Ontic Technologies
Series C Growth-Stage Security Intelligence Platform Diligence
Well-funded Series C security intelligence platform with strong market tailwinds but unproven unit economics and legacy reputational risk
Cover facts
Company profile
Ontic Technologies is an Austin-based enterprise SaaS company providing AI-powered Connected Intelligence software that helps corporate and government security teams identify threats, assess risk, and respond faster. The platform unifies security operations data into a centralized system of record, aggregating open-source intelligence and external threat signals alongside internal organizational data. Founded in 2017 and backed by $287M in total funding including a $230M Series C led by KKR in August 2025, Ontic serves Fortune 500 companies and federal agencies with programs spanning executive protection, threat intelligence, investigations, and workplace violence prevention.
- Website
- ontic.co
- Founded
- 2017-01-01
- Founders
- Lukas Quanstrom
- Founding location
- Austin, Texas, USA
- Headquarters
- Austin, Texas, USA
- Product
- Connected Intelligence Platform that unifies OSINT, threat signals, and internal data (HR, legal, IT, facilities) into a centralized system for risk assessment, incident management, investigations, case management, and executive protection.
- Customers
- Fortune 500 enterprises, federal government agencies, and large organizations with complex physical security and protective intelligence needs
- Business model
- Enterprise SaaS subscription with per-module pricing for risk intelligence, investigations, case management, and threat monitoring capabilities
- Stage
- Series C
- Funding status
- $230M Series C led by KKR (August 2025); $287M total raised across 4 rounds
Executive summary
Top strengths
- KKR-led $230M Series C provides institutional validation and growth capital for multi-year expansion
- FedRAMP Moderate Authorization unlocks federal market; Frost & Sullivan Leader validates competitive position
- Platform unification approach reduces tool sprawl for enterprise buyers and creates switching costs
- Strong macro tailwinds from executive threat awareness and physical-cyber convergence trends
Top risks
- Predecessor Banjo Inc. controversy creates lingering reputational risk in due diligence contexts
- Revenue and unit economics are opaque; third-party estimates conflict and may not reflect true performance
- Concentrated customer base (26 accounts) creates revenue concentration vulnerability
- Privacy regulation (GDPR, EU AI Act) may constrain international data collection capabilities
- Well-resourced competitors (Dataminr, Everbridge) with larger installed bases and deeper pockets
Open gaps
- Official valuation not disclosed; $1B estimate unconfirmed
- Gross margin, net retention, and burn rate completely unavailable
- Customer concentration and churn metrics not publicly reported
- KKR investment terms (liquidation preferences, control rights) unknown
- Revenue growth trajectory conflicting across third-party sources
Contents
01Company Overview
1.1 Identity and Business Model
Ontic Technologies is a privately-held enterprise SaaS company headquartered in Austin, Texas, providing AI-powered Connected Intelligence software for corporate and government security teams. The platform unifies security operations and data into a centralized system of record, enabling organizations to conduct risk assessments, protect against workplace violence, manage threats and incidents, and coordinate investigations efficiently. Ontic aggregates open-source intelligence (OSINT) and external threat signals alongside internal data from systems like HR, legal, IT, and facilities. The company's revenue model is SaaS subscription-based, serving Fortune 500 companies and federal agencies. Ontic was officially founded in 2017, though the company's history traces back to Banjo Inc., a real-time intelligence platform founded by Damien Patton in 2010 that was later rebranded to safeXai and then Ontic Technologies following a leadership scandal in 2020-2021.[CO001, CO002, CO003, CO004, CO005, CO006]
| Metric | Value | Date | Confidence | Gap |
|---|---|---|---|---|
| Valuation | ~$1B (estimated) | Aug 2025 | low | Not officially disclosed |
| Total Raised | $287M | Aug 2025 | high | |
| ARR | $35.6M | Dec 2025 | medium | Third-party estimate only |
| Headcount | 309-324 | Late 2025 | medium | Multiple sources vary |
| Customer Count | 26+ | 2025 | medium | Third-party; Fortune 500 focus |
| Revenue Growth YoY | ~45% | 2025 | low | Contradicted by ARR figures |
| Founded | 2017 | 2017 | high | |
| HQ | Austin, Texas | 2026 | high |
Valuation not disclosed officially; revenue/ARR figures from third-party trackers (GetLatka, Growjo) show conflicting data. Customer count may represent large enterprise accounts only.
[CO019, CO020, CO021, CO012]How Ontic's identity, product, customers, capital, and dependencies interconnect.
[CO001, CO002, CO003, CO019, CO020]1.2 Leadership and Governance
Ontic is led by CEO and Co-Founder Lukas Quanstrom, who guides the company's strategic direction and AI investment agenda. The executive team includes Brian Mazza as Chief Revenue Officer, Nitin Navare as Chief Technology and Product Officer, Kyle Giunta as Chief Operating Officer, Ryan Suneson as Chief Financial Officer, Scott Shepherd as Chief Legal Officer, Manish Mehta as Chief Solutions and Innovation Officer, Amy Sullivan as EVP of Alliances, and Murph Holder as VP of People. The board of directors includes Lukas Quanstrom, Mike Dodd (Silverton Partners), Jake Heller (KKR), Bob Nye (JMI Equity), and Murali Swaminathan. The company also maintains an advisory board of recognized security industry thought leaders including Fred Burton, Dave Komendat, Rich Davis, Thomas Kopecky, and Gagan Jain who help guide Ontic's product strategy and provide guidance on protective intelligence, enterprise software, and corporate security trends. Notably, the leadership team has been entirely reconstituted since the predecessor company's controversy, with no executives from the original Banjo leadership remaining in senior positions. This governance reset was a precondition for the institutional investor support that followed.[CO007, CO008, CO009, CO010, CO011]
| Person | Role | Background | Key-Person Dependency |
|---|---|---|---|
| Lukas Quanstrom | CEO & Co-Founder | Company co-founder; led growth from startup to $230M Series C | High — public face, strategic direction, investor relationships |
| Nitin Navare | Chief Technology & Product Officer | Technology and product leadership | High — owns platform architecture and AI roadmap |
| Brian Mazza | Chief Revenue Officer | Enterprise sales leadership | Medium — drives revenue growth |
| Kyle Giunta | Chief Operating Officer | Operations management | Medium — operational scaling |
| Ryan Suneson | Chief Financial Officer | Financial leadership | Medium — capital allocation, investor relations |
| Scott Shepherd | Chief Legal Officer | Legal and compliance | Medium — regulatory navigation, FedRAMP |
| Manish Mehta | Chief Solutions & Innovation Officer | Solutions architecture and innovation | Medium — customer solutions |
| Amy Sullivan | EVP, Alliances | Partnership development | Low — channel expansion |
Leadership roster from official Ontic website as of June 2026. Background detail limited to publicly available information.
[CO007, CO008, CO009, CO010]1.3 Funding History and Valuation
Ontic Technologies has raised approximately $287 million in total funding across four institutional rounds. The company completed a $4.65M seed round in January 2019 from Silverton Partners, Floodgate, and Village Global. The $14M Series A followed in April 2020 led by Felicis Ventures with participation from Silverton Partners and Floodgate. The $40M Series B in November 2021 was led by JMI Equity with participation from Felicis Ventures, Silverton Partners, and Ridge Ventures. The landmark $230M Series C in August 2025 was led by KKR via its Next Generation Technology III Fund, with participation from JMI Equity, Silverton Partners, Ridge Ventures, and Ten Eleven Ventures. The Series C valuation was not publicly disclosed, though third-party estimates place it at approximately $1 billion. KKR has invested approximately $24 billion in technology-focused growth companies since 2016 and brings a dedicated team of 28 technology growth equity investment professionals.[CO012, CO013, CO014, CO015, CO016, CO017]
| Stakeholder | Role | Importance | Diligence Ask |
|---|---|---|---|
| KKR (Next Gen Tech III) | Series C Lead Investor | Largest single investor ($230M round lead); board seat via Jake Heller | KKR fund performance, exit timeline expectations, control provisions |
| JMI Equity | Series B Lead / Series C Participant | Led $40M Series B; continued participation; board seat via Bob Nye | JMI portfolio focus areas, potential acquirer introductions |
| Silverton Partners | Seed through Series C Participant | Earliest institutional backer; board seat via Mike Dodd; Austin-based alignment | Early equity dilution, founder relationship history |
| Felicis Ventures | Series A & B Lead | Led early growth rounds ($14M Series A, co-led $40M Series B) | Current stake, exit preferences, follow-on decision in Series C |
| Ridge Ventures | Series B & C Participant | Growth-stage technology investor | Technology diligence perspective |
| Ten Eleven Ventures | Series C Participant | Cybersecurity-focused VC; deep domain expertise | Security market thesis validation |
| Floodgate | Seed Investor | Early-stage investor from seed round | Current stake post-dilution |
| Village Global | Seed Investor | Early-stage network-driven fund | Current involvement level |
Investor roster synthesized from press releases, PitchBook, and Crunchbase data. Board composition confirmed from official Ontic leadership page.
[CO012, CO013, CO014, CO015, CO016, CO017]1.4 Scale and Key Performance Indicators
As of late 2025, Ontic reported annual recurring revenue of $35.6M according to third-party tracking sources, with headcount in the range of 309-324 employees. The company services Fortune 50 companies across technology, financial services, and consumer goods verticals. Ontic clients collectively generate nearly $30 billion in revenue and employ over 14 million people. The company reports measurable client outcomes including reducing staffing needs by 33%, cutting investigation time in half, centralizing incident response across 400+ locations, and generating over $4.5M in cost avoidance over three years at a global enterprise. Employee growth rate in 2025 was approximately 9-10%. The company maintains distributed offices with approximately 40% of 2025 sales reportedly coming from EMEA and APAC regions, indicating meaningful international traction.[CO019, CO020, CO021, CO022, CO023, CO024]
| Date | Event | Type | Amount/Status | Participants | Implication |
|---|---|---|---|---|---|
| 2010 | Banjo Inc. founded by Damien Patton | founding | Damien Patton | Original entity; real-time surveillance AI focus | |
| Jan 2019 | Ontic seed round closes | financing | $4.65M | Silverton Partners, Floodgate, Village Global | Initial capitalization under Ontic brand |
| Apr 2020 | Series A funding | financing | $14M | Felicis Ventures (lead), Silverton Partners, Floodgate | Growth capital for early enterprise traction |
| 2020 | Banjo founder Damien Patton scandal; resignation | adverse | Damien Patton | Reputational crisis; led to rebrand from Banjo to safeXai to Ontic | |
| Nov 2021 | Series B funding | financing | $40M | JMI Equity (lead), Felicis Ventures, Silverton Partners, Ridge Ventures | Scaled enterprise sales and product development |
| Aug 2025 | Series C funding led by KKR | financing | $230M | KKR (lead), JMI Equity, Silverton Partners, Ridge Ventures, Ten Eleven Ventures | Transformational growth capital; unicorn-level scale |
| Aug 2025 | KKR board seat established | governance | Jake Heller (KKR) | Institutional governance upgrade with KKR participation | |
| Apr 2026 | FedRAMP Moderate Authorization achieved | regulatory | Authority to Operate granted | Ontic, U.S. Government | Unlocked federal/public sector deployments |
| Jun 2026 | Frost Radar Growth & Innovation Leader (3rd year) and Company of the Year (4th time) | product | Frost & Sullivan | Industry validation; competitive positioning reinforcement | |
| 2026 | Ontic Dispatch product launched | product | Ontic | Extended Connected Intelligence into physical security response |
Timeline synthesized from press releases, third-party databases, and news coverage. Banjo founding date (2010) refers to the predecessor entity; Ontic's official founding is 2017 per company statements.
[CO025, CO026, CO027, CO028, CO029, CO030]Key performance indicators summarizing Ontic's maturity, traction, and investment profile as of mid-2026.
[CO019, CO020, CO021, CO029, CO031]1.5 Key Milestones and Timeline
Ontic's history includes both the company's own trajectory since 2017 and its complex predecessor relationship with Banjo Inc. The original entity Banjo was founded in 2010 by Damien Patton, operating as a real-time surveillance AI platform. In 2020, founder Patton's past involvement with white supremacist groups in the 1990s was publicly reported, leading to contract cancellations and his resignation as CEO. The company rebranded first to safeXai and then to Ontic Technologies in 2021 under new leadership. Major milestones since the re-launch include securing a $40M Series B in November 2021, achieving sustained product-market fit in the enterprise security vertical, raising the transformational $230M Series C led by KKR in August 2025, achieving FedRAMP Moderate Authorization in April 2026, and being named Frost & Sullivan Growth and Innovation Leader in Risk Intelligence Solutions for the third consecutive year in 2026 plus Frost & Sullivan Company of the Year for the fourth time. In 2026, Ontic also introduced Ontic Dispatch, extending Connected Intelligence into physical security response and coordination.[CO025, CO026, CO027, CO028, CO029, CO030]
Chronological view of Ontic's major corporate events from predecessor founding through 2026.
[CO025, CO026, CO027, CO028, CO029, CO030]1.6 Exhibits
02Market Analysis
2.1 Market Definition and Boundary
Ontic Technologies operates squarely at the critical intersection of several key overlapping markets today: risk intelligence solutions, corporate physical security software, threat intelligence platforms, and protective intelligence tools. The core addressable market is risk intelligence solutions, which Frost & Sullivan defines to encompass platforms that operationalize data across physical security, cybersecurity, IT, and other internal business functions into unified threat detection and response capabilities. This broad market boundary explicitly includes OSINT aggregation, social media monitoring, executive protection software, workplace violence prevention systems, investigation and case management tools, and critical event management platforms. Excluded from the primary market boundary are pure-play cybersecurity products (endpoint protection, SIEM), physical security hardware (cameras, access control), manned guarding services, and general-purpose business intelligence platforms. Adjacent markets include cyber threat intelligence (narrower digital focus), mass notification systems, and physical security-as-a-service offerings that may compete for overlapping budget dollars.[CM001, CM002, CM003]
| Segment/Category | Included Spend | Excluded Spend | Primary Buyer | Relevance to Ontic |
|---|---|---|---|---|
| Risk Intelligence Solutions | Threat detection, OSINT, investigations, case management, executive protection software | Pure cybersecurity tools, physical hardware | CSO / VP Security | Core TAM — Ontic's primary competitive arena |
| Cyber Threat Intelligence | Digital threat feeds, dark web monitoring, vulnerability intel | Physical security, brand protection | CISO / SOC | Adjacent — partial overlap on OSINT feeds |
| Physical Security Systems | Video management, access control, intrusion detection hardware/software | Manned guarding, armored transport | Facilities / CSO | Adjacent — integration target, not direct competition |
| Critical Event Management | Mass notification, crisis comms, emergency response coordination | Routine business continuity planning tools | CSO / BCP Lead | Competitive overlap — Everbridge, AlertMedia compete here |
| Protective Intelligence | Executive protection analytics, travel risk, social media monitoring | Close protection staffing | CSO / EP Director | Core — Ontic's executive protection module |
Market boundaries synthesized from Frost & Sullivan, Mordor Intelligence, and Verified Market Reports segmentation frameworks. Overlap exists between categories.
[CM001, CM002, CM003]Buyer-user-payer relationships across key industry verticals showing adoption patterns.
