Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Claimed
Claimed

Top Rated Manifest Alternatives

Manifest Reviews & Product Details

Manifest Overview

What is Manifest?

Manifest helps organizations understand and reduce the cybersecurity risk in the technology they produce and procure. The Manifest platform operationalizes software bills of materials (SBOMs), artificial intelligence bills of materials (AIBOMs), and Vulnerability Exploitability eXchange (VEX) documents so organizations can analyze and action the risk in internal or third-party tools. Manifest manages the entire SBOM lifecycle for customers in critical industries like enterprise technology, aerospace, defense contracting, healthcare, manufacturing & logistics, financial services, and the federal government.

Manifest Details
Show LessShow More
Product Description

Manifest helps organizations understand and reduce the cybersecurity risk in the technology they produce and procure. The Manifest platform operationalizes software bills of materials (SBOMs), artificial intelligence bills of materials (AIBOMs), and Vulnerability Exploitability eXchange (VEX) documents so organizations can analyze and action the risk in internal or third-party tools. Manifest manages the entire SBOM lifecycle for customers in critical industries like enterprise technology, aerospace, defense contracting, healthcare, manufacturing & logistics, financial services, and the federal government.


Seller Details
HQ Location
Connecticut, USA
Twitter
@manifestcyber
79 Twitter followers
LinkedIn® Page
www.linkedin.com
14 employees on LinkedIn®

Mike M.
MM
Overview Provided by:

Recent Manifest Reviews

Nitish K.
NK
Nitish K.Small-Business (50 or fewer emp.)
5.0 out of 5
"Manifest saved us hours if not more work"
We work with large enterprises that require SBOMs as a part of compliance and governance reviews. Simply put, we'd have spent prohibitively high am...
Shaun M.
SM
Shaun M.Mid-Market (51-1000 emp.)
5.0 out of 5
"Cutting-Edge Tool Enables Complete Lifecycle Management of your Software Bill of Materials"
Manifest makes the generation of our SBOMs easy, secure and efficient. We get immediate and full lifecycle alerts on all of our software supply cha...
PZ
Peter Z.Mid-Market (51-1000 emp.)
5.0 out of 5
"Real “Continuous Compliance”"
Straightforward integration of GitHub Action into our CI pipeline allows us to continually monitor the risk we're incurring from third parties. On ...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

Manifest Media

Answer a few questions to help the Manifest community
Have you used Manifest before?
Yes

3 Manifest Reviews

5.0 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
3 Manifest Reviews
5.0 out of 5
3 Manifest Reviews
5.0 out of 5

Manifest Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons
G2 reviews are authentic and verified.
Shaun M.
SM
Director of Platform Engineering
Computer Software
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Manifest?

Manifest makes the generation of our SBOMs easy, secure and efficient. We get immediate and full lifecycle alerts on all of our software supply chain dependencies in real-time.

Their customer support is white-glove and they go above and beyond to make sure we are happy with the product. Manifest is so easy to implement that it's been great for us to take our time and integrate where needed.

Manifest is a precision-engineered app that we use everyday due to it's significance in securing our software supply chain. They provide a full API to all functionality within their application. Review collected by and hosted on G2.com.

What do you dislike about Manifest?

The more we use the product the more we want to integrate it into our other tools -- and that takes time. Review collected by and hosted on G2.com.

What problems is Manifest solving and how is that benefiting you?

Complete lifecycle management of our software bill of materials. Review collected by and hosted on G2.com.

PZ
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Manifest?

Straightforward integration of GitHub Action into our CI pipeline allows us to continually monitor the risk we're incurring from third parties. On several occasions during the vendor review process we have prevented the introduction of vulnerabilities into our tech stack by working with third parties to patch their software prior to deployment in our environment.

Incredible team and a mutually beneficial partnership. They're punching above their weight and it shows. Review collected by and hosted on G2.com.

What do you dislike about Manifest?

That more organizations haven't done the same rapid integration with Manifest already, creating an ecosystem of visibility beneficial to everyone producing products. Review collected by and hosted on G2.com.

What problems is Manifest solving and how is that benefiting you?

Quantifiable reduction of risk within the compliance space. Review collected by and hosted on G2.com.

Nitish K.
NK
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about Manifest?

