a direct customer announcement, so it does not prove Goldman Sachs is a current named customer. | Medium | SO033 |
| CO031 | Exiger’s banking and compliance roots still surface in current positioning through due-diligence, KYC, supplier-risk, trade-compliance, and third-party-risk offerings on the same platform. | High | SO005, SO006, SO007, SO018 |
| CO032 | Reviewed public materials after the 2023 majority investment do not provide a current board roster or detailed governance rights, leaving control and oversight structure publicly opaque. | Medium | SO008, SO009, SO010, SO012 |
| CO033 | Exiger presents itself as the largest provider of supply-chain technology to the U.S. federal government and says its software is deployed across 60+ U.S. government agencies. | Medium | SO004, SO023, SO025 |
| CO034 | The company’s public narrative explicitly spans corporations, banks, government agencies, and defense-industrial-base organizations, illustrating a move from pure diligence/compliance work into broader procurement and supply-chain execution. | High | SO001, SO008, SO025 |
| CO035 | Current public metrics are still mostly company-reported rather than audited, which makes customer count, employee count, and revenue quality harder to verify independently. | Medium | SO022, SO025, SO030, SO031 |
| CO036 | Gartner Peer Insights shows at least one critical 2026 review calling 1Exiger strong on visibility but challenging to tune for workflows, signaling real implementation friction beneath otherwise positive ratings. | Medium | SO031 |
| CO037 | The 2022 CEO transition formally moved day-to-day leadership from co-founder Mike Cherkasky to Brandon Daniels while keeping founder influence in governance and related operating entities. | Medium | SO012 |
| CO038 | By 2026 public messaging emphasizes AI-native decisioning, agentic workflows, and supply-chain execution rather than only due-diligence report automation. | Medium | SO004, SO006, SO032 |
| CO039 | Public milestone evidence supports a clear progression from compliance regtech in the late 2010s to platform integration in 2023, data-led acquisitions in 2024, and deeper federal deployment in 2025-2026. | High | SO011, SO007, SO013, SO014, SO015, SO027 |
| CO040 | Exact ARR, exact post-2023 ownership, and the present branding status of ORCA and WorldCompliance remain the main unresolved company-overview diligence gaps. | Medium | SO005, SO006, SO008, SO009 |
| CM001 | Exiger says its platform unifies supplier, product, part, component, and risk data across both physical and software supply chains. | High | SM001, SM006 |
| CM002 | Exiger markets 1Exiger as a combined risk-and-compliance platform covering trade compliance, supplier risk management, enhanced due diligence, third-party risk management, and know-your-customer workflows. | High | SM004, SM009 |
| CM003 | Exiger’s TPRM offer emphasizes automated onboarding and offboarding, conditional workflows, precise risk assessments, and issue remediation across global third parties. | Medium | SM003 |
| CM004 | Exiger’s supply-chain materials argue that hidden dependencies and part-level exposure matter more than simple entity scores in high-stakes supplier decisions. | Medium | SM002 |
| CM005 | Exiger’s software supply-chain-security boundary includes upstream provenance, SBOMs, components, and suppliers across IT, OT, firmware, and open source. | High | SM001, SM006 |
| CM006 | Exiger’s defense pages position defense agencies and DIB participants as buyers for real-time mapping, risk illumination, compliance support, and adversarial-supplier reduction. | High | SM007, SM008 |
| CM007 | Exiger’s financial-institutions page places the product inside KYC or third-party onboarding, sanctions screening, investigations, risk assessments, transaction monitoring, and cyber-related supply-chain controls. | High | SM009, SM004 |
| CM008 | The included market boundary is the overlap among supplier risk intelligence, sanctions or trade screening, multi-tier supply-chain mapping, and software provenance rather than generic ERP, payments, or standalone cybersecurity tools. | Medium | SM001, SM004, SM006, SM009 |
| CM009 | Dun & Bradstreet says poor or disconnected third-party data creates incomplete risk views and higher compliance exposure, making data harmonization a real implementation constraint. | Medium | SM031 |
| CM010 | Polaris defines TPRM as structured onboarding, risk assessment, due diligence, monitoring, and mitigation across vendors, suppliers, and partners. | Medium | SM021 |
| CM011 | Research and Markets values the global TPRM market at USD 8.09 billion in 2026. | Medium | SM020 |
| CM012 | Polaris values the global TPRM market at USD 9.34 billion in 2026 after reporting USD 8.09 billion in 2025. | Medium | SM021 |
| CM013 | Grand View’s retained lens puts the TPRM market at USD 7.42 billion in 2023 and USD 20.59 billion by 2030, while North America held more than 38% share in 2023. | Medium | SM022 |
| CM014 | Polaris says BFSI held the largest TPRM share in 2025, supporting finance as a core buyer vertical for Exiger-like workflows. | Medium | SM021 |
| CM015 | The Business Research Company estimates the supply-chain risk management market at USD 3.73 billion in 2026. | Medium | SM023 |
| CM016 | Fortune Business Insights estimates the supply-chain risk management market at USD 5.85 billion in 2026. | Medium | SM024 |
| CM017 | Coherent Market Insights estimates the supply-chain risk management market at USD 6.9126 billion in 2026. | Medium | SM025 |
| CM018 | The retained SCRM estimates span from USD 3.73 billion to USD 6.91 billion in 2026, so the public record is better treated as a range than a single TAM point. | Medium | SM023, SM024, SM025 |
| CM019 | Industry Research sizes software-only sanctions screening at USD 586.71 million in 2026. | Low | SM026 |
| CM020 | GII and Stratistics MRC size broader sanctions-screening solutions at USD 4.2 billion in 2026. | Medium | SM027 |
| CM021 | The sanctions-screening category changes dramatically with scope, because software-only and broader end-to-end solutions estimates differ by roughly seven times in the retained 2026 sources. | Medium | SM026, SM027 |
| CM022 | CMMC Phase 1 runs from November 10, 2025 through November 9, 2026 and focuses primarily on Level 1 and Level 2 self-assessments. | High | SM010, SM030 |
| CM023 | DFARS 252.204-7021 makes CMMC level requirements part of contract language for covered defense contractors and subcontractors. | High | SM011, SM030 |
| CM024 | UFLPA creates a rebuttable presumption against goods made wholly or partly in Xinjiang or by entities on the UFLPA Entity List. | High | SM012, SM013 |
| CM025 | CBP’s 2026 UFLPA dashboard update adds shipment count versus value, HTS-4 commodity detail, broader country-of-origin visibility, and a clarified transaction-level shipment definition. | High | SM012, SM013 |
| CM026 | Troutman reports that CBP had reviewed more than 18,000 shipments worth about USD 3.81 billion by early 2026 and that only about 6.5% of FY2025 UFLPA-stopped shipments were released. | Medium | SM028 |
| CM027 | OFAC’s sanctions-program page shows active country and thematic programs with update dates extending through 2026, supporting the need for continuous rather than static screening. | Medium | SM018 |
| CM028 | BIS Entity List controls add export-control screening obligations that matter alongside sanctions screening for defense and industrial supply chains. | Medium | SM019 |
| CM029 | EO 14017 states that the United States needs resilient, diverse, and secure supply chains for economic prosperity and national security. | Medium | SM014 |
| CM030 | EO 14017 explicitly requires a defense-industrial-base supply-chain assessment and names single-point-of-failure suppliers, digital-product risks, and forced-labor risks as issues to review. | Medium | SM014 |
| CM031 | NIST’s CHIPS page frames semiconductors as integral to economic and national security and essential to virtually all military systems, extending supply-chain visibility demand into upstream component provenance. | High | SM015, SM014 |
| CM032 | DoD’s first defense industrial strategy centers resilient supply chains, flexible acquisition, supplier diversification, stockpiles, and cyber-risk response as long-term priorities. | High | SM016, SM017 |
| CM033 | GAO says DoD estimates that over 200,000 suppliers help produce advanced weapon systems and noncombat goods. | Medium | SM017 |
| CM034 | GAO says existing federal procurement data provides little insight into the country of origin of parts and materials used in defense supply chains. | Medium | SM017 |
| CM035 | A May 2026 proposed rule would require contractors or subcontractors with DoD contracts above $5 million to report FOCI status in NISS, deepening ownership visibility expectations. | Medium | SM029 |
| CM036 | Exiger’s DIB materials frame geographic supplier diversification and alternative sourcing as strategic responses to geopolitical shifts and adversarial-country exposure. | High | SM008, SM007 |
| CM037 | Retained TPRM and SCRM sources consistently cite cyberattacks, regulatory pressure, and AI-enabled monitoring or analytics as growth drivers. | Medium | SM020, SM021, SM023, SM025 |
| CM038 | Polaris says high implementation cost, budget constraints, and limited skilled resources can slow TPRM adoption, especially among smaller organizations. | Medium | SM021 |
| CM039 | Fortune and Exiger both imply that large, opaque, multi-tier supply chains require customized tooling and integration effort, not a light-touch deployment. | Medium | SM024, SM005 |
| CM040 | GII and Stratistics MRC say high false-positive alert rates consume analyst time, create workflow bottlenecks, and raise compliance cost in sanctions programs. | Medium | SM027 |
| CM041 | Exiger’s buyer map spans procurement, supply-chain, compliance, legal, cyber, financial-crime, and government acquisition teams rather than a single technical user. | High | SM003, SM004, SM007, SM009 |
| CM042 | Financial institutions are a serviceable Exiger vertical because the company explicitly bundles KYC, sanctions, investigations, and third-party risk workflows for them. | High | SM009, SM004 |
| CM043 | Defense agencies and DIB contractors are a serviceable Exiger vertical because the company explicitly bundles mapping, provenance, cybersecurity, and supplier de-risking for defense supply chains. | High | SM007, SM008, SM010 |
| CM044 | Large industrial and critical-infrastructure buyers are a serviceable Exiger vertical because the company targets multi-tier supplier bases with hidden part dependencies and resilience needs. | High | SM005, SM002 |
| CM045 | No retained public source isolates a single Exiger-specific SAM or SOM across TPRM, SCRM, sanctions screening, and defense visibility because each public estimate is defined and forecasted separately. | Medium | SM020, SM021, SM023, SM024, SM025, SM026, SM027 |
| CM046 | The most defensible sizing approach is a bounded adjacency set—TPRM, supply-chain risk management, sanctions or compliance screening, and defense-oriented visibility—rather than a single additive TAM. | Medium | SM001, SM004, SM006, SM020, SM023, SM026, SM016 |
| CM047 | Phased compliance rollouts and formal affirmations make defense-market budget cycles slower and more programmatic than broad market-growth figures imply. | Medium | SM010, SM011, SM030 |
| CM048 | Sensitive defense workflows are likely to require auditable data handling, ownership evidence, and controlled deployment patterns, limiting simple plug-and-play assumptions. | Low | SM010, SM011, SM029 |
| CM049 | Exiger’s positioning against “noise,” combined with third-party evidence on false positives and poor data quality, implies buyers will judge these platforms on alert precision and data harmonization as much as coverage breadth. | Medium | SM002, SM027, SM031 |
| CM050 | Exiger’s market is being pulled toward AI-native automation because the company highlights AI-driven knowledge-graph workflows while adjacent market reports highlight predictive analytics and automation as growth trends. | Medium | SM002, SM003, SM021, SM023, SM027 |
| CM051 | Dun & Bradstreet’s third-party-risk analysis illustrates why many buyers need portfolio matching, enrichment, linkage, litigation, debarment, and country-risk data before monitoring can work at scale. | Medium | SM031 |
| CM052 | Exiger’s serviceability depends on a mixed buying center in which operational, compliance, legal, and acquisition teams share the workflow, so adoption path is part of the market definition rather than just a sales-motion detail. | Medium | SM003, SM004, SM007, SM009 |