[CM009, CM010, CM011, CM020]2.2 Market Sizing and Growth Projections
The risk intelligence solutions market was valued at $58.84 billion in 2025 according to Frost & Sullivan research cited in Ontic's 2026 press release, with a projected compound annual growth rate of 19.4% reaching $170.14 billion by 2030. This represents the broadest addressable market for Ontic's platform. A narrower lens on the cyber threat intelligence segment sizes the market at approximately $13.4-16.8 billion in 2025, growing to $15.8-19.3 billion in 2026, with long-term CAGRs of 14-18% through 2035 reaching $53-65 billion. The physical security market overall is approximately $129-131 billion in 2026, growing at a more modest 4-5% CAGR. The most relevant serviceable addressable market (SAM) for Ontic lies within the corporate security software and intelligence segment, estimated at $3-8 billion globally for pure software platforms targeting corporate security operations centers, protective intelligence, and investigation workflows in Fortune 1000 enterprises and government agencies.[CM004, CM005, CM006, CM007, CM008]
| Publisher | Year | Geography | Value | CAGR | Methodology | Confidence | Limitation |
|---|---|---|---|---|---|---|---|
| Frost & Sullivan (via Ontic PR) | 2025-2030 | Global | $58.84B → $170.14B | 19.4% | Bottom-up vendor tracking + top-down analysis | medium | Cited in company PR; original report paywalled |
| Verified Market Reports | 2025 | Global (threat intel) | $13.4-16.8B | 14-18% | Vendor revenue aggregation | medium | Broad threat intelligence scope, not security-specific |
| Precedence Research | 2025-2035 | Global (threat intel) | $16.8B → $65.3B | ~14.5% | Top-down with vendor surveys | low | Very long forecast horizon increases uncertainty |
| Mordor Intelligence | 2026 | Global (physical security) | $129-131B | 4-5% | Hardware + software + services | high | Includes non-software spend irrelevant to Ontic |
| Business Research Insights | 2026-2035 | Global (physical security) | $111B by 2035 | ~5% | Top-down macro analysis | low | Primarily hardware-weighted |
| Agent estimate (SAM) | 2026 | Global (corp security software) | $3-8B | 15-20% | Fortune 1000 security budgets × software share | low | Back-of-envelope; requires validation |
Multiple sizing methodologies yield wide range. Frost & Sullivan figure cited in official Ontic press release but original report is paywalled. SAM estimate is analytical inference, not sourced from a published report.
[CM004, CM005, CM006, CM007, CM008]TAM/SAM/SOM layered sizing for Ontic's addressable markets.
SAM is an analytical estimate; TAM from Frost & Sullivan via Ontic PR. SOM equals reported ARR.
[CM004, CM008]Low/base/high estimates of the global risk intelligence TAM in 2030.
Wide range reflects different market definitions. Conservative includes only threat intelligence software; expansive includes broader physical security intelligence.
[CM004, CM005, CM006]2.3 Buyer, User, and Payer Segmentation
The primary buyer persona for Ontic's platform is the Chief Security Officer (CSO) or VP of Corporate Security at Fortune 500 enterprises, who owns the physical security and protective intelligence budget. Secondary buyers include Directors of Global Security Operations Centers (GSOCs), heads of executive protection programs, and chief risk officers in industries with elevated physical threat profiles. In the public sector, buyers are agency security directors and protective intelligence program leads. The end users are security analysts, investigators, and GSOC operators who interact with the platform daily. The payer is typically the corporate security budget holder, though IT procurement may control vendor approvals and technical compliance. Budget ownership sits under the CSO function in most enterprises, separate from the CISO's cybersecurity budget. Adoption triggers include high-profile threat incidents, executive protection needs, regulatory mandates, workplace violence prevention requirements, and the desire to consolidate multiple point solutions into a single platform.[CM009, CM010, CM011, CM012]
| Segment | Buyer | User | Payer | Budget Owner | Adoption Trigger |
|---|---|---|---|---|---|
| Enterprise (Fortune 500) | CSO / VP Security | GSOC analysts, investigators | Corporate security budget | CSO | Executive threat incident, board mandate |
| Financial Services | Head of Corporate Security | Fraud investigators, EP team | Operational risk budget | COO / CRO | Regulatory requirement, insider threat |
| Technology | Director of Security Ops | Security engineers, analysts | Security operations budget | CSO / CISO (joint) | Data breach, workplace violence concern |
| Public Sector / Federal | Agency Security Director | Protective intelligence analysts | Government appropriation | Agency head | FedRAMP availability, mission requirement |
| Healthcare / Life Sciences | Security Director | Security team, compliance staff | Facilities/security budget | VP Operations | Active shooter concern, campus security |
Buyer personas derived from Ontic client stories, press releases, and industry analyst reports. Budget ownership varies by organizational structure.
[CM009, CM010, CM011, CM012]2.4 Growth Drivers and Adoption Constraints
Several macro forces are accelerating demand for risk intelligence platforms in 2026 and beyond. The fatal shooting of a UnitedHealth Group executive in late 2024 dramatically elevated corporate board awareness of executive security threats, driving increased budget allocation for protective intelligence solutions across multiple industry verticals. The convergence of physical and cyber threats is forcing security teams to break down organizational silos between CSO and CISO functions, creating demand for unified platforms that bridge both domains. AI and automation adoption is enabling resource-constrained security teams to do more with less, filtering noise and surfacing actionable intelligence from vast data volumes. Regulatory pressure including FedRAMP requirements for government contracts and international standards like ISO 27001 create compliance-driven purchasing motives. On the constraint side, enterprise sales cycles are long (6-12 months typical), switching costs from incumbent systems are high, data privacy regulations (GDPR, CCPA, EU AI Act) create compliance complexity around surveillance and monitoring capabilities, and budget competition from cybersecurity tools can crowd out physical security software spending.[CM013, CM014, CM015, CM016, CM017, CM018]
| Driver/Constraint | Direction | Timing | Implication | Diligence Ask |
|---|---|---|---|---|
| Executive threat awareness (UnitedHealth incident) | Accelerator | 2025-2027 | Board-level security budget increases | Survey Fortune 500 CSOs on budget changes |
| Physical-cyber convergence | Accelerator | 2024-2028 | Platform consolidation demand favors unified vendors | Track vendor consolidation M&A activity |
| AI/automation in security ops | Accelerator | 2025-2030 | Enables fewer analysts to cover more threats | Benchmark AI detection accuracy vs false positive rates |
| FedRAMP/government compliance | Accelerator | 2026+ | Opens public sector TAM for compliant vendors | Size federal security software budgets |
| Long enterprise sales cycles | Constraint | Ongoing | 6-12 month cycles slow revenue recognition | Track average deal timeline and pipeline conversion |
| Privacy regulation (GDPR, EU AI Act) | Constraint | 2025-2027 | Limits data collection scope in EU markets | Assess geographic revenue risk from regulation |
| CISO budget competition | Constraint | Ongoing | Physical security budgets compete with cyber spending | Measure CSO vs CISO budget allocation trends |
| Switching costs from incumbents | Constraint | Ongoing | Installed base of legacy tools slows displacement | Map incumbent penetration in target accounts |
Drivers and constraints assessed from market research, press coverage, and analyst reports. Timing estimates are directional only.
[CM013, CM014, CM015, CM016, CM017, CM018]Enterprise purchase and deployment stages for risk intelligence platforms.
Funnel percentages are illustrative based on typical enterprise SaaS conversion patterns, not Ontic-specific data.
[CM016, CM017]2.5 Exhibits
03Competitors
3.1 Landscape and Buyer Overlap
The competitive field around Ontic is broader than a simple protective-intelligence niche. Seerist's 2026 Frost Radar for risk intelligence solutions evaluates Ontic alongside Dataminr, Everbridge, Kroll, Flashpoint, Crisis24, ZeroFox, and other vendors, while Gartner and G2 alternative pages show that buyers compare Ontic against adjacent tools rather than only direct lookalikes. That matters because enterprise security leaders often assemble shortlists based on the job to be done: real-time threat detection, incident orchestration, investigations, executive protection, or broad operational resilience. Ontic's direct competition is strongest when a CSO or GSOC leader wants a single operating system for protective intelligence, investigations, and internal-external data correlation. It competes less effectively when the purchase is dominated by mass-notification depth, public-signal speed, or a highly verticalized incident-reporting requirement. The category therefore contains direct peers, communications incumbents, and workflow substitutes, which keeps pricing opaque and makes demonstrated deployment fit more important than category labels alone.[CP001, CP002, CP003, CP004, CP005, CP006]
| Vendor | Category | Scale / funding context | Primary buyer | Differentiation | Limitation |
|---|---|---|---|---|---|
| Ontic | Connected intelligence / protective intelligence | Series C private company with ~$287M raised and mid-hundreds headcount | CSO, GSOC, executive protection leader | Cross-functional case management and connected investigations | Smaller installed base than the largest alerting and resilience vendors |
| Dataminr | Real-time risk intelligence | Large private company with billion-plus capital raised per third-party funding trackers | Global security, risk, comms teams | Fast external-signal discovery and AI-driven alerting | Less centered on internal case management and evidence workflow |
| Resolver | Risk intelligence / incident workflows | Risk-software platform aligned with broader Kroll risk-services ecosystem | Security, investigations, compliance teams | Strong incident documentation and risk-workflow orientation | Less differentiated as a unified connected-intelligence narrative |
| Everbridge | Critical event management | Large enterprise resilience platform; private after Thoma Bravo acquisition | Enterprise resilience, security, business continuity | Mass notification, orchestration, and broad resilience footprint | Broader suite can be heavier when buyer wants focused protective-intelligence workflow |
| AlertMedia | Unified risk intelligence & response | PE-backed platform reportedly explored for >$1B sale in 2026 | Security, communications, operations | Simple deployment, emergency communications, executive-protection adjacency | Less evidence of deep investigations system-of-record positioning |
| Omnigo | Incident reporting / safety software | PE-backed safety software vendor with strong operational vertical fit | Healthcare, education, operations security leaders | Verticalized incident reporting and public-safety workflow depth | Narrower risk-intelligence breadth and weaker global signal narrative |
Scale and funding context is intentionally qualitative because public disclosures are uneven across private peers; rows emphasize buyer-relevant relative scale and ownership structure.
[CP001, CP009, CP010, CP011, CP012, CP013]Relative positioning of key vendors on connected-investigation depth versus alerting/resilience breadth.
Axes are ordinal and evidence-backed, not source-native numeric scores; they summarize relative workflow depth and suite breadth from reviewed product positioning.
[CP002, CP007, CP009, CP010, CP011, CP012]3.2 Direct Competitor Profiles and Positioning
Dataminr, Resolver, Everbridge, AlertMedia, and Omnigo represent the most relevant competitive set because each covers a material portion of the same corporate-security buying workflow but from a different starting point. Dataminr leads with AI-driven real-time external signal detection and global alerting. Resolver emphasizes risk intelligence, incident workflows, and investigative documentation. Everbridge leads with critical-event management and resilient communications across large enterprises. AlertMedia positions around unified risk intelligence, response, emergency communication, and executive-protection use cases. Omnigo is more verticalized, with incident reporting and public-safety workflows that fit healthcare, education, and other operational environments. Ontic's positioning is distinct in how explicitly it connects people, cases, evidence, and workflow across corporate security, legal, HR, and executive-protection use cases. That gives Ontic a strong narrative in complex enterprises, but it also means the company competes against larger installed bases and broader product suites that can win deals through familiarity, adjacent modules, or procurement standardization rather than through superior connected-investigation workflow alone.[CP009, CP010, CP011, CP012, CP013, CP014]
| Buying criterion | Ontic | Dataminr | Resolver | Everbridge | AlertMedia | Omnigo |
|---|---|---|---|---|---|---|
| External real-time signal discovery | Medium | High | Low-Medium | Medium | Medium | Low |
| Protective-intelligence case workflow | High | Low-Medium | Medium | Low-Medium | Medium | Low-Medium |
| Mass notification / communications | Low-Medium | Low | Low | High | High | Low-Medium |
| Incident documentation / investigations | High | Low-Medium | High | Medium | Medium | High |
| Public-sector / compliance trust posture | High | Medium | High | High | Medium | Medium |
| Cross-functional internal data correlation | High | Low | Medium | Medium | Medium | Low-Medium |
Ordinal strength scores reflect evidence-backed category positioning rather than vendor self-scored feature parity. Unsupported cells are avoided by using coarse comparative bands.
[CP003, CP004, CP005, CP006, CP009, CP010]Capability coverage across the most relevant evaluation criteria for corporate-security buyers.
[CP010, CP011, CP012, CP013, CP014, CP015]3.3 Pricing, Switching Costs, and Distribution Power
The pricing environment is structurally difficult for Ontic because the relevant vendors mostly sell through enterprise demo-led motions with negotiated contracts rather than transparent list prices. Everbridge and AlertMedia explicitly describe custom pricing, while Ontic, Dataminr, Resolver, and Omnigo similarly route buyers into sales-led evaluation paths. That makes feature fit, trust, deployment speed, and executive sponsorship central to deal conversion. Switching costs are moderate to high after deployment because these systems connect to HR, travel, communications, incident, and case-management workflows, but multi-homing remains possible: a buyer can retain Dataminr for external signal discovery while adopting Ontic for investigations, or keep Everbridge for mass notification while adding Ontic for protective intelligence. This mixed-stack reality is strategically important. Ontic does not need to displace every incumbent to win, but it also cannot assume a winner-take-all position. Distribution scale favors larger brands such as Everbridge and Dataminr, while public-sector trust posture and cross-functional workflow depth are areas where Ontic can punch above its size.[CP018, CP019, CP020, CP021, CP022, CP023]
| Vendor | Public pricing signal | Contract motion | Included capability emphasis | Discount / unknown | Implication |
|---|---|---|---|---|---|
| Ontic | No list pricing published on reviewed official pages | Enterprise demo / contact-sales | Connected intelligence, investigations, protective intelligence | Realized pricing and module packaging undisclosed | ROI proof and workflow fit likely drive negotiations |
| Dataminr | No public list pricing on reviewed official pages | Enterprise sales | Real-time risk signals and alerting | Seat, feed, and module economics not disclosed | Speed-to-value matters more than transparent entry pricing |
| Resolver | No public list pricing on reviewed official pages | Enterprise sales | Risk intelligence and incident workflows | Packaging and services mix not disclosed | Complex compliance buyers may accept opaque pricing for workflow fit |
| Everbridge | Explicit custom pricing | Enterprise sales with package tiers | Critical event management, communications, resilience | Package-level discounting not public | Breadth allows bundling leverage in large accounts |
| AlertMedia | Explicit custom pricing | Enterprise sales | Risk intelligence, communications, response | Customer-specific scope and audience sizing govern price | Simplicity can shorten evaluation even without price transparency |
| Omnigo | No public list pricing on reviewed official pages | Enterprise / vertical software sales | Incident reporting and safety workflows | Vertical-specific configuration likely affects realized pricing | Can undercut broader suites where workflow needs are narrow |
Reviewed official pages mostly direct buyers into demo-led sales flows. Where a vendor explicitly states custom pricing, the table records that; otherwise the gap remains part of diligence.
[CP018, CP019, CP020, CP021, CP022, CP023]Compact view of the competitive attributes that most influence Ontic's durability in 2026.
[CP018, CP019, CP024, CP026, CP029, CP035]3.4 Moat Durability and Competitive Risk
Ontic's moat is real but conditional. The strongest evidence of defensibility is not raw signal breadth or public-market scale; it is Ontic's ability to anchor a system of record for protective intelligence and security investigations that crosses departmental boundaries. That workflow position can become sticky once a customer embeds cases, playbooks, evidence, and internal controls. The company also benefits from a trust-and-governance story that matters more in 2026 as buyers weigh AI accountability, privacy, and public-sector readiness. However, the moat is vulnerable on several fronts. Dataminr can outgun Ontic on event detection scale; Everbridge can bundle broader resilience and communications; AlertMedia can compete on simplicity and response workflows; Omnigo can win verticals where tailored incident-reporting matters more than connected intelligence; and Resolver/Kroll can appeal to compliance-minded buyers that value risk documentation. The practical conclusion is that Ontic has a defendable wedge, but it must keep deepening integrations, proof of ROI, and public-sector credibility to prevent the category from collapsing into adjacent-suite competition or commoditized OSINT-plus-workflow bundles.[CP026, CP027, CP028, CP029, CP030, CP031]
| Moat claim | Threat | Severity | Why it matters | Mitigation / diligence ask |
|---|---|---|---|---|
| Connected investigations become sticky once embedded | Dataminr or Everbridge remains system of engagement while Ontic is additive only | High | Limits wallet share and keeps Ontic outside the broadest enterprise budget pools | Test whether reference customers expanded modules or kept Ontic narrow |
| Trust-sensitive AI posture supports public-sector and regulated wins | Larger competitors match trust messaging and compliance posture | Medium-High | AI governance claims can commoditize quickly if every vendor markets responsible AI | Request concrete procurement win/loss data tied to FedRAMP and privacy controls |
| Cross-functional workflow breadth differentiates Ontic from alerting tools | Suite vendors bundle adjacent modules at lower incremental price | High | Bundling can offset feature gaps and slow Ontic displacement wins | Map accounts where Ontic won despite incumbent communications or resilience contracts |
| Protective-intelligence specialization creates buyer relevance | Category labels remain fuzzy and buyers shortlist many substitutes | Medium | High substitution keeps pricing power limited and increases evaluation burden | Review win-loss analysis by use case instead of generic category |
| Customer workflow evidence can build a defensible system of record | Opaque pricing and limited public ROI benchmarks weaken sales narrative | Medium | Without hard economic proof, procurement can favor better-known brands | Obtain deployment-level ROI, renewal, and expansion evidence |
| Public-sector credibility broadens TAM | Competitors with larger installed bases or stronger global brands out-distribute Ontic | High | Distribution power influences shortlist inclusion before product comparison occurs | Measure pipeline sourced from channel, analyst, and public-sector relationships |
The register frames durability in buyer and distribution terms rather than pure technology novelty because the category is shaped by workflow adoption and enterprise procurement behavior.
