Thank you for joining us, friends. Up next, we have Justin Leger with Cybeats Technologies.
Good afternoon, everyone. Thank you to Planet MicroCap for having us here today. Appreciate the invitation. Thank you all for joining me and taking an interest in Cybeats. My name is Justin Leger. I'm the CEO of Cybeats Technologies. Very grateful to have people like you helping small, innovative companies become large, innovative companies. Cybeats is a pretty exciting story that I've been a part of now for several years, and I'm very excited to share it with you. Cybeats is a SaaS cybersecurity company with a leading cybersecurity solution that addresses the Software Supply Chain, which may not be a concept that you're very familiar with. We're going to talk about some new terms that you probably haven't heard before, specifically Software Bill of Materials or SBOM for short. That's okay.
You're going to learn about that and why it's so important, why regulators have taken such an interest in protecting the Software Supply Chain, and we're going to get into how Cybeats is enabling enterprises all over the world to protect the things that matter most. Again, Cybeats is a software company that addresses this Software Supply Chain Security gap that exists today using software bills of material or SBOMs. SBOMs are simply an ingredients list for software.
Much like a Hardware Bill of Materials, it lists all of the components and libraries, it looks at the licenses tied to all of that developers use every day to build the software that you use, that Critical Infrastructure providers use, that medical device manufacturers use, that all developers use to really speed up the development process. 70%-90% of code that is in software is from open source.
This is an incredible thing that saves a lot of time and money, but it also means that you're importing all of the vulnerabilities that are within them. Sometimes those are just errors, bugs, or other flaws. More and more, they're deliberate. Malicious code is being placed into open- source components, and hackers are exploiting the use of these to get access to important information and to disrupt Critical Infrastructure.
Cybeats uses Software Bills of Materials to help enterprises, companies that keep the power going, that keep the water flowing, that protect the medical devices that you and your family use. We help these companies identify these vulnerabilities very quickly as they come up with our continuous monitoring and help them to address them very quickly. Very importantly, we're also helping these large enterprises to meet regulatory requirements that are new and growing, and we'll get more into that.
Our product is called SBOM Studio, as this slide shows, we're able to make organizations compliant with regulation and do so in a way that reduces cost for those companies. Not only are we able to help them meet these regulatory requirements that have fines attached, the European Union Cyber Resilience Act has fines up to EUR 15 million or percentage of top-line revenue coming into effect very soon. We're also able to help them save a lot of time and money in the process of identifying, analyzing, and remediating critical software vulnerabilities. In some client cases, these have been tested in the real world. They've been able to save up to 76% or hundreds of hours of developer effort per project. You can imagine in that particular account, we saw very significant growth, which I'll show you here in a moment.
We're able to use our software to take something that is highly manual and painful and expensive and automate that and make it much more efficient and importantly, much more effective and in line with regulatory requirements. This is a very brief snapshot of the regulatory situation that's been developing over the last few years. The United States has taken a lead on this, our team at Cybeats has been part of the conversation from day one, helping to define what the space looks like and how SBOMs are going to be deployed globally.
Starting back in 2021, Executive Order 14028, essentially, among other things, said that if you want to do business with the U.S. federal government, you need to be prepared to use SBOMs, to submit them to the department that is making the purchase, we've seen that roll out over time. There's been more and more requirement. October 2023, the FDA required for any new market submissions for medical devices for sale in the United States that an SBOM be part of that. Not only did you need to provide it at that point in time, you need to monitor that in perpetuity for any known exploitable vulnerabilities for that and new versions of the software.
This is where Cybeats is really helpful in helping to automate that process and make it far, far more manageable. When you think about some of our customers that have tens of thousands of SKUs, many of those have software and multiple versions of software. The problem scales at a very, very high level. You can't manage that with people. This is where we really save the day.