| CP001 | Exiger says its third-party risk offering covers onboarding, risk-ranking, and continuous monitoring. | Medium | SP001 |
| CP002 | Exiger says its AI Expo demos highlighted multi-tier mapping, agentic risk workflows, and critical-node intelligence. | Medium | SP002 |
| CP003 | Exiger says 1Exiger gives a single-pane view of supplier ecosystems and automates compliance and procurement decisions. | Medium | SP003 |
| CP004 | Exiger says it powers one third of the Fortune 500 and more than 60 federal agencies and DIB members. | High | SP002, SP003 |
| CP005 | Exiger says it is FedRAMP authorized and the largest provider of supply chain technology to the U.S. Federal Government. | Medium | SP003 |
| CP006 | Dun & Bradstreet says Compliance Intelligence uses more than 10,000 global sources and covers more than 550 million entities to support onboarding and ongoing monitoring. | High | SP029, SP006 |
| CP007 | Dun & Bradstreet says its 2026 agentic AI and MCP release automates onboarding, screening, and due-diligence workflows. | High | SP006, SP029 |
| CP008 | LSEG says World-Check supports KYC, AML, anti-bribery, sanctions, PEP, and adverse-media screening. | High | SP008, SP009 |
| CP009 | LSEG packages the same risk intelligence as API-first On Demand access and points-based World-Check One self-service packages. | High | SP009, SP030 |
| CP010 | LexisNexis markets an end-to-end financial crime compliance suite across the customer lifecycle. | Medium | SP010 |
| CP011 | K2 Integrity overlaps mainly as a financial-crimes risk and compliance specialist for banks, fintechs, and other regulated entities. | Medium | SP022, SP027 |
| CP012 | Sayari says it verifies tier-1 through tier-N supply networks with 4B+ trade transactions and 500M+ entity profiles across 250+ jurisdictions. | High | SP019, SP020 |
| CP013 | Sayari says one platform combines trade data, corporate ownership, sanctions, export controls, and UFLPA or ESG screening. | High | SP019, SP020 |
| CP014 | Interos says it maps and monitors supply chains at scale and that buyers usually understand only 2% of their supply chain. | Medium | SP023 |
| CP015 | Interos says iQ adds ERP-linked predictive analytics, financial-exposure quantification, and suggested alternative suppliers. | High | SP024, SP023 |
| CP016 | Coupa says Supplier Risk & Performance accelerates onboarding, automates third-party risk detection, and recommends actions such as reviewing alternative suppliers. | High | SP011, SP026 |
| CP017 | Moody's and Coupa partner material shows buyers can embed third-party risk data inside Coupa workflows instead of leaving the procurement system. | High | SP012, SP026 |
| CP018 | Aravo positions third-party risk as a multi-domain problem and markets AI-enabled workflows to surface risks earlier and simplify due diligence. | Medium | SP013 |
| CP019 | ProcessUnity says its TPRM platform combines configurable workflows, external ratings, real-time reporting, and automated post-contract monitoring. | High | SP014, SP015 |
| CP020 | Business Wire reports that Forrester's 2026 TPRM wave highlighted ProcessUnity's dynamic questionnaire scoping, AI workflows, and visualization. | Medium | SP015 |
| CP021 | Ivalua says supplier risk management provides a 360-degree supplier view, aggregated external risk data, and sub-tier scorecards. | Medium | SP016 |
| CP022 | Supply Wisdom focuses on continuous monitoring across financial, cyber, compliance, sustainability, operational, nth-party, and location risks with real-time alerts. | High | SP017, SP018 |
| CP023 | Exiger's public competitor set falls into three buyer jobs: screening data, workflow orchestration, and multi-tier supply-chain mapping. | Medium | SP001, SP006, SP008, SP011, SP013, SP019, SP023 |
| CP024 | D&B, LSEG, LexisNexis, Sayari, and K2 Integrity are the clearest overlaps when the buyer only needs sanctions, AML, KYC, or due-diligence intelligence. | Medium | SP006, SP008, SP010, SP019, SP022 |
| CP025 | Coupa, ProcessUnity, Aravo, Ivalua, and Supply Wisdom are the clearest overlaps when the buyer wants third-party-risk workflow and supplier operations. | Medium | SP011, SP013, SP014, SP016, SP017 |
| CP026 | Sayari and Interos are the closest overlaps when the buyer wants multi-tier supply-chain mapping and critical-node visibility rather than questionnaire orchestration. | Medium | SP019, SP020, SP023, SP024 |
| CP027 | Exiger's public wedge is the combination of supply-chain intelligence, due-diligence workflow, and federal or defense deployment credibility in one platform. | High | SP001, SP002, SP003 |
| CP028 | Hackett specifically credits Exiger with component-, hardware-, and software-level risk analysis. | Medium | SP003 |
| CP029 | Sayari and Interos both argue that tier-1 questionnaires leave material blind spots in sub-tier supply-chain risk. | High | SP019, SP023 |
| CP030 | Coupa and Ivalua can act as good-enough substitutes when buyers want supplier-risk actions inside existing procurement suites. | Medium | SP011, SP016, SP026 |
| CP031 | LSEG's self-service and API-first packaging gives it a lightweight land-and-expand motion that Exiger's public materials do not show. | Medium | SP009, SP030, SP001, SP003 |
| CP032 | D&B's 2026 agentic release shows data incumbents are moving from static datasets toward embedded workflow automation. | High | SP006, SP029 |
| CP033 | ProcessUnity and Aravo can match Exiger on configurable TPRM workflow without matching its federal supply-chain positioning. | Medium | SP013, SP014, SP015, SP003 |
| CP034 | Supply Wisdom has a credible continuous-monitoring niche, but the retained public set emphasizes alerts more than trade or ownership provenance. | Medium | SP017, SP018, SP019 |
| CP035 | K2 Integrity is most relevant where buyers want expert-led AML and sanctions remediation or program design rather than procurement-native workflow or supply-chain mapping. | Medium | SP022, SP027 |
| CP036 | Public packaging is clearest at LSEG World-Check One, while most workflow vendors in the retained set remain demo-led or quote-led. | Medium | SP030, SP011, SP013, SP014, SP016, SP017 |
| CP037 | Exiger is most likely to win when the buyer values federal authorization, component-level analysis, and agentic multi-tier mapping together. | Medium | SP002, SP003, SP019, SP023 |
| CP038 | Exiger is more exposed in pure screening deals where D&B, LSEG, or Lexis can slot into existing workflows. | Medium | SP006, SP008, SP010, SP030 |
| CP039 | Exiger is also exposed in procurement-led accounts where Coupa or Ivalua already own the supplier workflow. | Medium | SP011, SP016, SP026 |
| CP040 | Buyers can compose best-of-breed stacks by pairing data providers such as LSEG or Sayari with workflow systems such as Coupa or Ivalua. | Medium | SP009, SP020, SP026, SP016 |
| CP041 | The main adverse angle is suite bundling by larger data and procurement incumbents. | High | SP006, SP009, SP010, SP011, SP016 |
| CP042 | Exiger's moat looks real but conditional because few public peers combine graph depth, TPRM workflow, and federal credibility in one marketed stack. | High | SP002, SP003, SP019, SP023 |
| CP043 | That moat is not structurally locked because data incumbents can deepen workflow and procurement suites can deepen risk data inside existing deployments. | High | SP006, SP009, SP011, SP016, SP030 |
| CP044 | Sayari and Interos are the most direct graph-side challenges because both market multi-tier visibility and continuous monitoring with differentiated data assets. | High | SP019, SP020, SP023, SP024 |
| CP045 | LSEG says World-Check On Demand reduces over-screening and false positives while speeding onboarding and payments. | High | SP007, SP009 |
| CP046 | Sayari says unified cross-regime screening can reduce assessment time from weeks to days. | Medium | SP020 |
| CP047 | Dun & Bradstreet says its 2026 agentic workflow release can reduce processing times by 70-90%. | Medium | SP006 |
| CI001 | Exiger says its platform unifies supplier, product, part, component, and risk data in a single workspace. | Medium | SI001 |
| CI002 | Exiger’s product and public-sector pages present the business as enterprise software and tech-enabled risk workflows rather than a self-serve SMB tool. | Medium | SI004, SI005 |
| CI003 | No reviewed official Exiger surface publishes a list price or self-serve rate card for the core platform. | Medium | SI001, SI004, SI005, SI012 |
| CI004 | Exiger’s about page describes a distributed operating footprint spanning 10 global offices, implying a scaled delivery organization for a private company. | Medium | SI002 |
| CI005 | Forbes reported in March 2024 that CEO Brandon Daniels said Exiger had 870 employees. | Low | SI017 |
| CI006 | Exiger’s 2026 Gartner and Hackett materials say the company serves more than 550 global customers. | High | SI013, SI014, SI018 |
| CI007 | Exiger’s 2026 Gartner and Hackett materials say the company serves 150 Fortune 500 customers. | High | SI013, SI014, SI018 |
| CI008 | Exiger’s 2026 Gartner and PR Newswire materials say the company serves 60+ government and Defense Industrial Base organizations and is the largest provider of supply chain technology to the U.S. Federal Government. | High | SI013, SI018 |
| CI009 | The World Economic Forum organization profile says Exiger serves 550 customers worldwide, including 150 Fortune 500 companies and over 50 government agencies. | Medium | SI019 |
| CI010 | The 1ExigerAI page says one deployment uncovered 20,000+ hidden downstream entities and cut signal noise by 45% across 50,000+ customers and distributors. | Medium | SI003 |
| CI011 | The 1ExigerAI page says Exiger normalized 40,000+ parts and improved forecasting accuracy by 10-20% in an industrial manufacturing use case. | Medium | SI003 |
| CI012 | The 1ExigerAI page says Exiger mapped 50,000+ drugs and identified country-of-origin data for 80%+ of the supply chain in a federal use case. | Medium | SI003 |
| CI013 | Exiger launched its 1Exiger platform in AWS Marketplace in March 2026. | Medium | SI012 |
| CI014 | Exiger says it was named a Leader in the 2026 Gartner Magic Quadrant for Supplier Risk Management and ranked highest in execution and furthest in vision. | Medium | SI013 |
| CI015 | Exiger says Hackett’s Spring 2026 SolutionMap assessed 118 vendors across 16 categories and recognized Exiger as a validated provider and top technology in risk management. | High | SI014, SI018 |
| CI016 | Carrick Capital Partners invested $80 million in Exiger in July 2018. | Medium | SI007 |
| CI017 | Exiger announced in December 2023 that Carlyle and Insight Partners would make a majority investment and that Carrick would reinvest. | High | SI006, SI016 |
| CI018 | No reviewed public release disclosed the dollar size or valuation of the 2023 Carlyle and Insight transaction. | High | SI006, SI016 |
| CI019 | Forbes reported that Exiger expected revenue to exceed $150 million by the end of 2024. | Low | SI017 |
| CI020 | Forbes reported that Exiger said it had grown at a compound annual rate above 80% over the prior five years. | Low | SI017 |
| CI021 | Forbes reported that Exiger was tracking events across 16 million supply chains, 600 million legal entities, and 5 billion pounds of goods. | Low | SI017 |
| CI022 | Exiger acquired Supply Dynamics in August 2022. | Medium | SI008 |
| CI023 | Exiger said the Supply Dynamics acquisition added item-level visibility, multi-tier mapping, and collaboration data to its platform. | Medium | SI008 |
| CI024 | Exiger announced the sale of its FCC advisory division to Capgemini in September 2023 to focus on its third-party risk and supply-chain technology business. | Medium | SI011 |
| CI025 | Exiger acquired XSB in August 2024. | Medium | SI009 |
| CI026 | Exiger said XSB added a catalog of 100 million parts and 400 million parts attributes used by the U.S. Federal Government. | Medium | SI009 |
| CI027 | Exiger acquired Versed AI in 2024. | Medium | SI010 |
| CI028 | Exiger said Versed AI added AI-driven multi-tier visibility and that the acquired company was an ISO 27001-certified Cambridge spinout. | Medium | SI010 |
| CI029 | Exiger’s 2022-2024 acquisition and divestiture cadence shows active portfolio shaping rather than a static single-product strategy. | Medium | SI008, SI009, SI010, SI011 |
| CI030 | Official Exiger materials indicate that revenue is sold through enterprise and government procurement motions, not through public per-seat or usage pricing. | Medium | SI004, SI005, SI012 |