[CP025, CP026, CP027, CP028, CP029, CP030]3.5 Exhibits
04Financials
4.1 Revenue Model and Public Traction
Ontic’s public materials support an enterprise SaaS revenue model built around connected-intelligence software sold to corporate and government security teams. The company markets a unified platform, promotes ROI and time-savings through customer stories, and does not publish self-serve pricing, all of which are consistent with a high-touch enterprise contract motion. The best available public traction figure is GetLatka’s estimate of $35.6M 2025 ARR, 26 customers, 324 employees, and roughly $1.4M average contract value. That is directionally consistent with a concentrated enterprise-customer base rather than high-volume SMB sales. However, the public record is messy: Growjo estimates materially different revenue, funding, and headcount, and the company itself still does not publish audited income statement or balance sheet detail. That forces investors to treat revenue, ARR, and customer economics as proxies rather than settled facts. The encouraging signal is that customer stories repeatedly frame Ontic as a workflow platform with measurable value; the caution is that revenue quality remains inferred rather than disclosed.[CI001, CI002, CI003, CI004, CI005, CI006]
| Stream | Mechanism | Unit | Current value / status | Quality | Diligence ask |
|---|---|---|---|---|---|
| Core platform subscription | Annual enterprise software contract | Account / ACV | Publicly evident; exact mix undisclosed | Medium | Break out recurring platform ARR by module and sector |
| Protective-intelligence / investigations workflow modules | Module upsell within the platform | Module / seat / account | Supported by product and case-study positioning, but not separately disclosed | Low-Medium | Provide module-level ARR and attach rates |
| Implementation / enablement services | Onboarding, integration, workflow setup | Project | Likely present in enterprise deployments but not quantified publicly | Low | Separate services revenue from recurring software revenue |
| Government / public-sector contracts | Enterprise or agency software contracts | Account | Strategic growth area implied by FedRAMP and federal references; public revenue share unknown | Low | Show current public-sector ARR, pipeline, and gross margin profile |
| Expansion / renewal revenue | Add-on modules, users, workflows, or geographies | Existing account | No public NRR or expansion data | Low | Disclose renewal, upsell, and contraction metrics by cohort |
Public sources support the existence of enterprise subscription revenue but do not disclose revenue mix between software, services, and expansion motion.
[CI001, CI002, CI003, CI004, CI005, CI006]| Element | Price / unit / contract | List vs. realized pricing | Source signal | Implication |
|---|---|---|---|---|
| Ontic platform | Not publicly listed | Realized pricing undisclosed | Official pages route to demo / contact sales | Enterprise pricing discipline likely depends on ROI proof and procurement fit |
| Average contract value proxy | ~$1.4M ACV | Third-party estimate | GetLatka | Suggests concentrated enterprise accounts if accurate |
| Everbridge comparison | Custom pricing | List price not public | Everbridge official FAQ | Peer set also competes with opaque negotiated contracts |
| AlertMedia comparison | Custom pricing | List price not public | AlertMedia official FAQ / platform page | Price opacity is normal across adjacent vendors |
| Discount / services mix | Unknown | No public disclosure | No direct source | Commercial quality cannot be underwritten without proposal-level data |
Pricing transparency is low across the category. The table therefore separates observed public signals from unverified realized pricing.
[CI003, CI011, CI014, CI032]How enterprise security demand converts into Ontic revenue and perceived value capture.
[CI001, CI004, CI005, CI006, CI007]4.2 GTM Motion and Unit-Economics Proxies
The available proxies point to a relatively high-ACV, low-logo-count enterprise model. If GetLatka’s 26-customer estimate is directionally right, Ontic is monetizing a small number of sizable deployments rather than broad seat-based penetration. That implies sales cycles are likely long, implementation work meaningful, and customer success central to expansion. Public customer stories reinforce this: Ally cites up to eight hours saved per site risk assessment, Visa highlights consolidated research workflows, and the broader ROI story is about proving program value to executives rather than about low-cost viral adoption. These are positive willingness-to-pay indicators, but they are not substitutes for CAC, payback, gross margin, or retention data. The tracker conflict is also important. GetLatka shows 324 employees and $35.6M ARR while Growjo estimates 272 employees and $42.4M revenue. That produces a wide public revenue-per-employee band and underlines why Ontic’s GTM efficiency cannot be underwritten confidently from open sources alone.[CI011, CI012, CI013, CI014, CI015, CI016]
| Metric | Value / null | Confidence | Why it matters | Diligence ask |
|---|---|---|---|---|
| 2025 ARR | 35.6 | medium | Best public recurring-revenue estimate anchors all valuation math | Confirm ARR bridge and whether figure is GAAP, run-rate, or management ARR |
| Customers | 26 | medium | Implies concentrated enterprise base and high ACV motion | Provide active logos, production deployments, and top-10 concentration |
| Average contract value | 1.4 | medium | Suggests meaningful enterprise willingness to pay if accurate | Provide contracted ACV distribution and realized first-year ACV |
| Revenue per employee | $0.11M-$0.16M | low | Proxy for GTM and operating efficiency | Provide fully loaded headcount, revenue, and contractor mix |
| Funding / ARR ratio | ~8.1x | medium | Shows how much cumulative capital supports current recurring scale | Reconcile use of capital by product, sales, and compliance investment |
| Gross margin | null | low | Core SaaS quality metric; missing publicly | Provide software gross margin and services drag |
| CAC payback | null | low | Critical for judging sales efficiency | Provide sales & marketing spend, new ARR, and payback by segment |
| NRR / GRR | null | low | Required to test platform stickiness | Provide cohort retention and expansion by vintage |
Numeric rows are either direct third-party estimates or simple calculations from public data; missing private-company metrics remain null by design.
[CI008, CI009, CI012, CI013, CI014, CI015]Publicly visible inputs versus missing private inputs in Ontic’s unit-economics story.
[CI008, CI009, CI012, CI014, CI030]Public-data range for key financial proxies where sources conflict or values require simple derivation.
Low/high values combine public trackers with official funding disclosures; ratios are rounded analytical calculations and should not be treated as audited metrics.
[CI008, CI013, CI014, CI015, CI016, CI017]4.3 Cost Structure and Capital Adequacy
The capital picture is simultaneously reassuring and incomplete. Official 2025 announcements confirm a $230M Series C led by KKR and roughly $287M raised to date, which gives Ontic a meaningful financing cushion relative to the public ARR estimate. Even using the more conservative $35.6M ARR figure, the implied cumulative funding-to-ARR ratio is about 8.1x, signaling that Ontic remains heavily capitalized relative to disclosed recurring revenue. That is not automatically negative for a category-defining platform, especially one investing in AI, public-sector readiness, and international expansion, but it does raise the bar for future operating leverage. Public data do not reveal cash on hand, monthly burn, runway, debt, deferred revenue, or gross margin. Nor do they isolate services, onboarding, or compliance costs associated with enterprise and government deployments. The result is that capital adequacy can only be judged at a coarse level: Ontic likely has near-term strategic flexibility because of the Series C, but investors cannot yet quantify whether that flexibility is being converted into efficient growth or simply masking expensive expansion.[CI021, CI022, CI023, CI024, CI025, CI026]
| Item | Value / status | Confidence | Why it matters | Diligence ask |
|---|---|---|---|---|
| Cash on hand | null | low | Primary runway input is undisclosed publicly | Request latest cash balance and restricted cash |
| Monthly burn | null | low | Needed to convert raise size into runway | Request trailing 12-month net burn and burn by function |
| Runway months | null | low | Cannot infer responsibly without cash and burn | Provide board runway model under base and downside cases |
| Planned use of Series C | AI, product innovation, and global expansion | high | Explains why capital requirements may stay elevated | Break out budget allocation and milestones by initiative |
| Next-round trigger | Not publicly disclosed | low | Determines whether current raise is a bridge or a long-duration round | Define revenue, margin, or public-sector milestones tied to future financing |
| Debt / project-finance obligations | None publicly disclosed | low | Debt could materially alter downside risk | Provide debt schedule, covenants, letters of credit, and vendor financing |
| Capital cushion vs ARR | Large on paper | medium | Official raise size lowers near-term financing risk despite sparse disclosures | Show cash conversion and capital-efficiency trend since Series B |
Historical round chronology is covered in Company Overview; this table focuses only on the capital adequacy implications that matter for underwriting today.
[CI021, CI022, CI023, CI024, CI025, CI026]Observed positives and missing data points that shape the underwriting view on capital adequacy.
Negative placeholders indicate unknown factors rather than numeric deductions; the figure visualizes directional underwriting logic, not a completed cash-flow statement.
[CI021, CI022, CI024, CI025, CI026]4.4 Financial Verdict and Diligence Blockers
Financially, Ontic looks like a credible but still partially opaque late-growth SaaS company. There is clear evidence of institutional investor confidence, customer-level ROI narratives, and enterprise-scale contracts, all of which support the idea that real revenue exists and that the product solves expensive problems. What is missing is the operating quality layer required for underwriting: audited revenue composition, gross margin, renewal behavior, cohort expansion, CAC, payback, burn, and runway. The most practical conclusion is that Ontic’s financial profile is investable only if investors can verify that the large 2025 raise is accelerating efficient growth rather than compensating for weak economics or prolonged federal/enterprise deployment cycles. The conflict between public trackers should be treated as a diligence signal, not a rounding issue. Until management opens the data room on retention, services mix, and cash conversion, the right stance is cautious optimism with explicit blocker status on revenue quality and capital efficiency.[CI030, CI031, CI032, CI033, CI034, CI035]
| Missing metric | Impact | Exact diligence path |
|---|---|---|
| Audited revenue and ARR bridge | Prevents clean underwriting of revenue quality | Request monthly recurring revenue bridge, deferred revenue, and GAAP revenue walk |
| Gross margin by software vs services | Hides real scalability and implementation drag | Request segment gross margin and services utilization detail |
| CAC, payback, and pipeline conversion | Blocks sales-efficiency analysis | Request S&M spend, new ARR, win rates, and payback by segment |
| NRR, GRR, and churn | Blocks durability analysis | Request cohort renewal and expansion data for 2023-2026 vintages |
| Cash balance, burn, and runway | Blocks capital adequacy analysis | Request latest board package with cash forecast and downside plan |
| Public-sector revenue mix and implementation cost | Blocks judgment on federal expansion economics | Request federal ARR, margin, deployment timeline, and compliance cost detail |
These are the exact financial blockers that prevent a full underwriting view from public evidence alone.
[CI028, CI029, CI030, CI031, CI033, CI034]4.5 Exhibits
05Product & Technology
5.1 Platform Definition and Module Map
Ontic’s product story is coherent: the company sells an AI-powered connected-intelligence platform for corporate and government security teams, not a collection of isolated point tools. Official pages describe a unified environment where incidents, investigations, integrated research, executive protection, and response workflows share data and context. That module structure matters strategically because the customer problem is fragmented by default—external signals live in one tool, case documentation in another, and guard response somewhere else entirely. Ontic’s product thesis is that value comes from connecting those surfaces into a defensible system of record. The March 2026 Dispatch launch strengthens that thesis by pulling physical response into the same operating model as intelligence and investigations. The case-management and integrated-research pages reinforce the same architecture pattern: connect signals, centralize case work, automate triage, and preserve evidence. Product breadth is therefore no longer just intelligence plus documentation; it now extends into real-time operational coordination as well.[CE001, CE002, CE003, CE004, CE005, CE006]
| Module / asset | Primary user | Status / maturity | Differentiation | Diligence gap |
|---|---|---|---|---|
| Platform core / Connected Intelligence | Security leaders, GSOC teams | Core platform, mature messaging | Unified system of record across workflows | Need detailed infrastructure and tenancy design |
| Incidents, Investigations, and Case Management | Investigators, analysts | Core product, mature | Connects incidents to research and case workflows | Need workflow-volume and performance detail |
| Integrated Research | Investigators, analysts | Core product, mature | OSINT-driven research inside the same workflow | Need source provenance, licensing, and refresh detail |
| Executive Protection | EP teams, corporate security | Established use case | Connects digital and physical signals around principals | Need precision / false-positive data |
| Dispatch | GSOC and response teams | New in 2026 | Brings real-time guard response into the platform | Need adoption, uptime, and mobile workflow evidence |
| Government / FedRAMP deployment posture | Federal security teams | Newly strengthened in 2026 | Authorization expands addressable mission-critical use | Need public-sector implementation references |
Module maturity is inferred from product-page visibility and launch timing rather than from a public SKU catalog.
[CE001, CE002, CE003, CE004, CE005, CE006]| User job | Current workflow pain | Ontic solution | Measurable benefit | Limitation |
|---|---|---|---|---|
| Investigate a threat report | Signals and evidence scattered across tools | Unified incidents, case management, and research | Faster triage and better evidence continuity | Public proof on throughput is limited |
| Monitor a principal / executive | Noisy online and physical signals are disconnected | Executive protection workflow connects disparate signals | Earlier pattern recognition before escalation | False-positive and alert-fatigue rates are not public |
| Run a site risk assessment | Manual collection and reporting effort | Structured workflow and reusable assessments | Ally cites up to 8 hours saved per assessment | Single case study is not a population-level metric |
| Respond to a physical incident | Dispatch lives outside investigation record | Dispatch links response into incidents and investigations | Time-stamped response documentation and SLA visibility | New module still needs production-scale proof |
| Share insights across functions | Security, HR, legal, and operations use separate systems | Connected intelligence and integrations unify context | Better coordination and a defensible record | Integration setup burden is not publicly quantified |
Benefits use public case-study and product-messaging signals; they should be treated as directional rather than benchmarked outcomes.
[CE004, CE007, CE010, CE012, CE014, CE021]Publicly visible layers of Ontic’s connected-intelligence platform.
[CE001, CE002, CE010, CE011, CE013]5.2 Architecture, Integrations, and AI Workflow
Public technical detail is high level, but the architecture signals that do exist are directionally strong. Ontic repeatedly frames the product as a centralized system that unifies disparate data sources, security systems, public data, and workflow records. The integrations page explicitly positions interoperability as a core product principle rather than an optional ecosystem feature. The incidents and investigations page says that case management connects to risk intelligence and integrated research, while the integrated-research page highlights OSINT-driven identity, watchlist, and international research checks. FedRAMP-related materials further state that the platform supports AI-driven workflows including summarization, entity resolution, and workflow automation. Taken together, that points to a cloud platform organized around an entity database, connected workflows, and external data ingestion rather than around a single analytics model. The main technical caveat is opacity: Ontic does not publish detailed infrastructure diagrams, model architecture, uptime metrics, or data-retention specifics publicly, so the real complexity cost of its integration-heavy design still requires direct technical diligence.[CE010, CE011, CE012, CE013, CE014, CE015]
| Layer / component | Role | Dependency | Risk |
|---|---|---|---|
| Entity / system-of-record layer | Centralizes people, incidents, cases, and relationships | Data model quality and permissions | Bad identity resolution or permissions could contaminate investigations |
| Integrated research / OSINT ingestion | Pulls public and watchlist signals into workflows | External data sources and licensing | Source outages or licensing shifts can reduce coverage |
| Integrations layer | Connects security, HR, identity, and operational systems | API access and partner ecosystem maintenance | Integration breakage can erode product value quickly |
| AI workflow layer | Summarization, entity resolution, automation | Model governance and human oversight | Opaque model behavior can create compliance and trust issues |
| Dispatch / response layer | Coordinates real-time response and documentation | Latency, mobile reliability, and staffing adoption | Real-time failures are more operationally visible than case-work delays |
| Compliance / control layer | Supports FedRAMP and defensible operations | Continuous monitoring and control maintenance | Authorization drift can jeopardize public-sector use |
The architecture is reconstructed from public materials; Ontic does not publish a detailed system diagram or control-plane specification publicly.
[CE011, CE012, CE013, CE015, CE016, CE018]How a signal becomes a documented response inside Ontic’s product model.
