
Black Kite
AI-native third-party cyber risk management platform for continuous vendor and supply chain risk intelligence.
By Black Kite · HQ Boston, US · 4.8/5 Value-Position score (estimate)
Positioning guardrails
Best for
- Security and third-party risk teams continuously monitoring hundreds to thousands of vendors
- Programs replacing spreadsheet questionnaires with AI-assisted assessments and evidence mapping
- Leaders who need cyber risk quantification and board-ready reporting on vendor exposure
- Supply chain teams that need nth-party and concentration-risk visibility beyond tier-one vendors
Ideal size: 100–5,000 employees people · Enterprise or scale-up with a formal third-party risk or GRC program
Not for
- Small businesses with a handful of vendors and no formal third-party risk program
- Buyers who want published self-serve pricing, free tiers or instant online signup
- Teams looking primarily for first-party endpoint detection and response tooling
Value metrics scorecard
Time-to-Value
~6 weeks (typical enterprise onboarding)
~45 days to first production value
Total Cost of Ownership
$60,000/yr
Starts at $25,000 · Quote-based annual subscription (SaaS); no public list pricing, demo required
Implementation Friction
3/5
Engineering + admin effort required
Value-Position score
out of 5 · model estimate
Full cost breakdown
Mandatory implementation fee
None
Seat tiers
Not published; enterprise quotes typically scoped to monitored vendor volume
Add-on costs
- Optional partner-delivered managed services (pricing not published)
Company & support
Who is behind Black Kite, and how your team gets help once it is live.
Company
- Founded
- 2016 · 10 yrs in business
- Headquarters
- Boston, US
How you get support
- PhoneNot listed
- EmailNot listed
- Live chatNot listed
- Support portal / ticketsNot listed
- Community forumNot listed
- Help centre / docsAll plans
- Dedicated account managerNot listed
- In person / on-siteNot listed
- Hours
- Not recorded
- Response time
- Not stated
Vendor reports 100% CSAT in customer support but does not publish support channels, hours or SLAs on the cited pages; the /docs resource centre is publicly available.
“Not listed” means the vendor’s public pages don’t mention that channel, not that it is unavailable. Ask about it during evaluation.
Market position
Where Black Kite sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.
Quadrant view
Typical annual cost × Time-to-value
The lines cross at the median of the solutions shown, so about half sit on each side of each line.
Companies on the chart 6 / 10
- Black Kite
- Sumsub
- Contrast Security
- Semgrep
- Ncontracts
- UpGuard
Add or change companies
Up to 10 companies including Black Kite. Listed closest first.
Stack fit signal
Compatibility with standard B2B ecosystems.
No supported MCP path today, so it cannot be driven from an AI client.
AI & MCP readiness
What Black Kite ships in AI, and what it asks of your ecosystem.
AI features shipped
AI is described as embedded across the platform: an in-context AI Assistant, a network of sub-agents for assessment, incident response, investigation and reporting, document parsing and control mapping, plus AI-driven detection and prioritisation of vendor risk signals.
Your data & models
- Trains on your data
- Not recorded — ask the vendor
- Runs on
- Not recorded
- AI pricing
- Not recorded
In your ecosystem
- AI connection
- Not supported
- Model key
- Not recorded
- AI usage audit
- Not recorded
Compliance attestations
* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.
Bottom line
Black Kite is an AI-native third-party cyber risk management platform. It continuously monitors vendors and nth parties, runs AI-assisted assessments that parse vendor documents and map controls, supports cyber event response, and quantifies risk in financial terms. It integrates with GRC, SIEM and workflow tools such as ServiceNow, Splunk and Slack, and ships an MCP server. Pricing is quote-based with no public list price; expect a multi-week enterprise onboarding.
Frequently asked questions
What does Black Kite actually do?
It is a third-party cyber risk management platform. Black Kite continuously monitors millions of organisations for adversary targeting, ransomware susceptibility and active cyber events, runs AI-assisted assessments that parse vendor documents and map controls to frameworks, supports breach and vulnerability response, and quantifies risk in financial terms.
How much does Black Kite cost?
Black Kite does not publish list pricing. Commercials are quote-based and typically scoped to the number of monitored vendors and modules (Monitor, Assess, Extend), so buyers should request a scoped quote and confirm which AI capabilities are included rather than assuming they are free.
How long until we see value?
Monitoring value starts as soon as your vendor portfolio is loaded, while assessment and workflow roll-out is a project. Enterprise buyers should plan on roughly six weeks to first production value, including onboarding of vendor lists and any GRC or SIEM integration work.
Does Black Kite use AI, and can we plug in our own agents?
Yes. The vendor states AI has been foundational since day one, with an embedded AI Assistant and a network of agents for assessments, incident response, investigation and reporting. Black Kite also provides its own MCP server so external AI assistants can securely access its data.
Which systems does Black Kite integrate with?
Its integration catalogue covers GRC and risk platforms (ServiceNow TPRM, Archer, OneTrust, LogicGate, Navex), SIEM and security tooling (Splunk, CrowdStrike, Securonix), workflow tools (Jira, Zapier, Tines, Slack, Microsoft Teams), plus Power BI and an open API.
Can Black Kite quantify cyber risk in financial terms?
Yes. Its cyber risk quantification module uses Open FAIR methodologies to put a dollar value on ransomware attacks, data breaches and business interruptions, which is what security leaders typically need for board and insurance conversations.