| CI031 | No reviewed public source disclosed Exiger’s ARR, gross margin, burn, runway, CAC, or net revenue retention. | Medium | SI001, SI004, SI006, SI013, SI017 |
| CI032 | No reviewed public source disclosed Exiger’s realized pricing, ACV, contract duration, or software-versus-services revenue mix. | Medium | SI004, SI005, SI011, SI012 |
| CI033 | Exiger’s 2023 and 2026 messaging consistently describes the business as SaaS or supply-chain AI software rather than a consulting-led outsourcer. | Medium | SI006, SI011, SI012, SI013 |
| CI034 | Public financial data shows Verisk generated roughly $3.073 billion of FY2025 revenue and about $2.147 billion of gross profit. | Medium | SI021, SI025 |
| CI035 | Stockanalysis showed Verisk with about $23.52 billion of market cap against about $3.10 billion of trailing revenue in mid-2026, implying roughly 7.6x revenue. | Medium | SI021, SI022 |
| CI036 | Public financial data shows Dun & Bradstreet generated about $2.382 billion of FY2024 revenue with about 2.93% growth. | Medium | SI023, SI026 |
| CI037 | Stockanalysis summarized Dun & Bradstreet’s Clearlake take-private at about $7.7 billion enterprise value and $4.1 billion cash equity. | Medium | SI024 |
| CI038 | Applying Dun & Bradstreet’s roughly 3.2x enterprise-value-to-revenue support to Forbes’s reported >$150 million revenue floor yields about $480 million of low-end implied value support for Exiger. | Medium | SI017, SI023, SI024 |
| CI039 | Applying Verisk’s roughly 7.6x public-market revenue multiple to the same >$150 million revenue floor yields about $1.14 billion of high-end implied value support for Exiger. | Medium | SI017, SI021, SI022 |
| CI040 | Because Exiger’s margin profile, net retention, and 2023 sponsor entry valuation are undisclosed, investor return expectations above the low-end public-comp floor depend on private economics rather than public evidence. | Medium | SI006, SI016, SI017, SI021, SI023 |
| CI041 | FTC privacy and security enforcement shows that buyers in Exiger’s market face real legal exposure when vendor controls fail. | Medium | SI027 |
| CI042 | CBP’s UFLPA enforcement framework shows that forced-labor and origin compliance remains an active operational and trade risk for importers. | Medium | SI028 |
| CI043 | Exiger’s large U.S. federal footprint is commercially attractive but creates a government-mix concentration question because no public source breaks out public-sector versus commercial revenue. | Medium | SI005, SI013, SI018, SI019 |
| CI044 | Exiger’s multi-acquisition roll-up creates integration and execution risk because public sources do not quantify acquired revenue, overlap, or synergy capture from Supply Dynamics, XSB, or Versed AI. | Medium | SI008, SI009, SI010 |
| CI045 | Exiger’s public disclosure is materially thinner than public analytics comps because the company discloses customer counts, awards, and acquisitions but not audited P&L or cash-flow metrics. | Medium | SI013, SI017, SI021, SI023, SI025, SI026 |
| CI046 | The financial underwriting case is directionally positive because Exiger shows scaled enterprise reach, product recognition, and repeated investor support. | Medium | SI013, SI014, SI016, SI017 |
| CI047 | The financial underwriting case remains incomplete because pricing realization, gross margin, burn, and customer concentration remain private. | Medium | SI003, SI004, SI005, SI006, SI017 |
| CI048 | The AWS Marketplace launch can shorten procurement friction and support expansion inside existing enterprise cloud workflows, but no public source quantifies its revenue contribution. | Medium | SI012 |
| CI049 | The Capgemini divestiture likely improved Exiger’s software mix by removing a people-intensive FCC advisory arm, but Exiger does not disclose pre- or post-sale revenue composition. | Medium | SI011 |
| CI050 | The public evidence supports a software-led, sponsor-backed risk-intelligence platform; it does not support a clean public valuation mark or runway estimate. | Medium | SI001, SI011, SI013, SI017, SI021, SI023 |
| CE001 | Exiger’s public product surface is organized around 1ExigerAI, supply chain, risk and compliance, and software supply chain security rather than a single screening tool. | Medium | SE001, SE003, SE004 |
| CE002 | Exiger describes 1Exiger as a single workspace that brings together procurement, supply chain, and compliance to identify, assess, and mitigate risk from the supplier network down to the part and material level. | High | SE002, SE005, SE017 |
| CE003 | DDIQ ingests structured watchlists, premium news, open-web sources, and proprietary lists into one audit-ready diligence profile. | Medium | SE003, SE022 |
| CE004 | DDIQ organizes evidence using configurable risk rules and presents high-, medium-, and low-risk contributors to support adjudication. | Medium | SE003, SE022 |
| CE005 | OpenCorporates was one of the first external data sources connected to DDIQ through an API for entity verification. | High | SE013, SE014 |
| CE006 | Exiger says over a million DDIQ due-diligence reports have been driven in part by OpenCorporates data. | High | SE013, SE014 |
| CE007 | Exiger’s OpenCorporates case study says stronger verification reduced downstream false positives by more than 80 percent. | Medium | SE013 |
| CE008 | The 1ExigerAI page claims Exiger uncovered 20,000-plus hidden downstream entities and cut signal noise by 45 percent across a network of more than 50,000 customers and distributors. | Medium | SE004 |
| CE009 | The 1ExigerAI page claims Exiger normalized more than 40,000 parts and improved forecasting accuracy by 10 to 20 percent across a customer network. | Medium | SE004 |
| CE010 | The 1ExigerAI page claims Exiger mapped more than 50,000 drugs and uncovered country-of-origin data for more than 80 percent of the supply chain in a federal use case. | Medium | SE004 |
| CE011 | LexisNexis says WorldCompliance contains more than 8 million risk profiles covering 180 sanctions lists, 1,700 enforcement sources, and 250 countries and territories. | Medium | SE015 |
| CE012 | WorldCompliance can be delivered as a standalone data file or integrated into screening platforms, and it is segmented into more than 60 risk categories and subcategories. | Medium | SE015 |
| CE013 | The reviewed 2026 public packaging emphasizes 1Exiger, 1ExigerAI, DDIQ, and solution families rather than a standalone ORCA product page, leaving ORCA nomenclature publicly ambiguous. | Medium | SE001, SE002, SE003, SE004, SE023 |
| CE014 | Exiger says it is API-first, offers hundreds of native integrations, exposes open APIs, and uses an AI-driven ETL layer to ingest ERP, PLM, and S2P data. | Medium | SE002 |
| CE015 | Exiger’s supply-chain and AWS Marketplace materials say 1Exiger embeds risk insights and workflows into ERP, PLM, and data-lake environments. | High | SE002, SE005, SE011 |
| CE016 | Exiger says Snowflake customers can onboard, vet, and continuously monitor suppliers, customers, and agents using Exiger risk signals directly inside their Snowflake environments. | Medium | SE011 |
| CE017 | Exiger says its product-aware engineering knowledge graph spans 10 billion supply-chain records, 400 million part attributes, and 6.5 million mapped relationships across more than 200 countries. | Medium | SE002 |
| CE018 | The XSB acquisition added a catalog of more than 100 million parts and 400 million part attributes used across government agencies, combatant commands, and the Defense Industrial Base. | High | SE009, SE018, SE019 |
| CE019 | Progress Partners says XSB’s SWISS knowledge graph can be queried from other applications through the SWISS API. | Medium | SE019 |
| CE020 | The Supply Dynamics acquisition integrated SDX, PAC, and ExplorerRX with Exiger’s DDIQ, Insight3PM, and Supply Chain Explorer into a single secure cloud platform. | Medium | SE010 |
| CE021 | Supply Dynamics specialized in real-time visibility over part, raw-material, and item-level bill-of-material requirements across tier-1 through tier-n suppliers. | Medium | SE010 |
| CE022 | Exiger says Versed AI automatically maps and contextualizes complex n-tier supply chains and uses automated bill-of-material mapping data to illuminate product-specific value chains. | Medium | SE008 |
| CE023 | Exiger’s 1ExigerAI and tour pages describe a human-plus-AI operating model that routes work to human reviewers, AI teammates, or both inside one decisioning environment. | High | SE004, SE023, SE024 |
| CE024 | The 1ExigerAI Activation Series markets agentic workflows for routine compliance, screening, documentation, and centralized intelligence across procurement, third-party risk, and supply-chain operations. | Medium | SE024 |
| CE025 | Exiger’s 2026 AI+ Expo page says the company is publicly demoing agentic AI supply-chain intelligence, live platform demos, and recruiting for AI-native supply-chain roles. | Medium | SE026 |
| CE026 | 1Exiger became generally available in AWS Marketplace in March 2026 as a discover-try-test-buy-deploy-manage channel. | High | SE005, SE017 |
| CE027 | Exiger Federal Cloud achieved government-wide FedRAMP Moderate authorization, and Exiger says the updated status is live and searchable in the FedRAMP Marketplace. | High | SE006, SE007 |
| CE028 | The FedRAMP Marketplace lists Exiger Federal Cloud under package FR2122140784 as FedRAMP Certified Class C (Moderate) on the Agency path. | Medium | SE007 |
| CE029 | Exiger says regulated-program integrations run on its FedRAMP Moderate authorized environment and that the company also maintains ISO 27001 and SOC 2 Type II controls. | High | SE002, SE006 |
| CE030 | Current Built In postings show Exiger hiring around Snowflake, AWS, APIs and data pipelines, CI/CD automation, Kubernetes, AI/ML analytics, and client implementation work. | Medium | SE020 |
| CE031 | A Built In full-stack role tied to Exiger’s XSB surface calls for Java web applications, RESTful services, relational databases, text analytics, Docker, Kubernetes, Jenkins or BitBucket CI/CD, and NIST/FedRAMP experience. | Medium | SE021 |
| CE032 | Carahsoft positions 1Exiger as a scalable and secure government solution for real-time cost savings, resilience, and compliance support. | Medium | SE016 |
| CE033 | Taken together, Supply Dynamics, XSB, and Versed AI extend Exiger beyond entity screening into item-level, part-level, and multi-tier supply-chain intelligence. | High | SE008, SE009, SE010, SE019 |
| CE034 | Exiger’s Digital Thread and Parts Intelligence product turns engineering PDFs and specifications into structured machine-readable data that can be exported to downstream systems. | Medium | SE012 |
| CE035 | Exiger says it reinvests more than 30 percent of annual revenue into generating proprietary, product-aware supply-chain data. | Medium | SE002 |
| CE036 | Compared with DDIQ’s diligence-research posture, 1ExigerAI emphasizes alternative sourcing, directed-buy, workflow execution, and procurement acceleration inside the same operating layer. | Medium | SE002, SE003, SE004, SE023 |
| CE037 | Software Advice lists DDIQ pricing as available only upon request, so public packaging remains sales-led rather than transparently self-serve on price. | Medium | SE022 |
| CE038 | GLACIS argues that AI vendor diligence should test model opacity, training-data provenance, drift monitoring, bias controls, human oversight, and audit rights for high-stakes deployments. | Medium | SE027 |
| CE039 | Exiger’s public AI materials emphasize explainable, action-oriented recommendations, but the reviewed file does not publish precision, recall, hallucination, fairness-testing, or drift metrics. | Medium | SE004, SE023, SE024, SE026, SE027 |
| CE040 | Current implementation roles imply non-trivial deployment work spanning client coordination, training, documentation, and process standardization in addition to software delivery. | Medium | SE020 |
| CE041 | Exiger’s workflow quality depends materially on external data-provider quality and update cadence, including OpenCorporates entity records and WorldCompliance sanctions and adverse-media feeds. | Medium | SE013, SE014, SE015 |
| CE042 | The public product file is stronger on breadth, data assets, and deployment channels than on public API documentation, SLA history, and module-level maturity evidence for every marketed workflow. | Medium | SE001, SE002, SE003, SE005, SE020 |
| CE043 | The 1ExigerAI page says administrators can configure roles, permissions, workflows, and centralized case activity without engineering support. | Medium | SE004 |