[CE004, CE007, CE015, CE021, CE022]Technical dependencies that can strengthen or weaken Ontic’s product advantage.
[CE011, CE012, CE013, CE018, CE024, CE029]5.3 Trust, Compliance, and Operational Maturity
Trust and compliance are becoming central parts of Ontic’s moat rather than back-office hygiene. The April 2026 FedRAMP Moderate authorization and associated ATO materially strengthen Ontic’s readiness for public-sector deployments and create a harder-to-replicate posture versus less regulated competitors. FedRAMP and the government-focused PR describe the platform as purpose-built for centralized threat management, integrated intelligence, AI-driven workflows, and mission-critical operations. The Dispatch launch adds another dimension of maturity because it implies the product can handle real-time response documentation, SLA visibility, and defensible records during active incidents, not just post-incident case management. These are strong signals for enterprise and federal buyers that care about auditability, chain of action, and defensible operating procedures. Still, the trust story has limits in public evidence. We do not see public SLA data, public model-governance disclosures, or transparent evidence about false-positive management. In other words, Ontic has crossed an important compliance threshold, but not all technology-risk questions are answered by authorization alone.[CE019, CE020, CE021, CE022, CE023, CE024]
| Control / certification / quality signal | Status | Scope | Gap |
|---|---|---|---|
| FedRAMP Moderate Authorization | Achieved Apr 2026 | Public-sector deployment eligibility | Need evidence on operating burden and customer adoption |
| Authority to Operate (ATO) | Received | Mission-critical security operations use | Need implementation examples and sponsoring-agency detail |
| Time-stamped response documentation | Publicly described for Dispatch | Compliance, legal defensibility, after-action review | Need proof of real-world workflow usage |
| AI-driven summarization and entity resolution | Publicly described | Workflow acceleration and threat surfacing | Need governance, override, and error-rate detail |
| Integrated intelligence from public data, security systems, social media, and dark web | Publicly described | Threat detection breadth | Need data-retention and provenance detail |
Controls are public signals, not a complete compliance matrix. FedRAMP is the strongest third-party validation in the current record.
[CE019, CE020, CE021, CE022, CE023, CE024]| Date / stage | Feature / milestone | Status | Implication | Source |
|---|---|---|---|---|
| 2025 | Integrated investigations + always-on research messaging | Launched / publicized | Signals tighter fusion of case management and research | Ontic press release |
| 2025-11 | 2026 security forecast report | Published | Shows company emphasis on AI, proactive security, and connected operations | Ontic forecast report |
| 2026-03 | Dispatch launch | Launched | Extends platform into physical response and coordination | PR Newswire |
| 2026-04 | FedRAMP Moderate + ATO | Achieved | Expands public-sector readiness and trust posture | PR Newswire / FedRAMP |
| 2026 | Ongoing hiring via careers and Ashby jobs | Active | Implies continued product and engineering investment | Careers / jobs pages |
| Current | Interoperability / integrations emphasis | Ongoing | Platform value depends on continuing partner and system connectivity | Integrations page |
Roadmap visibility is release-driven because Ontic does not publish a detailed forward roadmap or public changelog.
[CE006, CE017, CE019, CE026, CE033]Relative maturity of Ontic’s most visible capabilities based on public evidence.
[CE019, CE020, CE021, CE027, CE030]5.4 Roadmap Risk and Technical Verdict
The product roadmap looks strategically sensible: deepen the system-of-record thesis, add real-time response, and use AI to reduce analyst workload. The risk is that each of those moves also increases architectural burden. A platform that promises integrations, OSINT, investigations, dispatch, government-grade security, and AI workflow automation must maintain data quality, permissions, audit trails, latency, and explainability across many surfaces simultaneously. That complexity does not make the strategy wrong; in fact, it is part of what makes the product differentiated. But it does mean the company’s technical moat is execution-dependent rather than self-proving. Careers and jobs pages show the company is still building, which is encouraging for roadmap capacity but also implies continuing platform investment. The right technical verdict is positive with diligence conditions: Ontic appears to have a real platform and meaningful compliance progress, yet buyers and investors still need direct proof on reliability, model governance, infrastructure scale, and the operating burden of maintaining a deeply integrated security system.[CE027, CE028, CE029, CE030, CE031, CE032]
5.5 Exhibits
06Customers
6.1 Customer Base and Segmentation
Ontic’s public customer footprint is clearly enterprise-led rather than mass-market. The company’s homepage, clients pages, and case-story archive consistently point to corporate and government security teams, Fortune 500 environments, and functionally complex use cases spanning executive protection, investigations, risk assessment, and intelligence operations. Named or semi-named stories cover financial services, travel technology, insurance, enterprise software, and broader large-enterprise security teams, while FedRAMP-related materials indicate active public-sector relevance as well. GetLatka’s estimate of 26 customers in 2025 fits that picture: this is not a volume-logo motion, but a concentrated, high-touch enterprise base. That structure has positive and negative consequences. On the positive side, customers appear large enough to justify meaningful implementation effort and cross-functional workflow adoption. On the negative side, a relatively small number of logos can create concentration sensitivity if even a handful of accounts are disproportionately large, and public evidence does not yet disclose the top-account mix needed to dismiss that risk.[CU001, CU002, CU003, CU004, CU005, CU006]
| Segment | Buyer / user / payer | Use case | Scale signal | Revenue / strategic value | Gap |
|---|---|---|---|---|---|
| Fortune 500 enterprise security | CSO / investigators / security budget | Investigations, executive protection, response | Multiple named and anonymized case stories | Likely high ACV, strategic accounts | No segment-level ARR disclosed |
| Financial services | Security / risk teams | Site risk, threat assessment, research | Ally and Visa references | Strong proof of regulated-enterprise relevance | No renewal or expansion metrics |
| Technology / software | Security teams and GSOC | Research, investigations, team scaling | Travel-tech and software company stories | Indicates platform fit in complex digital businesses | Unknown customer count by vertical |
| Insurance | Corporate security | Workflow automation and manual-work reduction | Fortune 500 insurance case | Evidence of measurable efficiency outcome | Named logo withheld |
| Government / public sector | Government security teams | Threat management, investigations, response | FedRAMP and government positioning | Potential diversification beyond commercial base | No public customer-count or ARR data |
Segmentation is built from public case stories and regulatory posture rather than a disclosed customer roster or revenue-by-vertical table.
[CU001, CU002, CU003, CU005, CU006, CU026]| Metric | Value | Date | Source | Confidence | Implication | Missing denominator |
|---|---|---|---|---|---|---|
| Estimated customers | 26 | 2025 | GetLatka | medium | Suggests concentrated enterprise base | No official customer count |
| Public client-story surface | Multiple named and anonymized stories | 2026 | Ontic clients pages | medium | Shows breadth of referenceable deployments | No ratio of stories to live customers |
| Public-sector readiness | FedRAMP Moderate + ATO | 2026 | PR / FedRAMP | high | Expands eligible buyer pool | No disclosed federal customer count |
| External review presence | FeaturedCustomers, G2, Gartner, GetApp | 2026 | Review surfaces | medium | Indicates public customer feedback exists | No conversion from reviews to retention |
| Cross-functional expansion signal | Assessments + research + investigations + response | 2026 | Product and case stories | medium | Supports land-and-expand thesis | No module attach-rate data |
This table uses observable adoption signals because Ontic does not publish formal cohort, deployment, or active-user trajectories.
[CU003, CU018, CU022, CU026, CU027]Typical enterprise customer journey from trigger event to expanded Ontic deployment.
[CU004, CU010, CU014, CU026, CU027]6.2 Named Customer Proof and Outcomes
Ontic’s strongest customer evidence is its library of applied workflow outcomes. Ally says Ontic saved up to eight hours per site risk assessment. Visa says Ontic centralized threat research and integrated multiple investigative tools. A Fortune 500 insurance company reportedly cut manual work by 85 percent. A Fortune 500 travel-technology customer describes better investigations and more efficient information sharing. Additional enterprise-software stories emphasize turning disjointed research into a stronger investigations program and scaling a small security team. These are meaningful proofs because they map to specific security jobs to be done rather than vague “digital transformation” claims. They also suggest Ontic is used in production-like workflows across multiple verticals, not only in pilot or innovation-lab settings. Still, the quality of this evidence has an obvious limit: nearly all of it is company-authored, selectively curated, and biased toward successful deployments. Public case stories are useful proof of adoption and use-case fit, but they do not replace cohort retention data or independently audited usage metrics.[CU009, CU010, CU011, CU012, CU013, CU014]
| Customer | Segment | Deployment / use case | Production vs pilot | Outcome | Limitation |
|---|---|---|---|---|---|
| Visa | Financial services | Centralized threat research and integrated investigative tooling | Production-like public story | Research workflows centralized for enhanced protection | Company-authored case story only |
| Ally | Financial services | Site risk assessments | Production-like public story | Up to 8 hours saved per assessment | Single-customer productivity metric |
| Fortune 500 travel technology company | Technology / travel | Investigations and information sharing | Production-like public story | Saved time and maximized efficiency | Customer name not public |
| Fortune 500 insurance company | Insurance | Workflow automation and investigations | Production-like public story | Manual work reportedly cut by 85% | Customer name not public |
| Fortune 500 software company | Enterprise software | Research and investigations program build-out | Production-like public story | Disjointed research turned into stronger investigations | Quantitative outcome not public |
| Honeywell / leading security teams | Industrial / enterprise security | Value demonstration and reporting | Production-like public story | ROI and executive trust narrative | Outcome metrics are qualitative |
Rows are limited to customer proofs that were public and fetchable through the company site or cited case-study aggregators as of 2026-06-21.
[CU009, CU010, CU011, CU012, CU013, CU014]How Ontic appears to move from customer problem to durable workflow adoption.
Funnel values are ordinal illustrative stages rather than source-native conversion rates; the point is the deployment logic implied by public case studies.
[CU009, CU010, CU011, CU012, CU013]Quality of public customer proof across outcome specificity, naming quality, and durability visibility.
[CU009, CU010, CU011, CU012, CU013, CU015]6.3 Satisfaction, Retention, and Durability Signals
Satisfaction signals are present, but they are thinner than the case-study volume might suggest. FeaturedCustomers maintains an Ontic vendor page that advertises dozens of customer reviews and references, while G2, Gartner Peer Insights, and GetApp each host product-review surfaces for Ontic. That matters because it shows public customer feedback exists beyond the company’s own website. However, these surfaces do not solve the central durability problem for underwriting. Public review availability is not the same thing as high renewal rates, multi-year contract stickiness, or healthy expansion economics. No public source reviewed for this chapter provides NRR, GRR, logo churn, renewal cohorts, median contract length, or customer lifetime value. Even review pages that may speak to user sentiment are too shallow from an underwriting standpoint without underlying usage and commercial data. The result is a mixed but still favorable read: there is enough public evidence to believe Ontic has real and referenceable customers, but not enough to conclude those customers renew and expand at the rate an investor would want to see from a high-valuation enterprise-security platform.[CU018, CU019, CU020, CU021, CU022, CU023]
| Metric | Value / null | Segment | Confidence | Diligence ask |
|---|---|---|---|---|
| FeaturedCustomers review presence | 69 reviews and references | Cross-customer | medium | Validate how many references are current production users |
| Gartner review surface | Public page exists | Cross-customer | low | Request review excerpts, deployment scope, and recent dates |
| G2 review surface | Public page exists | Cross-customer | low | Request product-area breakdown and customer tenure |
| GetApp review surface | Public page exists | Cross-customer | low | Request independent CSAT or NPS instead of directory presence |
| NRR / GRR | null | All segments | low | Provide renewal and expansion metrics by cohort |
| Logo churn | null | All segments | low | Provide churn reasons and lost-account history |
Public review surfaces support customer existence and some satisfaction signal, but not a rigorous retention-underwriting view.
[CU018, CU019, CU020, CU021, CU022, CU023]6.4 Expansion and Concentration Risk
The expansion story is plausible but not yet numerically proven. Ontic’s multi-module product surface—assessments, research, incidents, investigations, executive protection, and now response—creates a logical land-and-expand path inside large accounts. Public-sector readiness through FedRAMP could also diversify the customer base beyond purely commercial enterprises over time. Customer stories further imply cross-functional value that can move from one team to others within the same organization. But every positive expansion narrative has a matching concentration caveat. If the public estimate of roughly 26 customers is directionally right, then Ontic likely depends on a modest number of high-value relationships. That raises exposure to procurement friction, slow federal cycles, budget resets, and account-level deployment disappointments. Because public sources do not disclose top-customer concentration, contract duration, or renewal history, investors cannot conclude that the current base is broadly de-risked. The proper customer verdict is therefore favorable on adoption proof, but incomplete on durability and concentration.[CU026, CU027, CU028, CU029, CU030, CU031]
| Expansion driver | Concentration risk | Impact | Diligence path |
|---|---|---|---|
| Multi-module product footprint | A small number of large logos may dominate ARR | High if 26-customer estimate is directionally right | Request top-10 customer ARR concentration and module mix |
| Public-sector expansion via FedRAMP | Federal sales cycles can be slow and lumpy | Medium-High | Request federal pipeline, wins, and implementation history |
| Cross-functional workflow value | Expansion may depend on successful internal change management | Medium | Request module attach rates and post-implementation adoption |
| High-ACV enterprise motion | Procurement and budget resets can delay renewals or upsells | High | Request contract terms, renewal timing, and deferred pipeline |
| Referenceable case studies | Company-authored proof may overstate broad-base expansion | Medium | Triangulate with third-party reference calls and support tickets |
Expansion logic is strategically sensible, but the public evidence is still too thin to rule out concentration-driven volatility.
[CU003, CU024, CU026, CU027, CU030, CU032]| Topic | Missing evidence | Why it matters | Owner / diligence path |
|---|---|---|---|
| Top-customer concentration | Top-10 ARR share and contract end dates | Needed to judge downside from a small logo base | Finance + sales ops data room |
| Retention durability | NRR, GRR, logo churn, and cohort expansion | Needed to separate referenceability from recurring strength | Revenue operations and FP&A |
| Public-sector customer mix | Live government customers vs pipeline | Needed to test diversification thesis | Public-sector sales leadership |
| Deployment depth | Active users, workflows, and modules per customer | Needed to judge stickiness and cross-sell potential | Product analytics / customer success |
| Support quality at scale | Ticket backlog, implementation time, and services effort | Needed to understand adoption friction | Support and implementation leaders |
These gaps explain why customer quality is positive but not fully underwritten from public evidence alone.
[CU028, CU029, CU031, CU033, CU034, CU035]6.5 Exhibits
07Risks
7.1 Legacy, Legal, and Regulatory Risk
The highest-salience risk is the lingering shadow of the Banjo controversy and its broader implications for privacy, procurement, and trust. Multiple independent sources describe how Banjo’s Utah surveillance contract unraveled after scrutiny of the company’s claimed capabilities, surveillance posture, and founder history. Even if Ontic’s current operating model is more enterprise-security-oriented and substantially cleaner, diligence processes will continue to revisit that legacy because it raises uncomfortable questions about data ethics, vendor vetting, public-sector suitability, and reputational resilience. Ontic’s 2026 FedRAMP win is an important counterweight, but it also increases the compliance burden. FedRAMP Moderate and an ATO are not endpoints; they introduce continuing control, documentation, and monitoring obligations. Broader compliance literature from KPMG, Thomson Reuters, Deloitte, Celent, and CMMC/FedRAMP commentary reinforces the same conclusion: AI-enabled security vendors face a rising burden around privacy, governance, documentation, and regulator expectations. For Ontic, the risk is not simply formal noncompliance. It is that any lapse could reactivate legacy skepticism precisely where trust matters most—in government and large-enterprise security use cases.[CR001, CR002, CR003, CR004, CR005, CR006]
| Rule / license / case | Jurisdiction | Status | Likelihood | Severity | Mitigation | Residual exposure | Diligence path |
|---|---|---|---|---|---|---|---|
| Banjo legacy surveillance controversy | US / Utah / reputational spillover | Historical but still diligence-relevant | Medium | High | Rebranding, new leadership, trust-forward posture | Reputational and procurement overhang remains | Test customer and agency reactions in reference calls |
| FedRAMP Moderate continuous compliance | US federal | Active current obligation | Medium | High | Continuous monitoring, controls, ATO maintenance | Control drift could threaten public-sector thesis | Review SSP cadence, POA&M process, and audit history |
| Privacy / surveillance law evolution (CCPA, GDPR-like regimes, AI rules) | Multi-jurisdiction | Ongoing external change | High | High | Policy updates, governance, product controls | Rules can tighten faster than product/process updates | Map data flows and privacy controls by jurisdiction |
| Procurement representation risk for AI/security claims | Government and enterprise procurement | Ongoing | Medium | Medium-High | Clear documentation and scoped claims | Overstatement risk remains material in trust-sensitive deals | Review RFP language, proof points, and legal review workflow |
| Civil-liberties scrutiny of integrated surveillance data use | Public-sector and large enterprise | Ongoing | Medium | Medium-High | Explainable workflows and documented use policies | Advocacy or press scrutiny can reignite quickly | Review acceptable-use policies and high-risk customer segments |
| AI governance and explainability expectations | Cross-jurisdiction | Rising | High | Medium-High | Human oversight and workflow controls | Opaque model behavior could still cause trust failures | Request AI governance artifacts and exception handling logs |
Rows are ordered by how directly they can damage trust, procurement eligibility, and the public-sector thesis.