We work with large enterprises that require SBOMs as a part of compliance and governance reviews. Simply put, we'd have spent prohibitively high amounts of time building SBOMs from scratch instead of using Manifest. The product is easy to use and integrate with. Review collected by and hosted on G2.com.

What do you dislike about Manifest?

I'd love to be able to share my SBOMs automatically via Manifest (almost like a "website embed") so it just shows up next to my other compliance certifications Review collected by and hosted on G2.com.

What problems is Manifest solving and how is that benefiting you?

Building SBOMs. Review collected by and hosted on G2.com.

There are not enough reviews of Manifest for G2 to provide buying insight. Below are some alternatives with more reviews:

1
Snyk Logo
Snyk
4.5
(122)
Snyk is a security solution designed to find and fix vulnerabilities in Node.js and Ruby apps.
2
Mend.io Logo
Mend.io
4.3
(112)
Integrated application security that identifies and automatically remediates vulnerabilities in open source and custom code.
3
JFrog Logo
JFrog
4.3
(92)
The JFrog Platform is an end-to-end, hybrid, and universal binary-centric solution that continuously manages and secures your entire software supply chain from source to edge. We empower developers to be more efficient using JFrog’s services, Artifactory, Xray, Distribution, Pipelines, and Connect on a single unified platform. The JFrog Platform is an enterprise-grade solution that handles the scale of the largest development organizations in the world. The JFrog family of products includes: JFrog Artifactory: -Provides definitive artifact management for flexible development and trusted delivery at any scale. The industry leader. JFrog Xray: -The industry’s only DevOps-Centric Security solution offers protection across your supply chain and is integrated seamlessly with Artifactory and the other JFrog products for a single point of management and security. JFrog Pipelines: -Integrates with the leading CI/CD tools to manage all software pipelines in a single place with additional event triggers and easy-to-use templates. JFrog Distribution and JFrog PDN: -Creates trusted software releases and gets them where they need to be, fast. Handles the highest scale of throughput and consumption. JFrog Connect: -A comprehensive solution for updating, managing and monitoring software applications on Linux-based edge and IoT devices. JFrog Mission Control & Insights: -Enhances control over your JFrog Platform deployment with access to key metrics.
4
CAST Highlight Logo
CAST Highlight
4.5
(80)
Rapid application portfolio analysis. Automated source code analysis of hundreds of applications in a week for Cloud Readiness, Open Source risks, Resiliency, Agility. Objective software insights combined with qualitative surveys for business context.
5
Aqua Security Logo
Aqua Security
4.2
(57)
Aqua Security stops cloud native attacks and is the only company with a $1M Cloud Native Protection Warranty to guarantee it. As the pioneer and largest pure-play cloud native security company, Aqua helps customers unlock innovation and build the future of their business. The Aqua Platform is the industry’s most integrated Cloud Native Application Protection Platform (CNAPP), prioritizing risk and automating prevention, detection and response across the lifecycle. Founded in 2015, Aqua is headquartered in Boston, MA and Ramat Gan, IL with Fortune 1000 customers in over 40 countries. For more information, visit https://www.aquasec.com/.
6
OX Security Logo
OX Security
4.8
(48)
OX Security helps teams focus on the 5% of issues that really matter, ensuring developers fix the most critical problems first. By consolidating all your security data into one clear view and seamlessly integrating into existing workflows, OX provides actionable insights to improve app security, reduce complexity, and resolve issues faster—all without slowing down development.
7
SOOS Logo
SOOS
4.6
(40)
SOOS is the affordable, easy-to-integrate Software Composition Analysis solution for your whole team. Scan your open source software for vulnerabilities, control the introduction of new dependencies, exclude unwanted license-types, generate SBOMs, and fill out your compliance worksheets with confidence–all for one low monthly price.
8
MergeBase Logo
MergeBase
4.5
(20)
rusted by security and development teams at top enterprises, MergeBase provides security and development teams with visibility to the real risk in their applications from vulnerable open source components at every stage of the software development lifecycle with CodeGreen, BuildGreen, and RunGreen. MergeBase accelerates triage by minimizing false positives and deemphasizing vulnerabilities in unused code. It automates remediation during development and can block attacks on vulnerable components in production.
9
Cybeats Logo
Cybeats
4.4
(15)
10
FOSSA Logo
FOSSA
4.2
(14)
FOSSA is a open source solution designed to provide developers with tools to analyze code automatically to help developers with open source license management.
Show More