| CE044 | Exiger says its AI-native product-development lifecycle is intended to push new capabilities to customers as regulations and operational needs change. | Medium | SE004 |
| CU001 | Exiger’s public customer surfaces span corporations, government agencies, and banks rather than a single-vertical buyer base. | High | SU001, SU021 |
| CU002 | Exiger’s financial-institutions page positions the buyer around compliance, legal, investigations, transaction monitoring, sanctions screening, and KYC/TPRM workflows. | Medium | SU003 |
| CU003 | The retained public proof set is strongest in government, industrial, and healthcare workflows, while financial-services proof is mostly anonymized case-study evidence. | Medium | SU002, SU022, SU023, SU024, SU025, SU026 |
| CU004 | Exiger’s 2026 official materials repeatedly state that the company serves 550+ global customers. | High | SU017, SU018, SU021 |
| CU005 | Exiger’s 2026 official materials repeatedly state that 150+ Fortune 500 companies are customers. | High | SU017, SU018 |
| CU006 | Exiger’s 2026 official materials repeatedly state that 60+ government and Defense Industrial Base organizations are customers. | High | SU005, SU017, SU018 |
| CU007 | The clearly identified external accounts in the retained corpus are U.S. Army Materiel Command, U.S. Customs and Border Protection, Northwell Health, and Oshkosh/JLG. | Medium | SU005, SU014, SU022, SU023 |
| CU008 | Exiger announced a multi-million-dollar contract from the U.S. Army to license 1Exiger software to Army Materiel Command. | High | SU005, SU006, SU007 |
| CU009 | The Army deployment is described as a live software program tied to sustainment operations and integration into Weapon System 360 and Vantage, not a generic pilot announcement. | High | SU005, SU006 |
| CU010 | Exiger’s federal contract vehicles page lists contract 47QFHA22F0027 with a $74.5 million ceiling, open availability across U.S. government agencies, and OUSD A&S sponsorship. | High | SU004, SU013 |
| CU011 | USAspending shows multiple funded modifications under OUSD Exiger DDIQ license and services, corroborating real federal procurement history beyond a single marketing claim. | High | SU013, SU004 |
| CU012 | Exiger says it won a place on the 10-year, $919 million SCRIPTS BPA as the highest-ranked unrestricted prime awardee. | High | SU012, SU015 |
| CU013 | Exiger says CBP awarded it a multi-million-dollar contract to deploy Trade AI for illicit transshipment detection across global supply chains. | High | SU014, SU008 |
| CU014 | Platform One awardable status gives DoD and other government customers a direct marketplace route to review Exiger Cyber use cases and solution features. | Medium | SU009, SU008 |
| CU015 | Exiger’s March 2026 AWS Marketplace launch is explicitly framed as a way to shorten procurement cycles for commercial and international customers. | High | SU010, SU011 |
| CU016 | Both the AWS Marketplace listing and Exiger’s launch release emphasize ERP, PLM, and data-lake integration plus continuous monitoring, signaling that Exiger is meant to sit inside customer workflows rather than beside them. | High | SU010, SU011 |
| CU017 | Northwell selected Exiger after using multiple tools and evaluating multiple providers, seeking a one-stop vendor-risk ecosystem at scale. | High | SU022, SU030 |
| CU018 | Northwell’s deployment includes API-fed integration into ERP and Service Desk workflows plus ongoing monitoring of critical suppliers. | Medium | SU022 |
| CU019 | Oshkosh/JLG used Exiger’s SDX and PAC workflow to normalize 40,000+ parts and onboard 40+ Tier 1 fabricators, which is materially deeper than a light pilot. | Medium | SU023 |
| CU020 | The Oshkosh case study attributes >80% visibility/control over carbon steel plate network spend and 10-20% forecasting accuracy improvement to the Exiger deployment. | Medium | SU023 |
| CU021 | Oshkosh’s initial Access business-unit deployment expanded to the Commercial business unit with stated plans to extend further into Fire & Emergency and Defense. | Medium | SU023 |
| CU022 | Exiger’s financial-services proof in the retained corpus consists of anonymized case studies for a major investment bank, a top-10 regional bank, and a European fintech rather than named marquee banks. | Medium | SU024, SU025, SU026 |
| CU023 | In the top-10 regional bank case, Exiger was extended for an additional five months after the initial 2,200-alert lookback because the client recognized the quality and pace of the work. | Medium | SU024 |
| CU024 | In the fintech case, Exiger says it ran a five-month EDD/KYC remediation program involving approximately 20,000 associated parties under regulatory pressure. | Medium | SU026 |
| CU025 | The global investment bank case shows Exiger being hired for commercial-banking control-environment design, implying access to complex banking buyers even when the bank is unnamed. | Medium | SU025 |
| CU026 | In the retained 2026 public corpus, Goldman Sachs and JPMorgan are not named as current Exiger customers, so those specific logos remain unverified. | Medium | SU002, SU003, SU021 |
| CU027 | Exiger’s customer stories page lists many case-study themes but only a small subset of clearly named external accounts, creating room for logo/reference inflation if counts are taken at face value. | Medium | SU002 |
| CU028 | Named public proof is much more specific for government, healthcare, and industrial workflows than for financial services. | Medium | SU005, SU014, SU022, SU023, SU024, SU025, SU026 |
| CU029 | Gartner’s visible January 2026 favorable review from a manufacturing manager says 1Exiger transformed third-party-risk workflows, reduced false positives, and had exceptional engagement and implementation teams. | Medium | SU019 |
| CU030 | The same Gartner product page includes a visible May 2026 critical review saying 1Exiger can be complex to implement and tune for specific workflows and may feel heavier than needed for simple monitoring. | Medium | SU019 |
| CU031 | The accessible Gartner product page references 69 reviews, which is a stronger satisfaction proxy than most private-software customer pages even though it is not a disclosed NPS or renewal rate. | Medium | SU019 |
| CU032 | PeerSpot’s 1Exiger page says it has not yet collected reviews, showing that public review depth is uneven across platforms. | Medium | SU020 |
| CU033 | None of the retained sources disclose NRR, GRR, logo churn, contract length, or named renewal cohorts for Exiger. | Medium | SU002, SU003, SU019, SU021 |
| CU034 | Switching costs appear meaningful once Exiger is embedded because customer proof repeatedly references custom APIs, ERP/PLM connections, tiered supplier onboarding, technical data packages, or real-time monitoring workflows. | High | SU005, SU011, SU022, SU023 |
| CU035 | Exiger’s public procurement path is segmented: federal contract vehicles and BPAs for government, direct enterprise evaluations for regulated enterprises, and AWS Marketplace for lower-friction channel procurement. | Medium | SU004, SU010, SU022 |
| CU036 | Implementation quality is part of Exiger’s value proposition, but the visible case studies and Gartner review also imply non-trivial onboarding effort for large accounts. | Medium | SU019, SU022, SU023 |
| CU037 | The public record creates a real public-sector concentration question because Exiger repeatedly emphasizes Army, CBP, Platform One, SCRIPTS, and 60+ government or DIB organizations while disclosing no public-sector revenue share. | Medium | SU005, SU009, SU012, SU017 |
| CU038 | Defense/public-sector concentration is directly named at the account level, while financial-services concentration is only indirectly visible through anonymized bank and fintech case studies. | Medium | SU003, SU005, SU014, SU024, SU025, SU026 |
| CU039 | The SBOM case study shows Exiger can be pulled in because end customers demand software provenance artifacts, extending customer proof beyond direct procurement teams into downstream customer requirements. | Medium | SU027 |
| CU040 | The anonymized U.S. government microelectronics case and the anonymized pharma federal case suggest Exiger can repeat the core illumination workflow across agencies, but anonymity weakens reference quality. | Medium | SU028, SU029 |
| CU041 | Craft independently reports 550 customers served as of November 2023 and describes Exiger as serving the defense industrial base, financial, corporate, government, and public sectors. | Medium | SU021 |
| CU042 | Hackett, ProcureTech, and Gartner-related Exiger pages provide adoption and customer-value signaling, but none substitute for disclosed renewal or concentration economics. | Medium | SU016, SU017, SU018 |
| CU043 | Taken together, the DDIQ contract, SCRIPTS BPA, Army award, CBP award, and Platform One route show a broad federal procurement lattice rather than a one-off defense win. | Medium | SU004, SU005, SU009, SU012, SU014 |
| CU044 | Within financial institutions, the public product surface suggests the payer sits with compliance, legal, and risk teams rather than general IT or broad procurement. | Medium | SU003, SU024, SU025, SU026 |
| CR001 | Exiger says it serves 550 customers globally, including 150 Fortune 500 companies and more than 55 government and Defense Industrial Base organizations. | High | SR004, SR008 |
| CR002 | Exiger’s AWS Marketplace seller profile states that the company serves 550+ customers, including 150 Fortune 500 and 60+ government and Defense Industrial Base organizations. | Medium | SR007 |
| CR003 | Exiger Federal Cloud has achieved FedRAMP Moderate Authorization. | High | SR004, SR008, SR013 |
| CR004 | FedRAMP is a government-wide program that standardizes cloud security assessment and maintains a searchable marketplace of certified services. | Medium | SR013 |
| CR005 | Exiger’s public-sector contract-vehicles page lists a GSA-assisted acquisition contract with a $74.5 million ceiling that is open to all U.S. government departments and agencies. | High | SR003, SR032 |
| CR006 | Carahsoft lists Exiger on multiple federal, state, and local procurement contracts. | Medium | SR006 |
| CR007 | Exiger announced on 2026-03-17 that 1Exiger became available in AWS Marketplace. | Medium | SR005 |
| CR008 | Exiger says AWS Marketplace helps organizations discover, try, buy, deploy, and manage software and AI tools in one destination. | Medium | SR005 |
| CR009 | SAM.gov is the U.S. government’s centralized source for finding contract opportunities, awards, and subcontract reports. | Medium | SR029 |
| CR010 | USAspending provides advanced search over federal awards by recipient, award ID, and time period. | Medium | SR028 |
| CR011 | Exiger announced in November 2025 that the U.S. Army Materiel Command awarded it a multi-million software contract. | Medium | SR027 |
| CR012 | The 2023 Carlyle and Insight transaction kept management, founders, and Carrick invested, which supports continuity but leaves governance rights and sponsor-exit pressure publicly under-disclosed. | Medium | SR031 |
| CR013 | Exiger’s public privacy and legal center includes a DPA tied to executed service agreements. | Medium | SR001 |
| CR014 | Exiger’s public DPA says the customer is controller and Exiger is processor for applicable personal data. | Medium | SR001 |
| CR015 | Exiger’s public DPA says Exiger will maintain technical, physical, and organizational safeguards against compromise of personal data. | Medium | SR001 |
| CR016 | Exiger’s public DPA says customers must make reasonable efforts to ensure that personal data provided to Exiger is accurate and complete. | Medium | SR001 |
| CR017 | Exiger’s public DPA says sub-processors handling customer data must provide written assurances substantially no less protective than Exiger’s own obligations. | Medium | SR001 |
| CR018 | Exiger’s public DPA includes jurisdiction-specific appendices for EU/EEA and Switzerland, the UK, intra-Europe transfers, California, and Australia or Singapore. | Medium | SR001 |
| CR019 | Exiger’s terms of use state that the site provides access to proprietary DDIQ and/or Insight 3PM technologies under executed licensing agreements. | Medium | SR002 |
| CR020 | Exiger’s 2026 AI article says leading programs are using AI to map hidden supplier networks, detect emerging risks in real time, and predict disruption before it strikes. | Medium | SR026 |
| CR021 | Exiger’s 2026 AI article says third-party risk management is moving from static compliance to dynamic intelligence and enterprise risk strategy. | Medium | SR026 |