[CR001, CR002, CR003, CR004, CR005, CR006]Relative ranking of Ontic’s highest-level risk themes by likelihood and impact.
[CR001, CR005, CR012, CR024]7.2 Operational and Technology Risk
Ontic’s product advantage is inseparable from operational complexity. A platform that promises connected investigations, integrated research, executive protection, and response coordination depends on data quality, integration reliability, permissions discipline, and low-latency workflow execution across many moving parts. The March 2026 Dispatch launch raises the stakes further because real-time response failures are more visible and more operationally damaging than slower research or documentation workflows. Ontic’s own product materials highlight integrated public data, security systems, social inputs, dark-web monitoring, and AI-driven workflow acceleration. Those features are commercially attractive, but they also multiply failure modes: noisy or stale data, false positives, identity-resolution errors, broken integrations, and user workarounds can all degrade trust. Public sources do not provide uptime, incident-history, or model-error metrics, which leaves meaningful operational risk unquantified. This is not unusual for a private security software company, but it matters because Ontic is increasingly asking buyers to run mission-critical processes inside the platform rather than use it only as an intelligence adjunct.[CR012, CR013, CR014, CR015, CR016, CR017]
| Failure mode | Likelihood | Severity | Mitigation maturity | Residual exposure | Unresolved gap |
|---|---|---|---|---|---|
| Integration failure or stale data sources | Medium | High | Medium | High | No public data on connector reliability or maintenance burden |
| AI false positives / false negatives in threat workflows | Medium | High | Medium | High | No public error-rate or override data |
| Dispatch or response-workflow failure during live incidents | Low-Medium | High | Low-Medium | High | No public uptime or incident-response benchmarks |
| Permissions / entity-resolution mistakes | Medium | Medium-High | Medium | Medium-High | No public evidence on identity-resolution QA controls |
| Security or privacy incident involving sensitive data aggregation | Low-Medium | High | Unknown | High | No public incident-history disclosure |
| Customer adoption workarounds or training failure | Medium | Medium | Medium | Medium | No public deployment-depth or support-quality metrics |
Operational severity is elevated because Ontic is positioning itself inside real investigative and response workflows, not only around peripheral monitoring.
[CR012, CR013, CR014, CR015, CR016, CR017]How legal, operational, and concentration risks can flow into growth, margin, and valuation.
[CR004, CR007, CR014, CR032, CR035]7.3 Dependency and People Risk
Dependency risk sits at three levels. First, Ontic depends on external data sources, enterprise integrations, and cloud or platform infrastructure to make its connected-intelligence thesis real. Second, it depends on regulators and compliance frameworks—especially FedRAMP—to unlock and preserve public-sector credibility. Third, it depends on people: CEO Lukas Quanstrom and the rest of the reconstituted leadership team are central to strategy, trust repair, and commercial execution after the Banjo era. The company’s careers and jobs pages suggest active ongoing hiring, which is positive for capacity but also a reminder that product, engineering, and customer-success talent are competitive bottlenecks. A security platform that sells into complex enterprises cannot tolerate weak implementation, thin support, or high turnover in go-to-market and product leadership roles. Public evidence also does not disclose top-customer concentration or account-level dependency, which means concentration could exist simultaneously on the customer and leadership sides. Those are manageable risks, but they become thesis-threatening if growth slows, key leaders leave, or implementation debt starts to show up in reference accounts.[CR022, CR023, CR024, CR025, CR026, CR027]
| Dependency | Counterparty | Role | Concentration | Failure scenario | Severity | Mitigation | Residual exposure |
|---|---|---|---|---|---|---|---|
| External data / OSINT sources | Multiple third-party feeds and public data providers | Fuel research and threat detection | Diffuse but essential | Coverage loss or licensing restrictions reduce platform value | High | Diversify inputs and document provenance | Medium-High |
| Enterprise integrations | HR, identity, security, and operational systems | Connect context into Ontic workflows | Account-specific | Broken APIs or poor mapping hurt deployments | High | Connector maintenance and implementation discipline | High |
| FedRAMP / government compliance authorities | FedRAMP ecosystem and sponsoring authorities | Enable government use | Moderate | Authorization drift blocks public-sector expansion | High | Control ownership and monitoring rigor | Medium-High |
| Large enterprise customers | Fortune 500 and public-sector accounts | Revenue base and referenceability | Potentially concentrated | One or two losses weaken growth and trust signals | High | Diversify base and increase module expansion | High |
| Capital providers and board sponsors | KKR and other investors | Governance and growth support | Moderate | Pressure for accelerated growth increases execution risk | Medium | Align milestones and maintain transparency | Medium |
Dependency risk is concentrated less in a single supplier and more in a set of interlocking external systems, regulators, and marquee accounts.
[CR022, CR023, CR024, CR025, CR032, CR033]| Role / function | Dependency or gap | Likelihood | Severity | Mitigation | Diligence path |
|---|---|---|---|---|---|
| CEO and public face | Trust, strategy, and investor narrative remain leadership-dependent | Medium | High | Board depth and executive bench | Assess succession planning and customer reliance on CEO access |
| Product / engineering leadership | Needed to sustain integrations, AI governance, and Dispatch quality | Medium | High | Active hiring and leadership depth | Review org chart, attrition, and roadmap ownership |
| Implementation / customer success | Complex deployments require strong field execution | Medium | High | Reference customers and process standardization | Review implementation timelines and escalation rates |
| Public-sector sales and compliance operators | Needed to convert FedRAMP into real revenue | Medium | Medium-High | Specialized hiring and process rigor | Review federal pipeline conversion and staffing plan |
| Culture / ethics after Banjo legacy | Trust repair depends on internal consistency and governance | Medium | Medium-High | Clear ethics stance and screening | Probe culture, training, and whistleblower processes |
Execution risk is elevated because Ontic’s moat depends on disciplined delivery as much as on product vision.
[CR026, CR027, CR028, CR029, CR030, CR031]External systems and actors that most affect Ontic’s risk profile.
[CR022, CR023, CR024, CR026, CR027]7.4 Financial / Model Risk and Kill Criteria
Ontic’s financial-model risk is less about imminent insolvency and more about whether the company can convert heavy capital, strong product ambition, and a referenceable customer base into efficient, durable growth. Public evidence does not disclose cash burn, retention, or concentration. GetLatka’s low customer count estimate and the chapter 4 capital-intensity math imply that a modest number of large accounts may carry substantial economic weight. That creates sensitivity to procurement delays, contract losses, or slower-than-expected public-sector conversions. The competitive backdrop compounds the issue: better-capitalized and better-known rivals can frame evaluations around their own strengths while Ontic is still investing in product breadth, compliance, and trust restoration. The right way to manage these risks is to define thesis-break triggers early. If FedRAMP slips, if major reference accounts fail to expand, if turnover hits the top team, or if privacy and surveillance narratives reattach to the brand, the investment case weakens quickly. Conversely, if Ontic demonstrates stable retention, disciplined compliance operations, and module expansion across a diversified base, many of these risks become manageable rather than fatal.[CR032, CR033, CR034, CR035, CR036, CR037]
| Risk | Monitorable trigger | Threshold / event | Action implication |
|---|---|---|---|
| FedRAMP / compliance slippage | Authorization or control findings worsen | Major POA&M backlog, authorization issue, or failed monitoring cycle | Pause government-growth underwriting and reassess trust posture |
| Customer concentration | Large reference account weakens or fails to renew | Top account loss, stalled expansion, or procurement freeze | Recut revenue durability and downside scenario |
| Leadership fragility | Top team turnover rises | CEO or key product / compliance leader departs unexpectedly | Increase execution-risk discount and test succession depth |
| Privacy / surveillance narrative relapse | Adverse press or advocacy scrutiny resurfaces materially | Major press cycle or customer objections tie Ontic back to Banjo-style surveillance concerns | Reassess reputational moat and public-sector viability |
| Operational reliability | Live-workflow failures emerge in the field | Reference customers cite uptime, integration, or response failures | Reduce confidence in platform-expansion thesis |
These kill criteria focus on the few risk transmissions that could change the investment thesis quickly rather than on every background operational issue.
[CR036, CR037, CR038, CR039, CR040]7.5 Exhibits
08Valuation
8.1 Current Financing Context and Entry Discipline
The current valuation puzzle starts with a fact pattern that is simultaneously bullish and incomplete. Official sources confirm a $230M KKR-led Series C in August 2025 and roughly $287M of total funding, but the company did not publish the post-money valuation. Third-party revenue trackers offer the only public operating anchors, and those anchors are modest relative to the round size: GetLatka reports $35.6M ARR in 2025 while Growjo estimates roughly $42.4M in revenue. If outside investors are using a valuation near $1B—as implied by multiple private-market references and market chatter—then Ontic is either priced on hidden quality metrics not visible publicly or on a very aggressive forward view of government expansion, workflow depth, and AI-enabled category leadership. That does not make the round irrational; late-stage private investors often pay for strategic option value. But it does mean entry discipline matters. Without retention, margin, burn, or concentration disclosure, the current public evidence supports a stretched valuation stance rather than an obviously attractive one.[CV001, CV002, CV003, CV004, CV005, CV006]
| Recommendation | Confidence | Risk rating | Valuation stance | Decision implication |
|---|---|---|---|---|
| research-more | medium | high | stretched | Continue diligence, but do not underwrite current price without private metric verification |
This recommendation is specific to valuation evidence, not a full investment committee decision across all dimensions.
[CV031, CV032, CV040]| Argument | What would change the view |
|---|---|
| Ontic owns a differentiated connected-intelligence workflow in a strategically important category | Proof of weak retention or heavy services mix would weaken the thesis materially |
| FedRAMP and public-sector readiness create optionality beyond enterprise accounts | Failure to convert public-sector readiness into real customers would reduce premium justification |
| Named enterprise customer proof shows the product solves costly problems | Evidence that case-story customers do not expand or renew would weaken conviction |
| Institutional sponsorship by KKR suggests serious upside ambition | A round-sized capital base without efficient growth would imply overfunding, not validation |
| Security / AI / vertical-workflow categories can command premium multiples | If Ontic’s AI is mostly marketing wrapper rather than defensible workflow, the premium should compress |
The anti-thesis focuses on the few facts that could most directly collapse the valuation bridge rather than on generic software risk.
[CV011, CV018, CV031, CV033, CV036]How market, product, customer, and financial evidence translate into a stretched valuation stance.
[CV001, CV003, CV011, CV012, CV031]8.2 Comparable Set and Multiple Framework
The most useful valuation lens is triangulation rather than precision. Public SaaS benchmark sources place median 2026 revenue multiples in the low single digits, with the best security, AI, infrastructure, or vertical-SaaS names earning materially higher premiums when growth, retention, and Rule-of-40 quality are strong. That is encouraging for Ontic because the company sits at the intersection of security, vertical workflows, and AI-flavored automation. However, the same benchmark sources repeatedly emphasize that premium multiples now require efficient growth, durable retention, and proof that AI is embedded in a defensible workflow rather than a marketing wrapper. Ontic’s adjacent-private comparables also cut both ways. Everbridge’s $1.8B take-private and AlertMedia’s reported >$1B sale exploration show real strategic value in resilience and communications platforms. Dataminr’s capital formation shows investors will support scaled signal leaders. Yet those comps are not plug-and-play. They each have different scale, maturity, or market structure. The takeaway is that Ontic may deserve a premium to generic public SaaS, but public evidence does not yet prove it deserves the kind of premium required to make a ~$1B valuation obviously conservative.[CV011, CV012, CV013, CV014, CV015, CV016]
| Case | Assumptions | Valuation / return logic | Key risks | Probability signal |
|---|---|---|---|---|
| Bull | True ARR materially above public trackers; strong NRR; government and enterprise expansion accelerate | ~$80M-$100M ARR at ~10x-12x supports ~$800M-$1.2B | Execution, concentration, and compliance still matter | Needs private data proving premium quality |
| Base | Public ARR range roughly right but quality is solid and premium justified | ~$40M-$45M ARR at ~6x-8x supports ~$240M-$360M | Current round likely priced ahead of public fundamentals | Most plausible on current public evidence |
| Bear | Public ARR range right and durability weaker than hoped | ~$35M-$40M ARR at ~4x-5x supports ~$140M-$200M | Retention, concentration, or margin disappoint | Downside if premium narrative breaks |
| Stretch-to-round | Current implied valuation near ~$1B requires hidden metrics or unusually strong forward underwriting | Either ARR is far above public proxies or investors are paying for future option value | Multiple compression if hidden quality does not materialize | Possible, but not proven publicly |
Scenario values are analytical estimates that combine public ARR proxies with benchmark multiple ranges from current SaaS-market sources.
[CV003, CV004, CV021, CV022, CV023, CV024]| Comparable | Metric | Multiple / valuation / status | Relevance | Limitation |
|---|---|---|---|---|
| Public SaaS median (publicsaascompanies) | Revenue multiple | 2.62x median / 4.77x average | Baseline for 2026 public software valuation | Broad cohort, not security-specific |
| Public SaaS benchmark (WeAreFounders) | EV/ARR multiple | 4.0x median / 6.6x average | Simple sanity check for public-market baseline | Secondary synthesis, not primary market data |
| Security / premium SaaS range | Revenue multiple | ~5x-8x typical premium band | Better fit for mission-critical security software | Still a sector heuristic, not Ontic-specific |
| Everbridge take-private | Transaction value | $1.8B all-cash | Adjacency in critical-event/resilience software | Much larger and more mature platform |
| AlertMedia sale exploration | Private value signal | > $1B sale process reported | Adjacent communications/risk platform value marker | Process, not closed transaction |
| Ontic implied round view | Private value signal | ~$1B widely implied but undisclosed | Current decision anchor | Methodology opaque and not confirmed by company |
This table intentionally mixes public-multiple and private-transaction lenses because no single comparable set cleanly matches Ontic’s stage, product scope, and disclosure level.
[CV012, CV013, CV014, CV015, CV016, CV017]Illustrative valuation sensitivity to different revenue-multiple assumptions on a ~$40M ARR base.
Uses a rounded $40M ARR base to illustrate how multiple changes alone do not bridge to a unicorn valuation without higher true ARR or much stronger future underwriting.
[CV021, CV022, CV023, CV024]Public-evidence valuation range across bear, base, and bull assumptions.
Ranges combine public ARR proxies with benchmark multiple bands and therefore represent scenario analysis, not direct market quotes.