We were recounting an interesting story earlier today where one of our earlier customers came to us and they said, "Hey, I think your software is broken. We put our SBOM into your solution. We found 4,000 vulnerabilities. That's not possible. We know what we're doing." We had to say, "Sorry, that's the real number." We helped them navigate that. They're not all exploitable. They're not all accessible to hackers today.
This is really the value that we provide in helping make it more accessible and much more streamlined. These are the ones that you need to pay attention to right now. In fact, this is the fix, we pushed that right into their development pipeline for them. They were over the moon, but it was a little bit of a shock there to learn that they had over 4,000 vulnerabilities in their software.
Move forward to today. We've got the European Cyber Resilience Act passed into law. That, again, it's a big overarching piece of legislation, but there is a piece in there that addresses Software Supply Chain and how SBOMs are going to help companies become compliant with helping to protect that Software Supply Chain. As I said, there are fines associated with that. We're helping companies now ahead of enforcement, which we're going to see starting this fall. They have to, within 24 hours, disclose to regulators when they find an exploitable vulnerability within their software. We're helping to automate that. Fast-forward to December 2027. They have to, not just for sale with government in the EU, but to sell anything that has software in the European Union, you're going to have to use SBOMs.
Just wanted to put up a little bit of a highlight here and some of the feedback that we've had on our software. These referrals come alongside significant institutional validation. Cybeats was recently included in the latest Gartner Report, and our technology has now been featured in 11 Hype Cycle reports. This, for our investors, its widespread inclusion, I think is quite significant. It underscores the importance of Software Supply Chain Security, that it's no longer a nice-to-have, but a requirement. Of course, that Cybeats is leading the way with our solution. Beyond this, we've also been recognized as a representative vendor for something new, an AI Bill of Materials, which our CTO and co-founder helped create, the AI BOM, if you will. These are a core system of record for the AI Supply Chain. Okay?
What model does your AI solution use? What are the biases inherent in that? What are the vulnerabilities that we know related to that? This is going to becoming much more important. I do get asked about AI a lot, and in fact, is very much a tailwind for our company because at the end of the day what our solution does and these regulations are intended to do is to shine a light on the Software Supply Chain.
Not allow people to stick their heads in the sand and just wait for hackers to exploit something, but to actively look for those vulnerabilities and address them as they're discovered. As AI is used to do more coding, that decreases the transparency on what's there, making that ingredients list so much more important. Our business model is very simple. I charge by the SBOM. We generally enter into multi-year contracts with the customers that are using our product, and they typically grow every year. There's two main ways that this happens. One is that there's a natural progression as you update your software, fix bugs, add new features. That's a new version, and it's a new SBOM.
You still want to monitor the old one because it's still out there in production somewhere, particularly important for those medical devices. We add more and more SBOMs every year. More than that, what we've seen is because this is a new area of cybersecurity, we're not displacing something. We're something brand new, and they don't fully know how they're going to operationalize it. This is where our team really shines because our team, I would say, is the best in the world right now at operationalizing SBOMs at large enterprises.
Nobody has more experience than us. We've done it many times now, and we're quite good at it, and we help them to find all of those savings that I had mentioned before. They go from in year one or the first six months of an agreement being with one product team, and then over time, we expand within the enterprise, adding more and more product teams to our solution. Our software is fully scalable. You could add the biggest customer I've ever had tomorrow, and I wouldn't change anything. We're fully in the cloud, very low touch. Where I add people is in helping our customers get the most out of the software whenever we add something new to conduct that initial training and to onboard the client.
We really work hard to make sure that they get the most out of it, the underlying infrastructure, infinitely scalable, or rather as scalable as Amazon, nigh infinite. We've been successful in certain key verticals. As I mentioned, Industrial Control Systems, Medical Devices. We've got water, wastewater management. We've got some Telecom, and recently we added Automotive. They follow this very same theme of really fitting under that Critical Infrastructure umbrella. We're going to see more and more of that as the regulatory pressure increases and the demands from their vendors, or rather from their clients, increase as well.