| CR022 | Exiger and The Chertoff Group launched a product-assurance playbook aimed at identifying, assessing, and remediating hardware and software supply-chain risk. | Medium | SR009 |
| CR023 | The Chertoff release frames foreign influence and increasing supply-chain scrutiny as active problems for customers. | Medium | SR009 |
| CR024 | Exiger’s 2022 Supply Dynamics acquisition was positioned as adding item-level visibility, multi-tier mapping, and automated due-diligence integration into one platform. | Medium | SR032 |
| CR025 | Exiger said it had already introduced Supply Dynamics products into its $74.5 million GSA contract. | Medium | SR032 |
| CR026 | Exiger’s 2024 XSB acquisition brought 100M+ parts and 400M+ parts attributes in-house. | Medium | SR010, SR011 |
| CR027 | SDCExec described the XSB deal as creating an end-to-end solution for logistics, PEO, and acquisition communities. | Medium | SR011 |
| CR028 | Exiger described the Versed AI acquisition as expanding AI-driven multi-tier supply-chain visibility, data, and mapping. | Medium | SR033 |
| CR029 | OFAC’s Sanctions List Service provides downloadable SDN and consolidated list data as well as custom datasets. | Medium | SR015 |
| CR030 | BIS highlights the EAR, item classification, country guidance, and screening resources as core export-control tools. | Medium | SR016, SR030 |
| CR031 | BIS’s EAR tool says users should confirm legal research with official CFR and Federal Register editions. | Medium | SR030 |
| CR032 | CBP says UFLPA creates a rebuttable presumption against imports made wholly or partly in XUAR or by entities on the UFLPA Entity List. | Medium | SR017 |
| CR033 | CBP says forced-labor enforcement is tied to economic and national security and spans UFLPA, WROs, and CAATSA-related tools. | Medium | SR018 |
| CR034 | FTC business guidance frames ongoing obligations around data security and consumer privacy for businesses. | Medium | SR019 |
| CR035 | The European Commission says EU data-protection law is built around the GDPR, the Law Enforcement Directive, and the EU institutions’ data-protection regulation. | Medium | SR020 |
| CR036 | The AI Act resource shows the EU AI Act has staged compliance tasks and a defined implementation timeline rather than a one-time policy event. | Medium | SR021 |
| CR037 | The SEC proposed in May 2026 to simplify registered offerings and reporting for public companies while maintaining investor protections. | Medium | SR022 |
| CR038 | The SEC’s 2026 Examination Priorities show ongoing federal scrutiny of disclosure and compliance processes for market participants. | Medium | SR023 |
| CR039 | PACER Case Locator is the nationwide federal litigation index and requires account registration before online searches. | Medium | SR024 |
| CR040 | U.S. Courts says PACER or the clerk’s office is the authoritative route for locating federal case files. | Medium | SR025 |
| CR041 | FeaturedCustomers aggregates 16 reviews or testimonials and 14 case studies for Exiger, so the public proof set is reference-heavy rather than complaint-heavy. | Low | SR012 |
| CR042 | Public-sector concentration risk is material because official and partner sources show contract vehicles, reseller channels, FedRAMP status, and Army deployment, while no retained source discloses government revenue share. | Medium | SR003, SR006, SR027, SR031 |
| CR043 | Procurement-timing risk remains high because reseller, contract-vehicle, SAM.gov, and USAspending routes imply multi-stakeholder contracting even after AWS Marketplace availability. | Medium | SR005, SR006, SR028, SR029 |
| CR044 | Acquisition-integration risk is real because Supply Dynamics, XSB, and Versed AI add distinct item-level, parts-intelligence, and product-breakdown capabilities that must be operationalized in one platform. | Medium | SR032, SR010, SR033 |
| CR045 | Data-accuracy liability is shared rather than eliminated by contract because customers warrant accuracy while Exiger still undertakes processing, security, and sub-processor obligations. | Medium | SR001 |
| CR046 | Compliance-error risk is structurally high for sanctions and supply-chain screening because OFAC, BIS, and CBP maintain changing lists, entity rules, and enforcement standards that downstream users must interpret correctly. | Medium | SR015, SR016, SR017, SR030 |
| CR047 | Public-exit risk exists because Exiger is majority PE-backed while the SEC’s 2026 reform push itself signals that registered offerings still involve enough friction to merit simplification. | Medium | SR031, SR022, SR023 |
| CR048 | Free public web research cannot fully clear litigation or contract-concentration questions without PACER, clerk-office checks, and recipient-specific federal award searches. | Medium | SR024, SR025, SR028, SR029 |
| CV001 | Exiger officially announced in December 2023 that it would receive a majority investment from Carlyle and Insight Partners. | Medium | SV001, SV002 |
| CV002 | Carrick's 2023 announcement framed Exiger as a high-growth AI supply-chain risk and resilience software company. | Medium | SV002 |
| CV003 | The official Exiger and Carrick releases do not disclose the valuation, ownership split, or financing structure of the 2023 deal. | Medium | SV001, SV002 |
| CV004 | Private Equity Insights reported that Carlyle and Insight agreed to buy Exiger at a $1.2 billion value. | Low | SV003 |
| CV005 | Alternatives Watch said the stake valuation was not officially disclosed and that The Wall Street Journal pegged the deal at about $1.2 billion. | Low | SV004 |
| CV006 | The AWS Marketplace seller profile says Exiger serves 550+ global customers. | Medium | SV005, SV006 |
| CV007 | The same 2026 AWS materials say Exiger serves 150 Fortune 500 organizations and 60+ government and Defense Industrial Base organizations. | Medium | SV005, SV006, SV007 |
| CV008 | Exiger's AWS profile says the company is FedRAMP authorized and the largest provider of supply-chain technology to the U.S. Federal Government. | Medium | SV005, SV006 |
| CV009 | Exiger's March 2026 AWS Marketplace launch was positioned as a way to accelerate customer access and reduce traditional procurement friction. | Medium | SV006 |
| CV010 | Exiger's 2026 Hackett release said the company made the 2025-2026 50 to Know list after a procurement-technology review of about 220 vendors. | Medium | SV007 |
| CV011 | Forbes reported in March 2024 that CEO Brandon Daniels said Exiger had 870 employees. | Low | SV008 |
| CV012 | Forbes reported in March 2024 that Exiger expected revenue to exceed $150 million by the end of 2024. | Low | SV008 |
| CV013 | Forbes reported in March 2024 that Exiger had compounded at over 80 percent annually during the prior five years. | Low | SV008 |
| CV014 | Forbes reported that Exiger was tracking events across 16 million supply chains and 600 million legal entities. | Low | SV008 |
| CV015 | Exiger announced in 2018 that Carrick Capital Partners invested $80 million of minority growth capital. | Medium | SV009, SV004 |
| CV016 | CompaniesMarketCap shows Dun & Bradstreet's last known market cap at $4.08 billion on October 3, 2025. | Medium | SV010 |
| CV017 | CompaniesMarketCap shows Dun & Bradstreet at roughly $2.40 billion of trailing revenue. | Medium | SV011, SV013 |
| CV018 | Using the retained D&B market-cap and revenue figures gives a simple market-cap-to-revenue proxy of about 1.7x. | Medium | SV010, SV011 |
| CV019 | CompaniesMarketCap shows Verisk's market cap at about $24.06 billion in July 2026. | Medium | SV014 |
| CV020 | CompaniesMarketCap shows Verisk's trailing revenue at about $3.10 billion in July 2026. | Medium | SV015 |
| CV021 | Using the retained Verisk market-cap and revenue figures gives a simple market-cap-to-revenue proxy of about 7.8x. | Medium | SV014, SV015 |
| CV022 | CompaniesMarketCap shows Moody's market cap at about $79.76 billion in July 2026. | Medium | SV017 |
| CV023 | CompaniesMarketCap shows Moody's trailing revenue at about $7.87 billion in July 2026. | Medium | SV018 |
| CV024 | Using the retained Moody's market-cap and revenue figures gives a simple market-cap-to-revenue proxy of about 10.1x. | Medium | SV017, SV018 |
| CV025 | CompaniesMarketCap shows TransUnion's market cap at about $14.06 billion in July 2026. | Medium | SV020 |
| CV026 | CompaniesMarketCap shows TransUnion's trailing revenue at about $4.72 billion in July 2026. | Medium | SV021 |
| CV027 | Using the retained TransUnion market-cap and revenue figures gives a simple market-cap-to-revenue proxy of about 3.0x. | Medium | SV020, SV021 |
| CV028 | CompaniesMarketCap shows NICE's market cap at about $5.58 billion in July 2026. | Medium | SV023 |
| CV029 | CompaniesMarketCap shows NICE's trailing revenue at about $2.94 billion. | Medium | SV024 |
| CV030 | Using the retained NICE market-cap and revenue figures gives a simple market-cap-to-revenue proxy of about 1.9x. | Medium | SV023, SV024 |
| CV031 | The reported $1.2 billion Exiger valuation implies about 8.0x revenue on Forbes's >$150 million 2024 revenue floor. | Low | SV003, SV008 |
| CV032 | If current revenue were already $175 million to $200 million, the same $1.2 billion valuation would compress to roughly 6.9x to 6.0x revenue. | Low | SV003, SV008 |
| CV033 | The retained public comp band spans roughly 1.7x to 10.1x revenue on simple market-cap-to-revenue proxies, with a median near 3.0x. | Medium | SV010, SV011, SV014, SV015, SV017, SV018, SV020, SV021, SV023, SV024 |
| CV034 | Exiger's 8.0x floor multiple sits above D&B, NICE, and TransUnion, near Verisk, and below Moody's. | Low | SV003, SV008, SV010, SV011, SV014, SV015, SV017, SV018, SV020, SV021, SV023, SV024 |
| CV035 | Chainalysis announced a $170 million Series F financing in 2022 that brought its valuation to $8.6 billion. | Medium | SV025, SV026 |
| CV036 | Interos raised $100 million in Series C financing and the retained article said the round valued the company at over $1 billion. | Low | SV027 |
| CV037 | TPG announced a $235 million strategic majority investment in Sayari in April 2024, but the retained public release did not disclose a valuation. | Medium | SV028 |
| CV038 | Mastercard agreed in 2024 to acquire Recorded Future from Insight Partners for $2.65 billion. | Medium | SV030 |
| CV039 | The retained 2026 adverse exit-market article says software exits face compressed multiples, slower liquidity, and more selective buyers. | Low | SV031 |
| CV040 | The retained public sources do not disclose Exiger's ARR, gross margin, NRR, services mix, burn, or public-sector revenue share. | Medium | SV001, SV002, SV005, SV006, SV007, SV008 |
| CV041 | The retained public sources do not disclose Carlyle and Insight's exact entry valuation terms, leverage, preference stack, or ownership split. | Medium | SV001, SV002, SV003, SV004 |
| CV042 | The bull case requires Exiger to already be materially above the $150 million floor and to look economically closer to Verisk or Moody's than to lower-band workflow or data vendors. | Low | SV008, SV014, SV015, SV017, SV018 |
| CV043 | A reasonable base case is that Exiger can create value but still only earn a modest uplift over the reported mark if it exits on a mid-single-digit multiple. | Low | SV008, SV014, SV015, SV020, SV021, SV031 |
| CV044 | A bear case that combines only moderate revenue growth with a 3x to 4x exit multiple can leave Exiger worth below the reported $1.2 billion valuation. | Low | SV008, SV010, SV011, SV020, SV021, SV031 |
| CV045 | At a $1.2 billion entry reference, sponsor-style 2x-plus gross returns appear available only if Exiger exits around $2.4 billion to $2.8 billion. | Low | SV003, SV008, SV031 |
| CV046 | Exiger's government footprint is clearly large in public materials, but exact public-sector revenue concentration remains unquantified. | Medium | SV005, SV006, SV007, SV008 |
| CV047 | Verisk, Moody's, and TransUnion all had 2026 first-quarter 10-Q filings on the SEC, confirming that the comp set includes current public reporting issuers. | Medium | SV016, SV019, SV022 |
| CV048 | Clearlake's August 2025 release said Dun & Bradstreet stockholders would receive $9.15 per share in cash. | Medium | SV012 |
| CV049 | Dun & Bradstreet's February 2025 results release said 2024 revenue was $2.3817 billion. | Medium | SV013 |
| CV050 | The retained evidence supports a research-more recommendation and a stretched valuation stance until management closes the current revenue, economics, concentration, and sponsor-term gaps. | Low | SV003, SV008, SV031 |
| ID | Publisher | Title | Quote |
|---|---|---|---|
| SO001 | Exiger | Exiger | Exiger unifies supplier, product, part, component, and risk data into a single platform. |