[CV003, CV004, CV021, CV022, CV023, CV024]8.3 Bull, Base, and Bear Scenarios
The scenario math is blunt. On public ARR proxies alone, even generous premium multiples struggle to support a unicorn valuation. Using the low end of the visible revenue range, a 4x-5x multiple produces a bear valuation around $140M-$210M. A base case that grants Ontic the benefit of better quality and a security premium—say 6x-8x on roughly $40M of ARR—still lands around $240M-$340M. The bull case only becomes compelling if one of two things is true: either public revenue trackers materially understate the company’s true recurring revenue, or Ontic can sustain premium growth and retention such that investors underwrite much higher forward ARR than outsiders can see today. In practical terms, a $1B+ private mark looks supportable only if hidden ARR is closer to $80M-$100M, or if investors believe Ontic can grow into that scale quickly with strong retention and government expansion. That gap between visible fundamentals and required upside is why the valuation stance should be stretched rather than fair on public evidence alone.[CV021, CV022, CV023, CV024, CV025, CV026]
| Trigger | Threshold | Transmission to thesis | Action implication |
|---|---|---|---|
| ARR quality disappoints | Private ARR is close to public proxy and retention is weak | Current premium collapses into stretched-to-untenable territory | Re-rate valuation to base or bear case |
| Customer concentration is high | Top accounts dominate ARR without durable renewals | Downside becomes account-loss driven | Increase discount rate and downside weighting |
| FedRAMP / public-sector conversion stalls | No meaningful federal wins or referenceability | Public-sector option value should be removed from bull case | Cut premium scenario weighting |
| Margin / services mix is weaker than expected | Implementation or services drag lowers software economics | Rule-of-40 style premium cannot be justified | Value on lower public multiple bands |
| Leadership or trust stumble emerges | Brand or governance issues reignite skepticism | Valuation premium for mission-critical trust erodes quickly | Pause investment case pending remediation |
The kill triggers focus on valuation-transmitting facts, not every operating issue covered elsewhere in the report.
[CV034, CV035, CV036, CV037, CV038]IC-style scorecard of the valuation decision inputs most relevant to Ontic in 2026.
[CV003, CV006, CV012, CV013, CV031, CV040]8.4 Recommendation, Thesis Breaks, and Final Diligence Asks
The investment recommendation at the current valuation is best framed as research-more with a stretched valuation stance and medium confidence. Ontic has enough positive evidence—credible institutional backing, a differentiated workflow thesis, named enterprise proof, FedRAMP progress, and adjacency to strategically valuable security-software categories—to justify continued interest. But there is not enough public evidence to justify price confidence. The company needs to prove that revenue quality, retention, concentration, and public-sector conversion are materially better than what the public record suggests. The anti-thesis is straightforward: if Ontic is really a ~$35M-$40M ARR company with heavy capital intensity and incomplete durability proof, then a unicorn-like mark bakes in too much future success too early. The thesis only improves if management can show high-quality ARR, strong net retention, expanding module depth, and a plausible path to scale that narrows the current multiple gap. Until then, valuation is an optimism tax rather than an edge.[CV031, CV032, CV033, CV034, CV035, CV036]
| Topic | Missing evidence | Why it matters | Owner or diligence path |
|---|---|---|---|
| ARR and revenue bridge | Board-approved ARR, GAAP revenue, and deferred-revenue bridge | Primary input to every valuation scenario | CFO / finance data room |
| NRR / GRR / churn | Cohort retention and expansion by segment | Determines whether Ontic deserves premium multiple support | Revenue operations |
| Customer concentration | Top-10 ARR share and contract end dates | Needed to assess downside concentration and renewal risk | Finance + sales ops |
| Gross margin and services mix | Software GM, services drag, implementation cost | Separates premium SaaS economics from labor-heavy delivery | FP&A / operations |
| Public-sector conversion | Live federal customers, pipeline, and deployment metrics | Validates whether FedRAMP creates real option value | Government sales leadership |
| Round terms and preference stack | Series C structure, liquidation preferences, dilution overhang | Needed to assess real return to new money at current price | Company counsel / financing docs |
These are the minimum valuation blockers; without them, price confidence remains materially lower than product or customer confidence.
[CV031, CV032, CV033, CV034, CV039, CV040]8.5 Exhibits
Disclaimer
This report is generated for informational purposes only based on publicly available data as of June 2026. It does not constitute investment advice. Financial metrics are sourced from third-party trackers and may not accurately reflect the company's actual performance. The company does not publicly disclose detailed financial information.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Ontic Technologies is headquartered in Austin, Texas and provides AI-powered Connected Intelligence software for corporate and government security teams. | High | SO001, SO002, SO008 |
| CO002 | Ontic's platform unifies security operations and data into a centralized system of record, aggregating OSINT and external threat signals alongside internal data from HR, legal, IT, and facilities. | High | SO001, SO017 |
| CO003 | Ontic's revenue model is SaaS subscription-based, serving Fortune 500 companies and federal agencies. | High | SO001, SO009 |
| CO004 | The official press release from BusinessWire states Ontic was 'Founded in 2017 and based in Austin, Texas' while predecessor entity Banjo Inc. was founded in 2010 by Damien Patton. | High | SO001, SO002 |
| CO005 | Ontic's platform spans risk intelligence, incident management, investigations, and case management, covering executive protection, workplace violence, insider threats, and travel risk. | High | SO001, SO017 |
| CO006 | Ontic's predecessor entity Banjo Inc. rebranded first to safeXai in 2020 and then to Ontic Technologies in 2021 following the founder's resignation. | Medium | SO008, SO003 |
| CO007 | Lukas Quanstrom serves as CEO and Co-Founder of Ontic Technologies as of 2026. | High | SO006, SO001, SO015 |
| CO008 | Ontic's C-suite includes Brian Mazza (CRO), Nitin Navare (CTPO), Kyle Giunta (COO), Ryan Suneson (CFO), Scott Shepherd (CLO), Manish Mehta (CSIO), Amy Sullivan (EVP Alliances), and Murph Holder (VP People). | High | SO006, SO007 |
| CO009 | The Ontic board of directors consists of Lukas Quanstrom, Mike Dodd (Silverton Partners), Jake Heller (KKR), Bob Nye (JMI Equity), and Murali Swaminathan. | Medium | SO006 |
| CO010 | Ontic maintains an advisory board including Fred Burton, Dave Komendat, Rich Davis, Thomas Kopecky, and Gagan Jain as recognized thought leaders in protective intelligence and corporate security. | Medium | SO006 |
| CO011 | Mark Rose does not appear in any current Ontic leadership or executive role as of 2026; the user's prior information was incorrect. | High | SO006, SO007 |
| CO012 | Ontic completed a $4.65M seed round in January 2019 from Silverton Partners, Floodgate, and Village Global. | Medium | SO012, SO013, SO014 |
| CO013 | Ontic raised a $14M Series A in April 2020 led by Felicis Ventures with participation from Silverton Partners and Floodgate. | Medium | SO012, SO013 |
| CO014 | Ontic closed a $40M Series B in November 2021 as confirmed in the Series C press release. | High | SO001, SO002, SO003 |
| CO015 | Ontic raised $230 million in Series C funding led by KKR on August 21, 2025, with participation from JMI Equity, Silverton Partners, Ridge Ventures, and Ten Eleven Ventures. | High | SO001, SO002, SO003, SO004 |
| CO016 | KKR funded the Series C investment through its Next Generation Technology III Fund, having invested approximately $24 billion in technology-focused growth companies since 2016. | High | SO001, SO002 |
| CO017 | Ontic has raised approximately $287 million in total funding across four institutional rounds (seed, Series A, B, and C). | Medium | SO012, SO013, SO014 |
| CO018 | The Series C valuation was not publicly disclosed per Reuters/Business Insurance reporting. | Medium | SO003 |
| CO019 | GetLatka reports Ontic's 2025 ARR at $35.6M with 26 customers, last updated December 22, 2025. | Medium | SO009 |
| CO020 | Ontic's employee headcount was in the range of 309-324 as of late 2025, with approximately 9-10% growth rate during 2025. | Medium | SO012, SO022 |
| CO021 | Ontic services Fortune 50 companies across technology, financial services, and consumer goods sectors. | High | SO001, SO002 |
| CO022 | Third-party sources report conflicting revenue figures for Ontic: GetLatka says $35.6M ARR, CompWorth estimates $42.4M, and Growjo estimates up to $46.5M annual revenue. | Low | SO009, SO010, SO011 |
| CO023 | Ontic clients collectively generate nearly $30 billion in revenue and employ over 14 million people. | High | SO001, SO002 |
| CO024 | Ontic clients report reducing staffing needs by 33%, cutting investigation time in half, centralizing incident response across 400+ locations, and savings exceeding $4.5M over three years. | Medium | SO001, SO002 |
| CO025 | Banjo Inc. was founded in 2010 by Damien Patton as a real-time surveillance AI platform that analyzed publicly available social media data. | Medium | SO008, SO003, SO027 |
| CO026 | In 2020, Banjo founder Damien Patton's past involvement with white supremacist groups in the 1990s was publicly reported, leading to contract losses with the state of Utah and his resignation as CEO. | Medium | SO008, SO003, SO027 |
| CO027 | Banjo initially rebranded to safeXai in 2020 before completing a further rebrand to Ontic Technologies in 2021 under new leadership. | Medium | SO008 |
| CO028 | Corporate security spending rose following the fatal shooting of a UnitedHealth Group executive in late 2024, increasing demand for platforms like Ontic. | Medium | SO003 |
| CO029 | Ontic achieved FedRAMP Moderate Authorization in April 2026, receiving an Authority to Operate for mission-critical security operations. | High | SO015, SO021 |
| CO030 | The Ontic Platform is already proven in high-stakes enterprise environments including Fortune 100 companies per the FedRAMP announcement. | Medium | SO015 |
| CO031 | Ontic was named the Growth and Innovation Leader in the 2026 Frost Radar for Risk Intelligence Solutions for the third consecutive year, besting 14 other companies. | High | SO016, SO024 |
| CO032 | Frost & Sullivan recognized Ontic as the 2026 Best Practices Company of the Year in the Global Risk Intelligence Solutions Industry for the fourth time. | High | SO016, SO024 |
| CO033 | Ontic introduced Ontic Dispatch in 2026, extending Connected Intelligence into physical security response and coordination. | Medium | SO016 |
| CO034 | Existing investors JMI Equity, Felicis Ventures, Silverton Partners and Ridge Ventures continued their participation in the Series C. | High | SO001, SO002 |
| CO035 | Kastner Gravelle LLP served as legal advisor to Ontic and Latham & Watkins LLP served as legal advisor to KKR in the Series C transaction. | High | SO001, SO002 |
| CO036 | Ontic is described as a private company; no public filings indicate imminent IPO plans as of June 2026. | Medium | SO001, SO012 |
| CM001 | The risk intelligence solutions market encompasses platforms that operationalize data across physical security, cybersecurity, IT, and internal business functions into unified threat detection and response. | High | SM001, SM010 |
| CM002 | Adjacent markets to risk intelligence include cyber threat intelligence, mass notification, and physical security-as-a-service, which compete for overlapping budget dollars. | Medium | SM006, SM007 |
| CM003 | Ontic's core addressable market excludes pure-play cybersecurity (endpoint, SIEM), physical hardware (cameras, access control), manned guarding, and general business intelligence. | Medium | SM001, SM007, SM010 |
| CM004 | Frost & Sullivan reports spending on risk intelligence platforms at $58.84 billion in 2025, projected to reach $170.14 billion by 2030 with a 19.4% CAGR. | High | SM001, SM017 |
| CM005 | The narrower cyber threat intelligence segment is sized at approximately $13.4-16.8 billion in 2025 with 14-18% CAGR through 2035. | Medium | SM002, SM003, SM004 |
| CM006 | The global physical security market overall is approximately $129-131 billion in 2026, growing at 4-5% CAGR, including hardware and services. | High | SM007, SM008, SM009 |
| CM007 | Multiple market research firms provide significantly different sizing estimates due to varying definitions of market boundaries and included spend categories. | High | SM001, SM002, SM004, SM007 |
| CM008 | The serviceable addressable market for corporate security software platforms targeting Fortune 1000 enterprises is estimated at $3-8 billion globally. | Low | SM001, SM007, SM017 |
| CM009 | The primary buyer for risk intelligence platforms is the CSO or VP of Corporate Security who owns the physical security and protective intelligence budget. | Medium | SM010, SM017, SM012 |
| CM010 | End users of risk intelligence platforms are security analysts, investigators, and GSOC operators who interact with the platform daily for monitoring and response. | Medium | SM010, SM015, SM022 |
| CM011 | Budget ownership for corporate security platforms typically sits under the CSO function, separate from the CISO's cybersecurity budget. | Medium | SM010, SM012 |
| CM012 | Key adoption triggers include executive threat incidents, board mandates for protective intelligence, regulatory requirements, and desire to consolidate point solutions. | Medium | SM016, SM017, SM010 |
| CM013 | Corporate security spending rose following the fatal shooting of a UnitedHealth Group executive in late 2024, increasing corporate board awareness of executive security threats. | High | SM016, SM017 |
| CM014 | Organizations are increasingly prioritizing physical security solutions and working to unify fragmented security operations, reinforcing demand for unified platforms. | Medium | SM017, SM021 |
| CM015 | AI and automation adoption enables resource-constrained security teams to process more data with fewer analysts, filtering noise and surfacing actionable intelligence. | Medium | SM010, SM015, SM013 |
| CM016 | Enterprise sales cycles for risk intelligence platforms are typically 6-12 months due to procurement complexity and compliance requirements. | Medium | SM010, SM017 |
| CM017 | FedRAMP authorization creates a significant market access barrier for non-compliant vendors, effectively limiting government market participation. | Medium | SM020, SM024 |
| CM018 | Privacy regulations including GDPR, CCPA, and the EU AI Act create compliance complexity for surveillance and monitoring platforms operating across borders. | High | SM018, SM019 |
| CM019 | Budget competition from cybersecurity tools and switching costs from incumbent legacy systems constrain growth for newer risk intelligence platforms. | Medium | SM010, SM012 |
| CM020 | North America and Europe lead in risk intelligence spending, but Asia-Pacific is the fastest-growing market driven by urbanization and critical infrastructure upgrades. | Medium | SM007, SM009 |
| CM021 | GSOCs are evolving from reactive surveillance centers into fusion centers handling intelligence, risk, supply chain, and incident response coordination. | Medium | SM010, SM015, SM014 |
| CM022 | Service revenue is rising faster than hardware as organizations outsource monitoring and response to managed security providers. | Medium | SM008, SM014 |
| CM023 | The convergence of physical security, cybersecurity, IT, and compliance functions is creating demand for open, interoperable platform architectures. | Medium | SM012, SM013, SM010 |
| CM024 | Protective intelligence is shifting from traditional bodyguarding to proactive, data-driven, intelligence-led risk management with real-time analytics. | Medium | SM010, SM014 |
| CM025 | Organizations increasingly demand measurable ROI, strategic transparency, and defensibility in security programs rather than just threat mitigation. | Medium | SM010, SM017 |
| CM026 | Ontic's 2026 Security Forecast Report identifies trustable AI with human oversight, connected intelligence ecosystems, and security-as-performance-driver as key industry shifts. | Medium | SM010, SM011 |
| CM027 | The Frost Radar 2026 report evaluated 15 companies in the risk intelligence industry, positioning Ontic as overall leader in growth and innovation. | Medium | SM001 |
| CM028 | Major verticals leading risk intelligence demand include BFSI, IT & Telecom, Government & Defense, and consumer goods enterprises. | Medium | SM002, SM006, SM017 |
| CM029 | Legacy security systems with high switching costs represent a significant constraint on new platform adoption in established enterprises. | Medium | SM010, SM012 |
| CM030 | Cloud-native and hybrid systems show the fastest growth among deployment models for security intelligence platforms. | Medium | SM006, SM013 |
| CM031 | Status-quo substitutes for dedicated risk intelligence platforms include manual spreadsheet-based tracking, email-based intelligence sharing, and fragmented point solutions. | Medium | SM010, SM017 |
| CM032 | The Frost & Sullivan $58.84B figure includes broader risk management software categories beyond Ontic's direct competitive arena. | Medium | SM001, SM007 |
| CM033 | Ontic's current ARR of ~$35.6M represents less than 0.1% of the total risk intelligence TAM, indicating early-stage market penetration. | Medium | SM001, SM017 |