One of our clients reached out to me to let me know, and I don't have a regular touch point with this person, but he wanted me to know so I could share it in forums like this, that they had their sales team reach out and say, "Hey, we need this SBOM thing to share, or we're not going to be able to close this deal. They're demanding our SBOM." The product security team previously would've really labored to make that happen, to pull it all together through their bespoke solution with all the different bits of software. They were able to turn it around same day and heroically help the sales team to close this multimillion-dollar deal. It's moving very much beyond just the government pulling from industry.
It's also industry demanding from industry that they take on these cybersecurity practices, and they're being self-enforced, if you will. The process for us to onboard a new client, because we're dealing with large enterprises, can take a little while, anywhere from 6 to 18 months. However, I'm seeing that speed increase. I'm seeing the urgency greatly increase ahead of the regulatory enforcement coming down in 2027.
I had a customer approach us in December, that global auto parts manufacturer, and we had them onboarded in February. It was a record for us from first contact to deployment at that scale. In particular, we thought that was quite impressive. We typically don't spend a ton of time convincing them that we've got the solution for them, although we do occasionally have to go through a formal procurement process competing against other solutions out there. We win.
The feedback that we get on why we win comes down to the quality of our solution and how we've positioned it to address the specific needs of large enterprises. We'll get more into some of those differentiators here in a minute. All of this has also generated interest from other partners. Late last year, we announced our OEM partnership with Keysight Technologies, a $60 billion company that works in this space. They had some technology that really works nicely with our solution. We worked with them to white label our solution into Keysight SBOM Studio, which you can read all about on the web. They've more recently taken that. They've gotten their Keysight global marketing behind it.
They've got their sales team. You can imagine the sales team of a $60 billion company is a lot more than what Cybeats can cobble together right now. We're on our way. That channel partner is really opening things up for that, for us rather. We're starting to see that reflect in the pipeline. Just last week, in fact, Keysight SBOM Studio won an award in Tokyo at a conference, prestigious Best of Show Award for security product. Of course, SBOM Studio is Cybeats SBOM Studio. We're very excited about that partnership and where that will take us. We're in the process of onboarding other channel partners as well, to help us really scale our go-to-market capability. Just a quick snapshot of the pipeline and some of the opportunities that we have. It's started to change.
We're seeing much more interest from other verticals, from the ones that we've been successful in. I'm seeing a lot more institutional interest in our solution. The governments that are demanding these SBOMs, what are they doing with them? How are they getting value out of them? This is a question that we're starting to address and have conversations with a few different government entities.
We're very excited to see where that goes. We've been successful with the large enterprises, and we think we'll be successful with the institutional customers as well. We're still targeting a $5 million annual recurring revenue at the end of this quarter, which I realize is in less than two weeks. We're targeting profitability by the end of the year. Just to take a look at some numbers. We're a SaaS business, high gross margin, 80%+.
Our average contract value is over $0.25 million . We saw significant growth last year, 49%, and projecting that $5 million ARR by the end of Q2. Also wanted to point out our 111% net retention ratio because we keep our customers, and we grow those accounts as well. Here's just a quick snapshot of some actual year-over-year customer account growth. You can see this one account, it's a good reference account that went from, I think it was about $84,000 to $534,000 now. The team has collectively over 100 years of cybersecurity experience. We've got a fantastic group of leaders in the space that are experts and respected people in the field. They've literally wrote the book on Software Supply Chain Security. Our advisory team has been incredible at helping us navigate both the government and the commercial side.
They sit at that intersection of government and industry, which has been incredibly helpful for us. To highlight a few of our competition that we've seen when we've gone head-to-head for business. Cybellum, Finite State, Manifest. These guys are doing great work. They're not directly competing with us. As I mentioned, we've positioned our product in a very unique way to address those enterprise customers and to really go after that recurring revenue. We don't generate SBOMs at Cybeats at all. We made a solution that's agnostic to where those SBOMs come from, whether they're generated by any of these guys, we work well with it. In some cases, you could even input a spreadsheet and we can work with that. This is very important in this space because we didn't want to start to challenge the organization.