| SO002 | Exiger | Company - Exiger | Founded in 2013, Exiger has more than 850 employees in 10 global offices. |
| SO003 | Exiger | Meet Our Professionals | Brandon Daniels | Brandon Daniels is the CEO at Exiger. |
| SO004 | Exiger | Supply Chain | Exiger supports the largest global enterprise and government agencies. We’re a critical enabler for the U.S. Army. |
| SO005 | Exiger | Due Diligence for Risk and Compliance | Trusted by 150 Fortune 500 Companies and Over 60 Federal Agencies. |
| SO006 | Exiger | 1ExigerAI | By bringing together intelligence, decision support, and execution in one AI-native environment, it activates Exiger data alongside customer data. |
| SO007 | Exiger | Exiger Unveils 1Exiger, A Comprehensive New UX Designed to Make Supply Chain Management Simple, Intuitive and Accessible | 1Exiger offers seamless access to Exiger’s products – DDIQ, Insight 3PM, Ion Channel, SDX and Supply Chain Explorer. |
| SO008 | Exiger | Carlyle and Insight Partners to Invest in Exiger in Partnership with Management | Exiger ... will receive a majority investment from funds managed by Carlyle and Insight Partners. |
| SO009 | Carlyle | Carlyle and Insight Partners to Invest in Exiger, a High-Growth AI Supply Chain Risk & Resilience Software Company, in Partnership with Management | The company serves over 500 customers globally, including 150 of the Fortune 500. |
| SO010 | Insight Partners | Exiger | Investment | Insight Partners | Exiger | Investment | Insight Partners |
| SO011 | Exiger | Exiger Announces $80 Million Minority Growth Capital Investment by Carrick Capital Partners | Carrick ... has invested $80 million. |
| SO012 | Exiger | Brandon Daniels Named CEO of Exiger | Daniels joined Exiger in early 2017. |
| SO013 | Exiger | Exiger Leads Market in AI-Driven Multi-Tier Visibility with Versed AI Acquisition | Versed AI automatically maps and contextualizes complex supply chains. |
| SO014 | Exiger | Exiger Acquires Widely Adopted Proprietary Parts Intelligence Company XSB | The acquisition combines ... engineering analytics platform with Exiger’s own proprietary data and AI. |
| SO015 | Exiger | Exiger Wins Multi-Million Dollar U.S. Army AI Contract to Transform Defense Supply Chains | Exiger ... has been awarded a multi-million dollar contract from the U.S. Army to license its 1Exiger software to Army Materiel Command. |
| SO016 | Exiger / OpenCorporates | Case Study: How DDIQ Automates Due Diligence Verification with OpenCorporates’ Data | Over a million DDIQ due diligence reports have been driven in part by OpenCorporates’ data. |
| SO017 | Exiger | How Oshkosh is Building Durability and Transparency into a Stronger Supply Chain | Improved forecasting accuracy by 10 – 20 percent with favorable working capital impact. |
| SO018 | Exiger | SMBC Selects Exiger’s DDIQ as a New AI AML Tool in EMEA Region | SMBC selected DDIQ to deploy throughout its client onboarding and monitoring processes. |
| SO019 | Exiger | Fortune 500 Multinational Corporation - Exiger | The company saved over $750K annually and introduced an effective process to manage the risks associated with their business partners. |
| SO020 | Exiger | Top 10 Regional Bank in the US | Exiger’s review of the alert population resulted in a 5.5% SAR filing rate. |
| SO021 | Exiger | Global Investment Bank Diversifies Its Banking Capabilities | The client has been able to leverage Exiger’s risk analysis and recommendations for an optimal control environment. |
| SO022 | Forbes | Exiger Has Taken The Supply Chain Risk Market By Storm | Mr. Daniels reports they have 870 employees ... and will have over $150 million in revenues by the end of the year. |
| SO023 | PR Newswire | U.S. Army Licenses 1Exiger AI Software to Accelerate Defense Acquisition, Reduce Lead Times and Enhance Operational Readiness | Exiger empowers 550+ global customers, including 150 Fortune 500 and 60+ government and Defense Industrial Base organizations. |
| SO024 | Homeland Security Today | U.S. Army Licenses 1Exiger AI Software to Accelerate Defense Acquisition, Reduce Lead Times and Enhance Operational Readiness | Exiger has announced that it has been awarded a multi-million dollar contract from the U.S. Army to license its 1Exiger software. |
| SO025 | PR Newswire | Exiger CEO Brandon Daniels Named 2026 Wash100 Award Winner | Exiger empowers 550+ global customers, including 150 Fortune 500 and 60+ government and Defense Industrial Base organizations. |
| SO026 | Wash100 | Exiger’s Brandon Daniels Secures 1st Wash100 Award Win | Founded in 2013, Exiger is a global technology company ... Headquartered in McLean, Virginia. |
| SO027 | WashingtonExec | Exiger Earns Awardable Status on P1 Solutions Marketplace | Exiger has achieved “Awardable” status on the Platform One Solutions Marketplace. |
| SO028 | Federal News Network | DoD Cloud Exchange 2024: Exiger’s Cameron Holt on SCRM across the hybrid cloud enterprise | To deepen its SCRM offerings Exiger acquired a company called Ion Channel. |
| SO029 | World Economic Forum | Exiger | Emboldening its 550 customers worldwide, including 150 in the Fortune 500 and over 50 government agencies. |
| SO030 | Aerospace Defense Review | Exiger | Supply Chain Management Company of the Year 2025 | With nearly a thousand employees across the globe ... driving its valuation to $1.2 billion. |
| SO031 | Gartner Peer Insights | 1Exiger Reviews & Ratings 2026 | Gartner Peer Insights | Strong supply chain visibility with challenging setup for workflow tuning. |
| SO032 | The Enterprise World | Making the World a Safe and Transparent Place to Succeed: A Look at the Operational Transformation of Exiger | These initiatives delivered nearly $20 million in annual cost savings. |
| SO033 | Exiger | Adverse Media Monitoring - Exiger | A major investment bank came to us looking for a solution to monitor a group of high-risk PWM foreign customers. |
| SM001 | Exiger | Exiger | Exiger unifies supplier, product, part, component, and risk data into a single platform to help customers map and orchestrate compliant and resilient physical and software supply chains. |
| SM002 | Exiger | Supply Chain | Exiger generates proprietary, product-aware data through the world’s largest engineering knowledge graph so users can see hidden dependencies and part-level risk, not just entity scores. |
| SM003 | Exiger | Third Party Risk Management - Exiger | Exiger’s platform delivers comprehensive third-party risk management with automated onboarding and offboarding, tailored conditional workflows, precise risk assessments, and proactive issue remediation. |
| SM004 | Exiger | Risk and Compliance | 1Exiger is the complete platform for Trade Compliance, Third-Party Risk Management, Supplier Risk Management, Enhanced Due Diligence, and Know Your Customer. |
| SM005 | Exiger | Supply Chain Risk Management - Exiger | For larger companies, suppliers are in the tens of thousands, each with its own unique threat landscape. |
| SM006 | Exiger | Software Supply Chain Security | Software supply chain security adds upstream provenance, components, and suppliers across IT, OT, firmware, and open source. |
| SM007 | Exiger | Protecting the Defense Supply Chain | Exiger’s AI-driven tools provide real-time supply chain mapping, risk illumination, and compliance support—enhancing resilience, securing critical components, and reducing reliance on adversarial suppliers. |
| SM008 | Exiger | Supply Chain Transparency to Bolster the Defense Industrial Base | The ability to source alternative suppliers can be a strategic advantage when geopolitical events dictate a shift in alliances. |
| SM009 | Exiger | Advanced Compliance and Risk Management for Financial Institutions | Exiger’s AI-driven technology solutions create the sustainable, auditable approach to identifying, mitigating, and remediating risk that financial institutions need. |
| SM010 | Department of Defense CIO | CIO - About CMMC | CMMC Phase 1 Implementation (Nov 10, 2025 - Nov 9, 2026) focuses primarily on CMMC Level 1 and Level 2 self-assessments. |
| SM011 | Acquisition.gov | 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. | CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025). |
| SM012 | U.S. Customs and Border Protection | Uyghur Forced Labor Prevention Act Enforcement Statistics | CBP updated this UFLPA Enforcement Statistics Dashboard in 2026 to provide greater transparency, including shipment count or shipment value and HTS-4 detail. |
| SM013 | U.S. Customs and Border Protection | Uyghur Forced Labor Prevention Act | CBP enforces the rebuttable presumption that goods mined, produced, or manufactured wholly or in part in the XUAR or by an entity on the UFLPA Entity List are prohibited. |
| SM014 | The White House | Executive Order on America's Supply Chains | The White House | The United States needs resilient, diverse, and secure supply chains to ensure our economic prosperity and national security. |
| SM015 | NIST | CHIPS FOR AMERICA | Semiconductors are integral to America’s economic and national security and essential to virtually all military systems. |
| SM016 | Department of Defense Manufacturing Technology Program | DOD Releases First Defense Industrial Strategy | The strategy focuses on four key areas critical to building a modernized defense industrial ecosystem: resilient supply chains, workforce readiness, flexible acquisition, and economic deterrence. |
| SM017 | U.S. Government Accountability Office | GAO-25-107283, DEFENSE INSUSTRIAL BASE: Actions Needed to Address Risks Posed by Dependence on Foreign Suppliers | DOD estimates that over 200,000 suppliers help produce advanced weapon systems and noncombat goods. |
| SM018 | Office of Foreign Assets Control | Sanctions Programs and Country Information | The OFAC sanctions programs page shows active programs with update dates extending into 2026. |
| SM019 | Bureau of Industry and Security | EAR | Bureau of Industry and Security | The Entity List under Part 744 imposes license requirements for listed persons because of national-security or foreign-policy concerns. |
| SM020 | Research and Markets | Third-party Risk Management Market Report 2026 - Research and Markets | The Third-party Risk Management Market, valued at USD 8.09B in 2026, is projected to reach USD 15.45B by 2030, growing at a 17.6% CAGR. |
| SM021 | Polaris Market Research | Third-Party Risk Management Market Trend & Global Analysis 2034 | Market Size in 2026: USD 9.34 Billion. |
| SM022 | Grand View Research | Third-party Risk Management Market Size Report, 2030 | The global third-party risk management market size was estimated at USD 7.42 billion in 2023 and is projected to reach USD 20.59 billion by 2030. |
| SM023 | The Business Research Company | Supply Chain Risk Management Market Size, Growth Report 2026 | The supply chain risk management market will grow from $3.45 billion in 2025 to $3.73 billion in 2026. |
| SM024 | Fortune Business Insights | Supply Chain Risk Management Market Size, Industry Share, Forecast to 2034 | The market is projected to grow from USD 5.85 billion in 2026 to USD 16.93 billion by 2034. |
| SM025 | Coherent Market Insights | Supply Chain Risk Management Market Share & Analysis 2033 | Supply Chain Risk Management Market size crosses USD 6,912.6 Mn in 2026. |
| SM026 | Industry Research | Sanctions Screening Software Market - Size, Share & Industry Forecast | The global Sanctions Screening Software Market in terms of revenue was estimated to be worth USD 586.71 Million in 2026. |
| SM027 | Global Information / Stratistics MRC | Sanctions Screening Solutions Market Forecasts to 2034 | The Global Sanctions Screening Solutions Market is accounted for $4.2 billion in 2026. |
| SM028 | Troutman Pepper Locke | High-Voltage Enforcement: UFLPA Turns Up the Heat on Lithium-Ion and Energy Storage Imports | Through early 2026, CBP has reviewed more than 18,000 shipments with an aggregate value of approximately $3.81 billion. |
| SM029 | Government Contracts Navigator | DoD Seeks “Unprecedented Level of Visibility” into the Supply Chain Under Newly Proposed Regulations - Government Contracts Navigator | Any contractor or subcontractor with a DoD contract exceeding five million dollars will need to report its FOCI status in the National Industrial Security System. |
| SM030 | Schellman | CMMC Final Rule: Key Changes and How to Prepare | The CMMC Final Rule became effective November 10, 2025 and full implementation is just beginning. |