| CM034 | Zero trust security architecture adoption is driving integration requirements between physical security platforms and IT/cyber infrastructure. | Medium | SM013, SM014 |
| CM035 | Investment in cross-functional training, governance, and user experience is becoming central to security platform adoption decisions. | Medium | SM010, SM012 |
| CP001 | Ontic positions itself as a connected-intelligence platform for corporate and government security teams rather than as a standalone alerting product. | High | SP001, SP002 |
| CP002 | Frost Radar 2026 places Ontic in the broader risk-intelligence vendor field alongside Dataminr, Everbridge, Kroll, and other adjacent competitors. | High | SP005, SP006 |
| CP003 | Buyer alternative directories indicate that Ontic is compared against a broad substitute set rather than a narrowly bounded protective-intelligence niche. | Medium | SP007, SP008, SP028 |
| CP004 | The most direct buyer overlap occurs when enterprises want one platform for protective intelligence, investigations, and internal-external data correlation. | Medium | SP001, SP002, SP012 |
| CP005 | Ontic competes less directly when the purchase decision is dominated by mass-notification depth or operational-resilience breadth. | Medium | SP015, SP016, SP018 |
| CP006 | Ontic also competes less directly when buyers want highly verticalized incident-reporting workflows over cross-functional connected intelligence. | Medium | SP020, SP021, SP022 |
| CP007 | The competitive field includes direct peers, communications incumbents, and workflow substitutes, which keeps category boundaries loose. | Medium | SP006, SP007, SP027 |
| CP008 | Loose category boundaries increase the importance of deployment fit and workflow proof over category labels alone. | Medium | SP007, SP008, SP027 |
| CP009 | Dataminr positions itself around AI-powered real-time event, threat, and risk intelligence for corporate-security users. | High | SP009, SP010 |
| CP010 | Dataminr’s strength is external-signal discovery and alert speed rather than internal case-management depth. | Medium | SP009, SP010, SP011 |
| CP011 | Resolver positions around the value of risk intelligence and incident-oriented workflow rather than around broad mass communications. | Medium | SP012, SP013 |
| CP012 | Everbridge markets enterprise resilience and critical-event management with a broader communications-and-orchestration footprint than Ontic. | Medium | SP014, SP015, SP016 |
| CP013 | AlertMedia positions around unified risk intelligence and response with strong communications and executive-protection messaging. | Medium | SP017, SP018, SP019 |
| CP014 | Omnigo positions around incident reporting and safety software with especially visible fit in operational verticals such as healthcare. | Medium | SP020, SP021, SP022 |
| CP015 | Ontic’s clearest differentiation is its explicit system-of-record story for protective-intelligence cases and connected investigations. | Medium | SP001, SP002, SP012 |
| CP016 | Dataminr and Everbridge each enter evaluations with stronger brand recognition in their core domains than Ontic. | Medium | SP006, SP024, SP025 |
| CP017 | AlertMedia and Omnigo can appeal to buyers that prioritize simpler response workflows or vertical incident reporting over a broader connected-intelligence model. | Medium | SP018, SP021, SP022 |
| CP018 | Reviewed official pages across Ontic, Dataminr, Resolver, and Omnigo do not publish list pricing and instead direct buyers toward demo-led sales conversations. | Medium | SP001, SP010, SP012, SP020, SP021 |
| CP019 | Everbridge explicitly states that it offers custom pricing dependent on the number of people, locations, and geographies covered. | Medium | SP015 |
| CP020 | AlertMedia explicitly states that it uses custom pricing based on audience size and geographic area. | Medium | SP018 |
| CP021 | Because pricing is negotiated and modules are separable, buyers can multi-home Ontic alongside Dataminr or Everbridge instead of running a strict replacement process. | Medium | SP010, SP015, SP018 |
| CP022 | Switching costs become meaningful after deployment because these platforms connect to incident, communication, travel, HR, and investigation workflows. | Medium | SP002, SP015, SP018, SP021 |
| CP023 | The coexistence of alerting, communications, and investigations tools limits winner-take-all dynamics in this category. | Medium | SP006, SP015, SP018 |
| CP024 | Opaque pricing shifts the sales burden toward ROI proof, trust, and deployment speed rather than headline price competition. | Medium | SP018, SP019, SP027 |
| CP025 | Distribution leverage from larger adjacent suites is a material competitive risk to Ontic even if Ontic wins workflow-specific product comparisons. | Medium | SP015, SP016, SP025 |
| CP026 | Ontic’s most defensible wedge is cross-functional workflow depth spanning protective intelligence, investigations, and internal governance rather than raw signal breadth. | Medium | SP001, SP002, SP006 |
| CP027 | That wedge can become sticky once a customer embeds cases, playbooks, evidence, and approvals into Ontic’s workflow. | Medium | SP002, SP012, SP021 |
| CP028 | Trust-sensitive procurement in 2026 increases the value of workflow accountability and public-sector readiness in this category. | Medium | SP005, SP011, SP013 |
| CP029 | Dataminr is better capitalized than Ontic according to third-party funding trackers, reinforcing its ability to invest in signal breadth and distribution. | Medium | SP023, SP024, SP029 |
| CP030 | Everbridge entered 2026 as a Thoma Bravo-owned platform, supporting the view that it competes from a larger and broader enterprise-resilience base than Ontic. | Medium | SP014, SP025, SP030 |
| CP031 | Private Equity Wire reported that Vista Equity explored a sale of AlertMedia at more than $1 billion, implying meaningful scale for a communications-oriented rival. | Low | SP017, SP031 |
| CP032 | The presence of Gartner, G2, Capterra, and Software Advice alternative pages is adverse evidence that Ontic can be readily short-listed against many substitutes. | Medium | SP007, SP008, SP027, SP028 |
| CP033 | If Ontic fails to show measurable ROI or expansion proof, broader suites can frame the purchase around procurement familiarity instead of workflow depth. | Medium | SP015, SP016, SP027 |
| CP034 | Public sources reviewed do not reveal durable win-rate or market-share data that would prove Ontic is consistently taking share from direct rivals in 2026. | Low | |
| CP035 | Public sources reviewed do not reveal stable competitor-by-competitor retention or expansion metrics sufficient to quantify moat durability precisely. | Low | |
| CI001 | Ontic publicly presents itself as an enterprise software platform for corporate and government security teams. | High | SI001, SI002 |
| CI002 | The company’s product positioning supports a subscription-like enterprise software revenue model rather than a transactional product sale. | Medium | SI001, SI002 |
| CI003 | Ontic does not publish self-serve list pricing on the official pages reviewed for this chapter. | Medium | SI001, SI002 |
| CI004 | Ontic’s customer-marketing materials emphasize measurable ROI and executive trust building rather than low-touch product-led adoption. | Medium | SI005, SI022 |
| CI005 | Ontic says Ally saved up to eight hours per site risk assessment using its workflow. | Medium | SI006 |
| CI006 | Ontic says Visa centralized threat research and integrated tools such as social listening and dark web monitoring on the platform. | Medium | SI007 |
| CI007 | Ontic says a Fortune 500 travel technology customer used the platform to save time and maximize investigative efficiency. | Medium | SI008 |
| CI008 | GetLatka estimates Ontic reached $35.6M revenue or ARR in 2025. | Medium | SI013 |
| CI009 | GetLatka estimates Ontic had 26 customers and 324 employees in 2025. | Medium | SI013 |
| CI010 | GetLatka estimates Ontic’s average contract value at approximately $1.4M. | Medium | SI013 |
| CI011 | Growjo estimates Ontic at about $42.4M revenue, 272 employees, and $56.7M total funding. | Low | SI014 |
| CI012 | The conflict between GetLatka and Growjo means even basic public revenue and headcount figures are not yet reconciled. | Medium | SI013, SI014 |
| CI013 | If GetLatka is directionally right, Ontic is operating a high-ACV, low-logo enterprise model rather than a high-volume SMB motion. | Medium | SI013 |
| CI014 | Using GetLatka’s estimates, Ontic generates roughly $1.37M of ARR per customer, which is consistent with large enterprise deals. | Medium | SI013 |
| CI015 | Using public tracker data, Ontic’s revenue per employee falls in a wide band of roughly $110k to $156k. | Medium | SI013, SI014 |
| CI016 | The wide public revenue-per-employee band makes Ontic’s GTM and operating efficiency impossible to benchmark confidently from open sources alone. | Medium | SI013, SI014 |
| CI017 | Official 2025 announcements confirm Ontic raised $230M in a Series C led by KKR. | High | SI009, SI010, SI011 |
| CI018 | Official and third-party 2025 reports support total capital raised of roughly $287M after the Series C. | High | SI009, SI010, SI012 |
| CI019 | Ontic and KKR described the Series C proceeds as funding AI, product innovation, and continued global expansion. | High | SI009, SI010 |
| CI020 | The official funding story and the tracker-based historical funding story do not reconcile cleanly in public data. | Medium | SI009, SI013, SI014, SI015 |
| CI021 | Third-party trackers present materially lower historical funding totals than the official post-Series-C disclosure. | Medium | SI013, SI014, SI015 |
| CI022 | The best public evidence indicates Ontic has meaningful near-term financing flexibility because the Series C is large relative to visible ARR. | Medium | SI009, SI010, SI013 |
| CI023 | Using the official total-raised figure and GetLatka’s ARR estimate implies a cumulative funding-to-ARR ratio of about 8.1x. | Medium | SI009, SI010, SI013 |
| CI024 | A funding-to-ARR ratio around 8x suggests Ontic remains capital intensive relative to the recurring revenue visible in public sources. | Medium | SI009, SI010, SI013 |
| CI025 | Public sources reviewed do not disclose Ontic’s cash balance. | Low | |
| CI026 | Public sources reviewed do not disclose Ontic’s monthly burn or quarterly cash burn trend. | Low | |
| CI027 | Public sources reviewed do not disclose Ontic’s runway in months. | Low | |
| CI028 | Public sources reviewed do not disclose CAC, payback period, or pipeline conversion metrics for Ontic. | Medium | SI001, SI002, SI013 |
| CI029 | Public sources reviewed do not disclose software gross margin, services gross margin, or cost-to-serve detail for Ontic. | Medium | SI001, SI002, SI013 |
| CI030 | Public sources reviewed do not disclose net revenue retention, gross retention, or logo churn for Ontic. | Medium | SI001, SI002, SI013 |
| CI031 | Customer ROI stories are directionally positive evidence of willingness to pay, but they do not substitute for retention and margin disclosure. | Medium | SI005, SI006, SI007, SI008 |
| CI032 | The presence of Gartner and G2 review pages indicates customer validation exists, but public review surfaces do not provide enough detail here to resolve economics questions. | Low | SI020, SI021 |
| CI033 | Ontic’s careers page signals continued hiring and therefore continued operating-expense investment rather than a harvest mode. | Medium | SI003 |
| CI034 | Federal and public-sector expansion should be assumed to carry compliance and onboarding cost even though Ontic does not publicly quantify that burden. | Medium | SI001, SI009, SI010 |
| CI035 | Premier Alternatives contributes to the valuation-opacity problem rather than solving it, because private-company mark data remain thin and low-confidence. | Low | SI017 |
| CI036 | The right financial verdict from public evidence is cautious optimism: real enterprise traction is visible, but revenue quality and capital efficiency remain blocked by missing private metrics. | Medium | SI008, SI009, SI013, SI014, SI017 |
| CE001 | Ontic publicly defines its product as AI-powered Connected Intelligence software for corporate and government security teams. | High | SE001, SE002 |
| CE002 | Ontic’s product thesis is to unify intelligence, incidents, investigations, and response inside a single system of record. | Medium | SE002, SE004, SE013 |
| CE003 | The publicly visible module set includes incidents and case management, integrated research, executive protection, and Dispatch. | Medium | SE004, SE005, SE006, SE013 |
| CE004 | Ontic’s incidents and case-management workflow is explicitly connected to risk intelligence and integrated research. | Medium | SE004 |
| CE005 | Ontic’s integrated-research capability supports global intelligence checks, watchlist searches, and OSINT-powered research. | Medium | SE005 |
| CE006 | Ontic markets executive protection around connecting noisy digital and physical signals before threats escalate. | Medium | SE006 |
| CE007 | Dispatch was launched in March 2026 as a response-management and coordination solution for enterprise security teams. | High | SE013, SE016 |
| CE008 | Dispatch brings response activity directly into the same platform where teams manage incidents, investigations, and intelligence. | Medium | SE013 |
| CE009 | Dispatch adds operational coordination to Ontic’s product footprint, not just post-incident documentation. | Medium | SE013 |
| CE010 | Ontic’s integrations page frames interoperability as central to product value rather than as a peripheral ecosystem feature. | Medium | SE003 |
| CE011 | Public architecture signals point to a centralized platform organized around entities, cases, research, and external data ingestion. | Medium | SE003, SE004, SE005, SE014 |
| CE012 | The platform’s workflow value depends heavily on external data sources, security systems, and partner integrations. | Medium | SE003, SE005 |
| CE013 | Ontic’s public materials do not expose a detailed infrastructure diagram, tenancy design, or data-retention architecture. | Medium | SE001, SE002, SE003 |
| CE014 | Ontic publicly describes AI-driven workflows, including automated summarization, entity resolution, and workflow automation. | High | SE014, SE015 |
| CE015 | Because Ontic uses AI in mission-critical security workflows, governance and explainability are material diligence topics. | Medium | SE014, SE015 |
| CE016 | The investigations press release and webinar indicate Ontic has been expanding how always-on research integrates with case management. | Medium | SE009, SE010 |
| CE017 | Ontic’s 2026 forecast materials reinforce the company’s emphasis on proactive, AI-enabled, connected security operations. | Medium | SE011, SE012 |
| CE018 | The deepest public technical gap is not whether Ontic has integrations, but how burdensome they are to maintain at scale. | Medium | SE003, SE013 |
| CE019 | Ontic announced in April 2026 that it had achieved FedRAMP Moderate Authorization. | High | SE014, SE016 |
| CE020 | FedRAMP Marketplace independently lists Ontic for Government, corroborating public-sector authorization status. | High | SE014, SE015 |
| CE021 | Ontic also disclosed that it had received an Authority to Operate for mission-critical security operations use. | High | SE014, SE015 |
| CE022 | FedRAMP and ATO materially strengthen Ontic’s trust posture for government and highly regulated buyers. | Medium | SE014, SE015, SE016 |
| CE023 | Public FedRAMP materials describe Ontic as integrating public data, security systems, social media, and dark-web intelligence. | Medium | SE014 |
| CE024 | FedRAMP does not by itself answer uptime, latency, or model-error questions for Ontic’s platform. | Medium | SE014, SE015 |
| CE025 | The combination of compliance language, AI workflows, and a system-of-record narrative is a stronger trust signal than generic product marketing alone. | Medium | SE001, SE014, SE015 |
| CE026 | Publicly visible 2025-2026 roadmap milestones include the integrated-investigations push, Dispatch launch, and FedRAMP Moderate authorization. | Medium | SE009, SE013, SE014 |
| CE027 | Ontic appears to be a real multi-module platform rather than a monitoring-only tool because it spans research, case work, assessments, and response. | Medium | SE004, SE005, SE006, SE013, SE021 |
| CE028 | Customer stories show the product is used in real investigative and assessment workflows, not only marketed conceptually. | Medium | SE020, SE021, SE022, SE023 |
| CE029 | Ontic’s technical moat is execution-dependent because integration breadth, AI workflow, and real-time response all increase architectural burden. | Medium | SE003, SE013, SE014, SE015 |
| CE030 | Public materials do not provide objective SLA, uptime, or disaster-recovery metrics for the platform. | Low | |
| CE031 | Public materials do not provide enough evidence to evaluate model provenance, override controls, or false-positive rates in Ontic’s AI workflows. | Low | |
| CE032 | Moving from siloed legacy tools into a unified platform likely creates training and change-management burden for customers. | Medium | SE013, SE021, SE023 |
| CE033 | Ontic’s careers and jobs pages indicate continued investment in product and engineering capacity. | Medium | SE007, SE008 |
| CE034 | Review surfaces such as GetApp, G2, and Gartner provide some independent product-proof signal, though they do not resolve deep technical diligence questions here. | Low | SE017, SE018, SE019 |
| CE035 | Overall, the product and technology evidence supports a positive but conditional verdict: strong platform coherence and compliance progress, with unresolved diligence on architecture detail and AI governance. | Medium | SE001, SE013, SE014, SE015 |
| CU001 | Ontic’s public customer materials target corporate and government security teams rather than a broad SMB user base. | High | SU001, SU021 |
| CU002 | Ontic’s client pages and case-story archive show visible traction across enterprise-heavy verticals including financial services, technology, and insurance. | Medium | SU001, SU002, SU023 |