That's a huge barrier to get through, is the organizational change of getting different development teams all over the world doing things in slightly different ways to onboard a new solution that they didn't ask for. No. We wanted something that would empower the product security folks at companies, the CISOs at companies, to collect this information, these SBOMs, no matter where they came from or what format they're in, and provide great results.
All I wanted to show here is there's no one big player in the space today. Obviously, I think Cybeats is leading the way in terms of our market validation from folks like Gartner, from the types of customers that we've been able to capture, and the important industries that we've been able to capture. There isn't one big leader here yet. Quickly looking at our capital structure.
Our market cap today is between $35 million and $40 million. We've got approximately 216 million shares outstanding, 37% insider ownership. The float is not as large as you might think. You can see the warrants we have here have limited time left. That about wraps it up. To sum up, Cybeats is well-positioned in this growing Software Supply Chain Security area of cyber. Regulators are driving adoption. We have a solution that is ready to scale to meet that demand. We've got very proven strength of technology, not only with the customers, but also evidenced by the net retention ratio that we have.
We've got a pipeline that could very significantly increase our ARR in the short term based on both our organic internal sales and our channel partners, which are on a scale that we can't even touch. Because of that, we're very excited. I'll wrap it up there. We have a very little amount of time here for any questions. Very happy to take any questions.
Can you talk about the pipeline a bit more clearly?
Talking about the Keysight pipeline. I don't work for Keysight, and I don't think they'd want me to talk in detail about their sales pipeline, but I can say that we're working with them on some of these opportunities, and they are very much in line with some of the other opportunities that we've been able to capture, and perhaps even bigger. It's looking very positive. Because of that effort they've put in over the last little bit, it's really starting to come alive. We're very excited about that.
Can you talk about how that partnership works to serve revenues?
Yeah. Just the sort of structure of that relationship. Yeah. We've never disclosed that publicly, but I can tell you that it is very favorable, I think, for both parties and really does a good job of protecting that margin for us. Jeff, you had one.
Yeah. Third question related to–
Yeah.
My understanding is they only onboard maybe a handful of external like yours into their platform every couple of years, I think. $50 billion, $60 billion corporations. What kind of expectations would they have for such a large enterprise to a small company like yours only get a handful every few years? I know you can only say so much. Can you give us kind of an idea of what their expectations are for new solutions like yours?
Yeah. What are Keysight's expectations on revenue? Look, your guess is as good as mine just looking at the company, but just doing some back of the napkin math, they're not doing anything for $1 million here or $1 million there. They're operating, for each product, in the tens of millions annually. I would expect that's their expectation. They haven't shared that information with me, but that's my guess. As far as new solutions that they're onboarding, I don't know the exact details, but I do know that our team was one of two that were recently trained to their sales force. That only happens every couple of years, and obviously, we're really excited to be there teaching them how to use Keysight SBOM Studio, and more importantly, how to sell it. I got one minute left. Sir.
What about the security clearance that they have? Anything lacking FedRAMP?
Question about security clearances and things like FedRAMP. Where Cybeats is today, we don't have FedRAMP today. This is something that we have kept a close eye on because we do see a future where we may need it. The barrier of entry to getting FedRAMP has come down significantly. There are programs and vendors out there that they can make it much cheaper, much faster than in the past. I've worked on government contracts previously. I know that's been an issue. We don't have that problem. We do have some government clients today, and we're not FedRAMP certified. We do meet standard industry cybersecurity, things like SOC 2 Type 2, that put us at a high level.
Every company that we've onboarded with has done a full risk assessment on us, from the company to the financials to the cyber piece, and nobody's turned us down yet. We're meeting enterprise-level expectations. We've been able to work with government partners through third parties to get our solution in their hands, and whatever we need to do, we'll get there. We're familiar with the processes and are happy to navigate them as needed. Looks like we're at time here. Thank you so much for your attention and hope to speak with you soon.