| SM031 | Dun & Bradstreet | Dun & Bradstreet | Third-Party Risk Analysis | Disconnected data creates incomplete and inaccurate views of third parties and their relationships, causing increased potential for compliance risk. |
| SP001 | Exiger | Products - Exiger | |
| SP002 | Exiger | Exiger at AI+ Expo 2026 | At the Exiger booth, visitors slipped on headsets to augment reality and step into the platform that powers one third of the Fortune 500 and more than 60 federal agencies and DIB members. |
| SP003 | PR Newswire | Exiger Named to The Hackett Group's 2026 "50 to Know" in Procurement Tech | A key differentiator is Exiger's ability to analyze risk at the component, hardware and software level. |
| SP006 | PR Newswire | Dun & Bradstreet Introduces Agentic AI Capabilities to Accelerate Compliance and Third-Party Risk Workflows from Days to Seconds | New capabilities combine verified business context with AI agents to automate onboarding, screening and due diligence. |
| SP007 | LSEG | LSEG Risk Intelligence | |
| SP008 | LSEG | World-Check - KYC Screening | |
| SP009 | LSEG | LSEG World-Check On Demand | |
| SP010 | LexisNexis Risk Solutions | Financial Crime Compliance & Risk Management Solutions | |
| SP011 | Coupa | Supplier Risk & Performance | Coupa | |
| SP012 | Moody's | Strengthening Supplier Risk Management with the Moody's Connector for Coupa | |
| SP013 | Aravo | Risk Domain and Compliance Applications | |
| SP014 | ProcessUnity | Third-Party Risk Management Platform | |
| SP015 | Business Wire | ProcessUnity Recognized as a Leader in 2026 Third-Party Risk Management Platforms Report | The report notes that ProcessUnity differentiates in risk identification with features such as dynamic scoping of questionnaire depth and cadence, risk response with preconfigured AI workflows, and powerful visualization. |
| SP016 | Ivalua | Supplier Risk Management Solutions Software | Supplier Risk | Ivalua | |
| SP017 | Supply Wisdom | Real-Time Third-Party and Location Risk Management Solutions | |
| SP018 | Supply Wisdom | Supply Chain Risk Management Solutions | Supply Wisdom | |
| SP019 | Sayari | Supply Chain Risk Management & Compliance | Sayari | Self-reported supplier questionnaires don't reveal sub-tier supplier exposure, forced labor risk, or ownership by sanctioned parties. |
| SP020 | Sayari | Supply Chain Compliance Software | Sayari | Sayari provides unified supply chain risk intelligence: trade data, corporate ownership, and sanctions screening in a single platform. |
| SP022 | K2 Integrity | Financial Crimes Risk Management | |
| SP023 | interos.ai | Supply Chain Risk Management Software | |
| SP024 | Business Wire | interos.ai Launches iQ to Elevate Supply Chain Risks to the C-Level | |
| SP026 | KPMG | Coupa | Identify, assess, and mitigate supplier risk | |
| SP027 | K2 Integrity | Home | |
| SP029 | Dun & Bradstreet | Risk Analytics Compliance Intelligence | Dun & Bradstreet | D&B Compliance Intelligence provides key risk insights from over 10,000 global sources covering over 550 million entities worldwide. |
| SP030 | LSEG | World‑Check One Usage Packages | Flexible points-based pricing, giving you control over how and when to use the services. |
| SI001 | Exiger | Exiger | |
| SI002 | Exiger | Company - Exiger | Founded in 2013, Exiger has more than 850 employees in 10 global offices. |
| SI003 | Exiger | 1ExigerAI | AI uncovered 20,000+ hidden downstream entities and cut signal noise by 45%, enabling scalable oversight across 50,000+ customers and distributors. |
| SI004 | Exiger | Products - Exiger | |
| SI005 | Exiger | Public Sector | |
| SI006 | Exiger | Carlyle and Insight Partners to Invest in Exiger in Partnership with Management | Exiger has entered into a definitive agreement through which it will receive a majority investment from funds managed by Carlyle and Insight Partners. |
| SI007 | Exiger | Exiger Announces $80 Million Minority Growth Capital Investment by Carrick Capital Partners | Carrick has invested $80 million. |
| SI008 | Exiger | Exiger Acquires Supply Dynamics to Create First End-to-End Supply Chain Visibility and Supplier Risk Management Solution | Exiger announced today that it has acquired Supply Dynamics. |
| SI009 | Exiger | Exiger Acquires Widely Adopted Proprietary Parts Intelligence Company XSB | The company’s catalog spans 100 million parts and 400 million parts attributes used by the U.S. Federal Government. |
| SI010 | Exiger | Exiger Leads Market in AI-Driven Multi-Tier Visibility with Versed AI Acquisition | Versed AI is a spin-out from Cambridge University, a Gartner Cool Vendor in Sourcing and Procurement Technologies, and is ISO 27001 certified. |
| SI011 | Exiger | Exiger Announces Capgemini Will Acquire its FCC Advisory Division as Exiger Continues to Accelerate and Focus the Scaling of its Third Party Risk and Supply Chain Management Technology Business | Capgemini’s acquisition allows us to focus on our core third-party risk and supply chain management technology business. |
| SI012 | Exiger | Exiger Launches Supply Chain AI Platform in AWS Marketplace | Exiger announced that its supply chain and third-party risk intelligence platform, 1Exiger, is now available in AWS Marketplace. |
| SI013 | Exiger | Exiger Named Gartner Magic Quadrant Leader 2026 | Exiger empowers 550+ global customers, including 150 Fortune 500 and 60+ government and Defense Industrial Base organizations, with supply chain AI. |
| SI014 | Exiger | Exiger Named Value Leader in The Hackett Group’s Spring 2026 SolutionMap for Procurement Technology | Exiger was evaluated as part of an assessment spanning 118 vendors across 16 source-to-pay categories. |
| SI015 | Exiger | 1ExigerAI Activation Series | The 1ExigerAI Activation Series brings senior leaders together in select cities throughout 2026. |
| SI016 | Carlyle | Carlyle and Insight Partners to Invest in Exiger, a High-Growth AI Supply Chain Risk & Resilience Software Company, in Partnership with Management | Exiger announced today that it has entered into a definitive agreement through which it will receive a majority investment from funds managed by Carlyle and Insight Partners. |
| SI017 | Forbes | Exiger Has Taken The Supply Chain Risk Market By Storm | Mr. Daniels reports they will have over $150 million in revenues by the end of the year and that over the last five years they have had a compound annual growth rate of over 80 percent. |
| SI018 | PR Newswire | Exiger Named to The Hackett Group's 2026 "50 to Know" in Procurement Tech | Exiger empowers 550+ global customers, including 150 Fortune 500 and 60+ government and Defense Industrial Base organizations, with supply chain AI. |
| SI019 | World Economic Forum | Exiger | Exiger's mission is to make the world a safer and more transparent place to succeed. Emboldening its 550 customers worldwide, including 150 in the Fortune 500 and over 50 government agencies... |
| SI020 | Verisk | Verisk Analytics, Inc. - Investor Relations | Verisk is a leading strategic data analytics and technology partner to the global insurance industry. |
| SI021 | StockAnalysis | Verisk Analytics (VRSK) Financials & Income Statement | Revenue FY 2025: 3,073; Gross Profit FY 2025: 2,147. |
| SI022 | StockAnalysis | Verisk Analytics (VRSK) Stock Price & Overview | Market Cap 23.52B; Revenue (ttm) 3.10B. |
| SI023 | StockAnalysis | Dun & Bradstreet Holdings (DNB) Financials & Income Statement | Revenue FY 2024: 2,382; Revenue Growth (YoY): 2.93%. |
| SI024 | StockAnalysis | Dun & Bradstreet Holdings (DNB) Stock Price & Overview | Dun & Bradstreet Holdings agreed to be acquired by private equity firm Clearlake Capital Group in a transaction valued at $7.7 billion, including outstanding debt. |
| SI025 | Securities and Exchange Commission | Verisk Analytics 2025 Form 10-K | ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 For the fiscal year ended December 31, 2025. |
| SI026 | Securities and Exchange Commission | Dun & Bradstreet Holdings 2024 Form 10-K | ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934 For the Fiscal Year Ended December 31, 2024. |
| SI027 | Federal Trade Commission | Privacy and Security Enforcement | The FTC has brought legal actions against organizations that have violated consumers’ privacy rights, or misled them by failing to maintain security for sensitive consumer information. |
| SI028 | U.S. Customs and Border Protection | Uyghur Forced Labor Prevention Act | CBP enforces the rebuttable presumption that goods mined, produced, or manufactured wholly or in part in the XUAR ... are prohibited from U.S. importation. |
| SE001 | Exiger | Products | |
| SE002 | Exiger | Supply Chain | |
| SE003 | Exiger | Due Diligence for Risk and Compliance | |
| SE004 | Exiger | 1ExigerAI | |
| SE005 | Exiger | Exiger Launches Supply Chain AI Platform in AWS Marketplace | |
| SE006 | Exiger | Exiger Achieves FedRAMP® Authorization for Supply Chain AI | |
| SE007 | FedRAMP Marketplace | Exiger Federal Cloud (EFC) | FedRAMP Marketplace | |
| SE008 | Exiger | Exiger Leads Market in AI-Driven Multi-Tier Visibility with Versed AI Acquisition | |
| SE009 | Exiger | Exiger Acquires Widely Adopted Proprietary Parts Intelligence Company XSB | |
| SE010 | Exiger | Exiger Acquires Supply Dynamics to Create First End-to-End Supply Chain Visibility and Supplier Risk Management Solution | |
| SE011 | Exiger | Exiger AI Supply Chain Risk Management and Orchestration Now Embedded in Snowflake Energy Solutions | |
| SE012 | Exiger | Digital Thread and Parts Intelligence | |
| SE013 | Exiger | Case Study: How DDIQ Automates Due Diligence Verification with OpenCorporates’ Data | |
| SE014 | OpenCorporates | Exiger – OpenCorporates | |
| SE015 | LexisNexis Risk Solutions | WorldCompliance™ Data: Trusted Compliance Database | |
| SE016 | Carahsoft | Exiger Government Solutions 1Exiger | Carahsoft | |
| SE017 | PR Newswire | Exiger Launches Supply Chain AI Platform in AWS Marketplace | |
| SE018 | XSB | Exiger, the Market-Leading Supply Chain and Third-Party Risk AI Company, Acquires Logistics Intelligence Platform XSB | |
| SE019 | Progress Partners | XSB Acquired By Exiger | Progress Partners | |
| SE020 | Built In | Exiger Jobs + Careers | Built In | |
| SE021 | Built In | Full Stack Developer - Exiger | |
| SE022 | Software Advice | DDIQ Software Reviews, Demo & Pricing | |
| SE023 | Exiger | Tour 1ExigerAI | |
| SE024 | Exiger | 1ExigerAI Activation Series | |
| SE025 | Exiger | From Reactive to Predictive: How AI Is Redefining Third-Party Risk Management in 2026 | |
| SE026 | Exiger | Exiger Advances AI-Native Supply Chain Intelligence at 2026 SCSP AI+ Expo | |
| SE027 | GLACIS | AI Vendor Due Diligence: Complete Checklist 2026 | |
| SU001 | Exiger | Exiger | |
| SU002 | Exiger | Customer Success Stories - Exiger | |
| SU003 | Exiger | Advanced Compliance and Risk Management for Financial Institutions | Exiger’s AI-driven technology solutions create the sustainable, auditable approach to identifying, mitigating, and remediating risk that financial institutions need. |
| SU004 | Exiger | Federal Contract Vehicles - Exiger | Contract Ceiling: $74,500,000. Availability: Open to all U.S. Government Departments and Agencies. |
| SU005 | Exiger | Exiger Wins Multi-Million Dollar U.S. Army AI Contract to Transform Defense Supply Chains | Exiger ... has been awarded a multi-million dollar contract from the U.S. Army to license its 1Exiger software to Army Materiel Command (AMC). |
| SU006 | PR Newswire | U.S. Army Licenses 1Exiger AI Software to Accelerate Defense Acquisition, Reduce Lead Times and Enhance Operational Readiness | |
| SU007 | Homeland Security Today | U.S. Army Licenses 1Exiger AI Software to Accelerate Defense Acquisition, Reduce Lead Times and Enhance Operational Readiness - HSToday | |
| SU008 | WashingtonExec | Exiger Earns Awardable Status on P1 Solutions Marketplace | |
| SU009 | Exiger | Exiger is “Awardable” for DoW Work in P1 Solutions Marketplace | Exiger’s AI is deployed across the U.S. Government, including recent contract wins with the U.S. Army and Customs and Border Protection. |
| SU010 | Exiger | Exiger Launches Supply Chain AI Platform in AWS Marketplace | Availability in AWS Marketplace accelerates customers’ access to these capabilities without the traditional, lengthy procurement process. |
| SU011 | AWS Marketplace | Unified Supply Chain & Third-Party Risk Intelligence Platform | |
| SU012 | Exiger | Exiger Wins Government-Wide $919 Million GSA Supply Chain Risk Illumination Award | Convergent Solutions, Inc., DBA Exiger Government Solutions, is the highest-ranked unrestricted vendor awardee of the 10-year, $919 million contract. |