| CU003 | GetLatka estimates that Ontic had 26 customers in 2025. | Medium | SU016 |
| CU004 | A public customer base of roughly 26 logos would imply a concentrated enterprise-customer model. | Medium | SU016 |
| CU005 | FedRAMP-related materials expand the visible customer opportunity set to public-sector and government security teams. | High | SU018, SU019, SU020 |
| CU006 | Ontic’s public customer evidence is centered on large, security-mature organizations rather than small-team self-serve users. | Medium | SU001, SU003, SU004, SU007 |
| CU007 | The client-story surface suggests use cases spanning assessments, investigations, research, and executive-protection adjacent workflows. | Medium | SU002, SU023, SU024 |
| CU008 | Ontic’s current customer proof appears enterprise-first and use-case-diverse, but not yet quantified by revenue band or geography. | Medium | SU001, SU002, SU016 |
| CU009 | Visa publicly says it centralized threat research and integrated investigative tooling with Ontic. | Medium | SU003 |
| CU010 | Ally publicly says Ontic saved up to eight hours per site risk assessment. | Medium | SU004 |
| CU011 | A Fortune 500 travel technology customer publicly describes better investigations and higher efficiency with Ontic. | Medium | SU005 |
| CU012 | A Fortune 500 insurance customer publicly reports cutting manual work by 85% with Ontic. | Medium | SU006 |
| CU013 | Honeywell-oriented customer proof emphasizes demonstrating value, ROI, and executive trust through Ontic. | Medium | SU007 |
| CU014 | A Fortune 500 software company publicly describes turning disjointed research into a more powerful investigations program with Ontic. | Medium | SU008 |
| CU015 | Another enterprise-software customer story says Ontic helped scale a small security team. | Medium | SU010 |
| CU016 | CaseStories.com also attributes faster threat investigations to an Ontic deployment at a Fortune 100 CPG company. | Low | SU012 |
| CU017 | These public stories look more like production deployments than lightweight pilots because they reference concrete workflows and outcomes. | Medium | SU003, SU004, SU005, SU006, SU008 |
| CU018 | FeaturedCustomers maintains an Ontic page advertising 69 customer reviews and references. | Medium | SU011 |
| CU019 | Public review surfaces for Ontic also exist on G2, Gartner Peer Insights, and GetApp. | Medium | SU013, SU014, SU015 |
| CU020 | Public review presence is a positive validation signal but not a substitute for retention and renewal disclosure. | Medium | SU011, SU013, SU014, SU015 |
| CU021 | No public source reviewed for this chapter provides NRR, GRR, or logo churn metrics for Ontic. | Medium | SU011, SU013, SU014, SU015, SU016 |
| CU022 | No public source reviewed for this chapter provides contract-length or renewal-cohort detail for Ontic. | Medium | SU011, SU013, SU014, SU015, SU016 |
| CU023 | Because retention math is undisclosed, public customer evidence is stronger on adoption proof than on durability proof. | Medium | SU003, SU004, SU011, SU016 |
| CU024 | The 26-customer estimate implies that top-account concentration could matter materially to revenue durability. | Medium | SU016 |
| CU025 | Public sources do not disclose Ontic’s top-customer concentration, so concentration risk remains unquantified. | Low | |
| CU026 | Ontic’s multi-module surface creates a plausible land-and-expand path inside large customer accounts. | Medium | SU024, SU025, SU018 |
| CU027 | FedRAMP Moderate and the FedRAMP marketplace listing increase Ontic’s ability to pursue government security accounts. | High | SU018, SU019, SU020 |
| CU028 | Public customer proof suggests customer diversity across finance, travel technology, insurance, software, and government-adjacent security use cases. | Medium | SU003, SU004, SU005, SU006, SU018 |
| CU029 | Enterprise procurement friction is still likely high because Ontic sells into complex security environments with multi-workflow deployment. | Medium | SU001, SU024, SU025 |
| CU030 | If Ontic’s customer base is concentrated, procurement delays and account-level budget changes can have outsized impact. | Medium | SU016, SU018 |
| CU031 | Public evidence does not quantify how many government or public-sector customers Ontic has today. | Low | |
| CU032 | Public evidence does not show material customer-loss events or churn events, but the absence of evidence is not proof of low churn. | Low | |
| CU033 | Customer stories are overwhelmingly company-authored, which creates obvious selection bias in the visible proof set. | Medium | SU002, SU003, SU004, SU006, SU008 |
| CU034 | The company has enough named and anonymized case evidence to support a positive adoption read, but not enough independent cohort data to underwrite world-class retention. | Medium | SU003, SU004, SU011, SU014, SU016 |
| CU035 | Overall, Ontic’s customer base looks referenceable and enterprise-relevant, with the main remaining questions concentrated in durability, concentration, and expansion quality. | Medium | SU001, SU003, SU004, SU011, SU016, SU018 |
| CR001 | The Banjo controversy remains a live diligence issue because it ties the broader lineage around Ontic to surveillance, procurement, and trust concerns. | Medium | SR013, SR015, SR019 |
| CR002 | Independent reporting and advocacy describe Banjo as a surveillance-focused system that drew significant privacy criticism. | Medium | SR013, SR018 |
| CR003 | The Utah audit record and related reporting say Banjo could not do what it claimed. | High | SR014, SR015, SR017 |
| CR004 | Because trust is central to government and enterprise security buying, Banjo-era perception risk can still transmit into current Ontic diligence. | Medium | SR013, SR015, SR019 |
| CR005 | Ontic announced that it achieved FedRAMP Moderate Authorization in April 2026. | High | SR007, SR008 |
| CR006 | Ontic also disclosed an Authority to Operate for mission-critical security operations use. | High | SR007, SR008 |
| CR007 | FedRAMP creates a continuing compliance burden rather than a one-time certification event. | Medium | SR007, SR020, SR023 |
| CR008 | Broader 2026 compliance commentary indicates security software vendors face rising pressure around privacy, governance, and documentation. | Medium | SR021, SR022, SR023, SR024 |
| CR009 | For Ontic, a compliance lapse could hurt both cost structure and trust in the public-sector thesis. | Medium | SR007, SR008, SR024 |
| CR010 | Privacy and surveillance narratives are especially sensitive for Ontic because its platform aggregates multiple kinds of risk and identity data. | Medium | SR001, SR013, SR018 |
| CR011 | Procurement-representation risk matters in this category because AI and security claims can be difficult for buyers to independently verify before deployment. | Medium | SR014, SR017, SR023 |
| CR012 | Ontic’s integrated platform increases operational complexity because product value depends on many data sources and workflows working together. | Medium | SR001, SR002, SR010 |
| CR013 | External data quality, stale signals, or broken integrations can directly degrade the platform’s usefulness for investigations and response. | Medium | SR001, SR002, SR010 |
| CR014 | Dispatch raises the operational stakes because response-workflow failures during live incidents are more visible than back-office documentation delays. | Medium | SR010 |
| CR015 | Ontic’s AI-driven workflows create false-positive, false-negative, and explainability risks that are not quantified publicly. | Medium | SR001, SR007, SR022 |
| CR016 | Public sources do not disclose uptime, outage history, or SLA performance for the Ontic platform. | Low | |
| CR017 | Public sources do not disclose model-governance metrics, override controls, or false-positive rates for Ontic’s AI workflows. | Low | |
| CR018 | Because Ontic increasingly supports mission-critical workflows, operational incidents would likely translate into both trust and economic damage. | Medium | SR007, SR010, SR024 |
| CR019 | The platform’s data and permissions model likely carries identity-resolution and access-control risk that public materials do not detail deeply. | Medium | SR001, SR002 |
| CR020 | Customer adoption workarounds or weak training could undermine the platform’s intended connected-workflow value even without a formal outage. | Medium | SR005, SR026, SR027 |
| CR021 | Operational risk is elevated because Ontic is trying to sit inside intelligence, case management, and response, not just one narrow task. | Medium | SR001, SR010 |
| CR022 | Ontic depends on external data providers and public-data access for parts of its connected-intelligence workflow. | Medium | SR001, SR002 |
| CR023 | Ontic also depends on enterprise integrations to make customer workflows feel unified rather than fragmented. | Medium | SR001, SR002, SR010 |
| CR024 | GetLatka’s estimate of 26 customers implies concentration risk if even a few large logos dominate revenue. | Medium | SR011 |
| CR025 | Public sources do not quantify top-customer ARR concentration directly. | Low | |
| CR026 | CEO Lukas Quanstrom and the current leadership bench are central to strategy, trust repair, and commercial execution. | Medium | SR004 |
| CR027 | Ongoing hiring on Ontic’s careers and jobs pages signals continued dependence on attracting and retaining talent to scale the platform. | Medium | SR005, SR025 |
| CR028 | Implementation and customer-success capacity are material execution risks for a complex enterprise security platform. | Medium | SR005, SR026, SR028 |
| CR029 | Public-sector sales and compliance execution need specialized talent beyond generic enterprise software capabilities. | Medium | SR007, SR020, SR025 |
| CR030 | Culture and ethics risk remain relevant because Banjo-era baggage makes inconsistency between marketing and governance especially costly. | Medium | SR013, SR019 |
| CR031 | Customer and leadership dependencies can compound: if growth slows or a key leader departs, referenceability and trust can weaken together. | Medium | SR004, SR011, SR025 |
| CR032 | Ontic’s financial-model risk is amplified by missing public data on retention, concentration, burn, and public-sector conversion. | Medium | SR007, SR011, SR012 |
| CR033 | A modest number of large accounts could make revenue sensitive to procurement delays or renewal slippage. | Medium | SR006, SR011 |
| CR034 | Better-capitalized competitors increase risk that Ontic must keep spending to maintain trust, product breadth, and shortlist relevance. | Medium | SR012, SR029 |
| CR035 | Compliance burden can transmit into higher operating cost and slower roadmap velocity, not just into legal risk. | Medium | SR007, SR021, SR024 |
| CR036 | A major FedRAMP control issue or authorization problem would be a thesis-break event for the public-sector expansion story. | Medium | SR007, SR008 |
| CR037 | A major reference-account loss or stalled expansion in top accounts would materially weaken Ontic’s durability thesis. | Medium | SR006, SR011, SR028 |
| CR038 | Unexpected turnover in top leadership or core product/compliance roles would raise execution risk sharply. | Medium | SR004, SR005, SR025 |
| CR039 | If privacy or surveillance narratives materially reattach to the brand, trust-sensitive sales motions could deteriorate quickly. | Medium | SR013, SR018, SR019 |
| CR040 | Overall, Ontic’s risk profile is manageable only if it continues proving disciplined compliance, reliable operations, and diversification beyond a small set of large relationships. | Medium | SR007, SR011, SR025, SR029 |
| CV001 | Official sources confirm Ontic raised $230M in a KKR-led Series C in August 2025. | High | SV001, SV002 |
| CV002 | Official and third-party 2025 coverage support total funding of roughly $287M after the Series C. | High | SV001, SV002, SV027 |
| CV003 | GetLatka estimates Ontic reached $35.6M ARR or revenue in 2025. | Medium | SV003 |
| CV004 | Growjo estimates Ontic at roughly $42.4M revenue and 272 employees. | Low | SV004 |
| CV005 | The visible public revenue range for Ontic is therefore roughly $35.6M to $42.4M. | Medium | SV003, SV004 |
| CV006 | Ontic did not publicly disclose the post-money valuation of the Series C. | Medium | SV001, SV002 |
| CV007 | Private-market references such as Dealroom and Premier Alternatives indicate valuation visibility exists externally but is not methodologically transparent. | Low | SV005, SV006 |
| CV008 | If Ontic were valued around $1B, that would imply roughly 23.6x to 28.1x on the visible public ARR range. | Medium | SV003, SV004, SV006 |
| CV009 | Such an implied multiple would be far above broad 2026 public SaaS medians. | Medium | SV008, SV010, SV014 |
| CV010 | The KKR filing confirms the sponsor is a large public alternative asset manager, reinforcing that the round likely involved institutional-style underwriting rather than retail exuberance. | Medium | SV001, SV009 |
| CV011 | Public SaaS benchmark sources show 2026 public software multiples sitting in the low single digits on average or median, far below 2021 highs. | Medium | SV010, SV011, SV014, SV015 |
| CV012 | PublicSaaSCompanies reports a 2.62x median and 4.77x average revenue multiple across its June 2026 public SaaS sample. | Medium | SV010 |
| CV013 | WeAreFounders summarizes January 2026 public SaaS benchmarks at roughly 4.0x median and 6.6x average EV/ARR, with higher premiums for AI and vertical SaaS. | Low | SV014 |
| CV014 | Multiples.vc says June 2026 software valuations are segmented by AI application, technical complexity, market position, and specialization depth. | Medium | SV012 |
| CV015 | Benchmark sources consistently argue that stronger security, infrastructure, and vertical-workflow businesses can trade at a premium to generic SaaS. | Medium | SV012, SV013, SV014, SV028 |
| CV016 | Those same benchmark sources also argue that premium multiples now require efficient growth, strong retention, and real Rule-of-40 quality. | Medium | SV011, SV012, SV014, SV028 |
| CV017 | Everbridge’s take-private valued the company at approximately $1.8B in an all-cash transaction. | Medium | SV017 |
| CV018 | Private Equity Wire reported Vista Equity exploring a >$1B sale of AlertMedia, creating another adjacent private-category value marker. | Low | SV016 |
| CV019 | Clay and Tracxn indicate Dataminr has raised materially more capital than Ontic, underscoring how much scale investors can support in top-tier risk-intelligence leaders. | Low | SV018, SV019 |
| CV020 | Ontic’s FedRAMP progress, Frost Radar recognition, and named enterprise customers are the main public arguments for awarding it a premium over generic SaaS. | Medium | SV020, SV021, SV022, SV023, SV029, SV030 |
| CV021 | GetLatka’s public timeline shows Ontic’s ARR proxy falling from $42.3M in 2024 to $35.6M in 2025. | Medium | SV003 |
| CV022 | If the visible ARR range is roughly right, then a bear-case valuation on 4x-5x public-style multiples is only about $140M-$210M. | Medium | SV003, SV004, SV010, SV014 |
| CV023 | If the visible ARR range is roughly right, then a base-case valuation on 6x-8x premium multiples is about $240M-$360M. | Medium | SV003, SV004, SV013, SV014 |
| CV024 | A $1B+ valuation looks supportable only if private ARR is materially above public proxies or if forward growth and retention are exceptional. | Medium | SV003, SV004, SV014, SV020 |
| CV025 | One way to justify a unicorn-like mark would be hidden ARR closer to roughly $80M-$100M at 10x-12x quality multiples. | Medium | SV003, SV014, SV015 |
| CV026 | FedRAMP and government-option value can improve upside, but they do not offset weak current revenue quality by themselves. | Medium | SV021, SV022, SV024 |
| CV027 | Customer proof and referenceability matter because valuation premiums increasingly depend on workflow depth and retention, not just category buzz. | Medium | SV023, SV024, SV025, SV026, SV029 |
| CV028 | No public source reviewed for this chapter discloses verified NRR, GRR, or churn for Ontic. | Medium | SV003, SV023, SV024, SV025, SV026 |
| CV029 | No public source reviewed for this chapter discloses enough margin data to compute a reliable Rule of 40 for Ontic. | Medium | SV003, SV004, SV011, SV014 |
| CV030 | No public source reviewed for this chapter discloses top-customer concentration, which weakens conviction in the premium case. | Medium | SV003, SV023, SV029 |
| CV031 | On public evidence alone, the correct valuation recommendation is research-more rather than buy. | Medium | SV003, SV010, SV014, SV020 |
| CV032 | The current valuation stance should be considered stretched rather than fair on public evidence alone. | Medium | SV008, SV010, SV014 |
| CV033 | The most important thesis-break question is whether private metrics are much stronger than the visible public proxies. | Medium | SV003, SV006, SV014 |
| CV034 | If ARR quality, retention, or concentration come in weaker than hoped, Ontic should be rerated toward the base or bear valuation bands. | Medium | SV003, SV014, SV028 |
| CV035 | If public-sector conversion stalls despite FedRAMP, a meaningful part of the bull-case option value should be removed. | Medium | SV021, SV022 |
| CV036 | If gross margin or services mix prove worse than premium-SaaS norms, Ontic’s multiple should compress materially. | Medium | SV011, SV014, SV028 |
| CV037 | The anti-thesis is that Ontic may simply be a strong product with too much future success already priced into the latest round. | Medium | SV003, SV004, SV006, SV014 |
| CV038 | The bull thesis is that Ontic is building a security workflow system of record with enough AI, government, and customer depth to grow into its price rapidly. | Medium | SV020, SV021, SV022, SV029, SV030 |
| CV039 | No public source reviewed for this chapter discloses actual Series C preference terms or liquidation stack. | Low | |
| CV040 | Overall, Ontic remains interesting strategically, but the valuation case depends on private metrics that have not yet been substantiated publicly. | Medium | SV001, SV003, SV010, SV014, SV020 |