| SU013 | USAspending | CONTRACT to CONVERGENT SOLUTIONS, INC. | USAspending | |
| SU014 | Exiger | U.S. Customs and Border Protection Selects Exiger’s AI as Critical Tool for Detection of Illicit Transshipment | Exiger ... has been awarded a multi-million dollar contract by U.S. Customs and Border Protection (CBP) to modernize the detection of illicit transshipment across global supply chains. |
| SU015 | GovCon | Exiger Wins Government-Wide $919M GSA Supply Chain Risk Illumination Award | |
| SU016 | Exiger | Exiger Recognized in the 2025/26 ProcureTech100 | |
| SU017 | Exiger | Exiger Named to The Hackett Group’s 2025–2026 “50 to Know” in Procurement Technology | Exiger empowers 550+ global customers, including 150 Fortune 500 and 60+ government and Defense Industrial Base organizations, with supply chain AI. |
| SU018 | Exiger | Exiger is the Highest in Execution and Furthest in Vision in the Gartner® Magic Quadrant™ for Supplier Risk Management | |
| SU019 | Gartner Peer Insights | 1Exiger Reviews & Ratings 2026 | Gartner Peer Insights | What I dislike most about it is that it can be complex to implement and tune for specific workflows. |
| SU020 | PeerSpot | 1Exiger Reviews, Competitors and Pricing | |
| SU021 | Craft | Exiger Company Profile - Office Locations, Competitors, Revenue, Financials, Employees, Key People, Subsidiaries | Craft.co | |
| SU022 | Exiger | PRESS RELEASE: Northwell Health Partners with Exiger for Supplier Risk Management and Supply Chain Risk | Northwell previously used multiple tools to perform vendor due diligence, but sought a “one-stop shop” to consolidate its efforts. |
| SU023 | Exiger | How Oshkosh is Building Durability and Transparency into a Stronger Supply Chain | Today, over 40 Tier 1 fabricators have logged in to SDX to validate their bills of material for Oshkosh. |
| SU024 | Exiger | Top 10 Regional Bank in the US | Exiger’s quality and pace was recognized by the Bank and Exiger was asked to continue working through its BAU population as an extension of the team for an additional 5 months. |
| SU025 | Exiger | Global Investment Bank Diversifies Its Banking Capabilities | |
| SU026 | Exiger | Global FinTech Requests Expedited Client KYC Refresh | Exiger was retained for five months to conduct their EDD file remediation including all customer open-source research analysis as well as watchlist screening of approximately 20,000 associated parties. |
| SU027 | Exiger | Responding to Customer Demands for SBOMs | The company’s customers were requesting SBOMs to guarantee the integrity of their software supply chain to mitigate risk exposure to vulnerabilities. |
| SU028 | Exiger | Solution Improves Visibility, Continuity of Supply, and Risk Management for US Government Client | |
| SU029 | Exiger | Pharma Supply Chain Mapping for the Government | |
| SU030 | Exiger | A Vertically Integrated Approach to Third-Party and Supply Chain Risk Management in Healthcare | |
| SR001 | Exiger | Privacy and Legal Center - Exiger | The DPA says Customer is the data controller and Exiger is the data processor under applicable data protection law. |
| SR002 | Exiger | Exiger | Terms and Conditions | This Website provides the User with access to DDIQ and/or Insight 3PM, which are proprietary technologies owned by Exiger. |
| SR003 | Exiger | Federal Contract Vehicles - Exiger | Contract Ceiling: $74,500,000 ... Availability: Open to all U.S. Government Departments and Agencies. |
| SR004 | Exiger | Exiger Achieves FedRAMP® Authorization for Supply Chain AI | Exiger Federal Cloud has achieved Federal Risk and Authorization Management Program (FedRAMP) Moderate Authorization. |
| SR005 | Exiger | Exiger Launches Supply Chain AI Platform in AWS Marketplace | 1Exiger is now available in AWS Marketplace. |
| SR006 | Carahsoft | Exiger Government Solutions Government IT Procurement Contracts | Carahsoft | |
| SR007 | AWS Marketplace | Exiger seller profile - AWS Marketplace | Exiger empowers 550+ global customers, including 150 Fortune 500 and 60+ government and Defense Industrial Base organizations, with supply chain AI. |
| SR008 | PR Newswire | Exiger Achieves FedRAMP® Authorization for Supply Chain AI | Exiger Federal Cloud has achieved Federal Risk and Authorization Management Program (FedRAMP®) Moderate Authorization. |
| SR009 | The Chertoff Group | Exiger and The Chertoff Group Unveil Supply Chain Product Assurance Playbook | The playbook identifies, assesses, and remediates risks in hardware and software products and supply chains. |
| SR010 | XSB | Exiger, the Market-Leading Supply Chain and Third-Party Risk AI Company, Acquires Logistics Intelligence Platform XSB | The acquisition brings XSB’s 100M+ parts and 400M+ parts attributes database in-house to Exiger. |
| SR011 | Supply & Demand Chain Executive | Exiger Acquires Proprietary Parts Intelligence Company XSB | |
| SR012 | FeaturedCustomers | 30 Exiger Customer Reviews & References | |
| SR013 | FedRAMP | FedRAMP | FedRAMP.gov | FedRAMP is a government-wide program that provides a standardized approach to security assessment. |
| SR014 | U.S. Treasury OFAC | Home | Office of Foreign Assets Control | |
| SR015 | U.S. Treasury OFAC | Sanctions List Service | Office of Foreign Assets Control | OFAC’s Sanctions List Service provides users with easy access to the most up-to-date sanctions lists and data ready for immediate download. |
| SR016 | U.S. Bureau of Industry and Security | Homepage | Bureau of Industry and Security | |
| SR017 | U.S. Customs and Border Protection | Uyghur Forced Labor Prevention Act | CBP enforces the rebuttable presumption that goods mined, produced, or manufactured wholly or in part in the XUAR, or by an entity on the UFLPA Entity List, are prohibited from U.S. importation. |
| SR018 | U.S. Customs and Border Protection | Forced Labor | CBP’s forced labor enforcement efforts safeguard U.S. economic and national security. |
| SR019 | Federal Trade Commission | Privacy and Security | |
| SR020 | European Commission | Data protection | EU data protection legislation is comprised of the General Data Protection Regulation (GDPR), the Law Enforcement Directive (LED), and the Data Protection Regulation for EU institutions. |
| SR021 | EU Artificial Intelligence Act | EU Artificial Intelligence Act | Up-to-date developments and analyses of the EU AI Act | |
| SR022 | Securities and Exchange Commission | SEC Proposes Transformative Reforms to Help Public Companies Conduct Registered Offerings and Simplify Reporting Requirements | The SEC proposed amendments designed to increase efficiency, flexibility, and cost savings for public companies while maintaining robust investor protections. |
| SR023 | Securities and Exchange Commission | SEC.gov | 2026 Examination Priorities | |
| SR024 | PACER | PACER | PACER Case Locator | The PACER Case Locator is a national index for district, bankruptcy, and appellate courts. |
| SR025 | U.S. Courts | Find a Case (PACER) | Locate a federal court case by using PACER or by visiting the Clerk’s Office of the courthouse where the case was filed. |
| SR026 | Exiger | From Reactive to Predictive: How AI Is Redefining Third-Party Risk Management in 2026 | Leading programs are replacing static compliance with dynamic intelligence by using AI solutions to map hidden supplier networks, detect emerging risks in real time, and predict disruption before it strikes. |
| SR027 | Exiger | Exiger Wins Multi-Million Dollar U.S. Army AI Contract to Transform Defense Supply Chains | Exiger has been awarded a multi-million dollar contract from the U.S. Army to license its 1Exiger software to Army Materiel Command. |
| SR028 | USAspending.gov | Federal Awards | Advanced Search | USAspending | |
| SR029 | SAM.gov | Contracting | SAM.gov | SAM.gov is a centralized source for finding and bidding on U.S. government contract opportunities, awards and publishing subcontract reports. |
| SR030 | U.S. Bureau of Industry and Security | EAR | Bureau of Industry and Security | This tool simplifies access to the EAR, 15 CFR Parts 730-774, but it does not replace the official legal editions of the CFR or Federal Register. |
| SR031 | Exiger | Carlyle and Insight Partners to Invest in Exiger in Partnership with Management | Exiger will receive a majority investment from funds managed by Carlyle and Insight Partners. |
| SR032 | Exiger | Exiger Acquires Supply Dynamics to Create First End-to-End Supply Chain Visibility and Supplier Risk Management Solution | Exiger acquired Supply Dynamics to integrate item-level visibility and multi-tier supply chain mapping into one cloud platform. |
| SR033 | Exiger | Exiger Leads Market in AI-Driven Multi-Tier Visibility with Versed AI Acquisition | The acquisition expands Exiger’s AI-driven multi-tier supply chain visibility, data and mapping. |
| SV001 | Exiger | Carlyle and Insight Partners to Invest in Exiger in Partnership with Management | Exiger announced that it entered into a definitive agreement to receive a majority investment from Carlyle and Insight Partners. |
| SV002 | Carrick Capital Partners | Carlyle and Insight Partners to Invest in Exiger, a High-Growth AI Supply Chain Risk & Resilience Software Company, in Partnership with Management | |
| SV003 | Private Equity Insights | Carlyle, Insight to Buy Exiger at $1.2 Billion Value | Carlyle and Insight agreed to buy Exiger at a $1.2 billion value. |
| SV004 | Alternatives Watch | Carlyle, Insight Partners acquire majority stake in SaaS provider Exiger | The valuation of the stake was not disclosed, but The Wall Street Journal pegged it at about $1.2 billion. |
| SV005 | AWS Marketplace | Exiger - AWS Marketplace seller profile | Exiger empowers 550+ global customers, including 150 Fortune 500 and 60+ government and Defense Industrial Base organizations. |
| SV006 | PR Newswire | Exiger Launches Supply Chain AI Platform in AWS Marketplace | |
| SV007 | PR Newswire | Exiger Named to The Hackett Group's 2026 "50 to Know" in Procurement Tech | |
| SV008 | Forbes | Exiger Has Taken The Supply Chain Risk Market By Storm | Mr. Daniels reports they will have over $150 million in revenues by the end of the year and that over the last five years they have had a compound annual growth rate of over 80 percent. |
| SV009 | Exiger | Exiger Announces $80 Million Minority Growth Capital Investment by Carrick Capital Partners | Carrick has invested $80 million. |
| SV010 | CompaniesMarketCap | Dun & Bradstreet (DNB) - Market capitalization | |
| SV011 | CompaniesMarketCap | Dun & Bradstreet (DNB) - Revenue | |
| SV012 | Clearlake Capital Group | Clearlake Completes Acquisition of Dun & Bradstreet | Dun & Bradstreet stockholders will receive $9.15 in cash for each share they own. |
| SV013 | Nasdaq | Dun & Bradstreet Reports Fourth Quarter and Full Year 2024 Financial Results | |
| SV014 | CompaniesMarketCap | Verisk Analytics (VRSK) - Market capitalization | |
| SV015 | CompaniesMarketCap | Verisk Analytics (VRSK) - Revenue | |
| SV016 | Securities and Exchange Commission | Verisk Analytics 2026 Q1 Form 10-Q | |
| SV017 | CompaniesMarketCap | Moody's (MCO) - Market capitalization | |
| SV018 | CompaniesMarketCap | Moody's (MCO) - Revenue | |
| SV019 | Securities and Exchange Commission | Moody's 2026 Q1 Form 10-Q | |
| SV020 | CompaniesMarketCap | TransUnion (TRU) - Market capitalization | |
| SV021 | CompaniesMarketCap | TransUnion (TRU) - Revenue | |
| SV022 | Securities and Exchange Commission | TransUnion 2026 Q1 Form 10-Q | |
| SV023 | CompaniesMarketCap | NICE (NICE) - Market capitalization | |
| SV024 | CompaniesMarketCap | NICE (NICE) - Revenue | |
| SV025 | Chainalysis | Chainalysis Series F financing announcement | Chainalysis announced a $170 million Series F financing that brought its valuation to $8.6 billion. |
| SV026 | PR Newswire | Chainalysis Doubles Private Sector Business and Raises New Funding to Double Its Valuation to $8.6 Billion | |
| SV027 | The SaaS News | Interos Raises $100 Million in Series C | The round brought the company's valuation to over $1 billion. |
| SV028 | TPG | Sayari Closes $235 Million Strategic Investment from TPG | TPG Growth closed a $235 million strategic majority investment in Sayari. |
| SV030 | Mastercard | Mastercard invests in continued defense of global digital economy with acquisition of Recorded Future | Mastercard agreed to acquire Recorded Future from Insight Partners for $2.65 billion. |
| SV031 | UCapital | Private equity exit crunch in 2026: how software valuations are reshaping buyout strategies | Sponsors are facing compressed software valuations, market volatility, and longer holding periods in 2026. |