Plurilock Security Inc. (TSXV:PLUR)
Canada flag Canada · Delayed Price · Currency is CAD
0.1350
+0.0050 (3.85%)
Sep 18, 2026, 3:22 PM EST
← View all transcripts

Investor update

Aug 20, 2026

Summary

Major contract wins with NASA and NATO expand access to U.S., Canadian, and NATO government markets, supported by a growing services segment and strong industry partnerships. The platform's unique reach and high entry barriers position it for continued growth in both public and private sectors.

Ian L. Paterson
CEO, Plurilock Security

Good morning for those who just joined. We're just going to give it another 30 seconds, and then we will officially get started with the proceedings. All right. Good morning, and thank you for joining us. I know it is an early start for those on the West Coast, and I appreciate you being here. My name is Ian L. Paterson, and I am CEO of Plurilock Security. We're going to be covering a corporate update today on our growing defense platform, followed by a short question and answers session.

A few notes on logistics. All participants are in listen-only mode. You are more than welcome to submit a question at any time using the Q&A tab at the bottom of your screen, and I will take questions after the prepared remarks. A recording will be posted to the investor relations page on our website following today's presentation.

One piece of housekeeping before we start. This is a business update only. Our second quarter 2026 financial results are due later this month. We're not going to be covering any details of that today, and we're not going to be taking any questions on that. I'd refer you to communications later this month. Before we get to business, I'll just draw your attention to the disclaimer on the screen and remind everybody that certain statements made on this call may be forward-looking in nature.

Please take a moment to review and take a screenshot as needed. Okay. For anyone new to the story, we'll start with a quick orientation of us as a company, and then we'll get into the specifics around the growing defense platform. Plurilock Security is a cybersecurity solutions provider and systems integrator.

We were founded in 2016, and we trade on the TSX Venture Exchange under the ticker PLUR and on the OTCQB under the ticker PLCKF. Last year, we generated over CAD 60 million in revenue with increasing gross margins, driven by our growing Critical Services segment across our portfolio of customers, including both commercial and public sector.

We maintain strong partnerships with some of the most consequential technology and cybersecurity companies in the world, and are seeing strong tailwinds from the global trends of increasing defense spending, AI disruption, and cyber risk. Our strategy since we went public has been easy to state, and that is to acquire distribution and then cross-sell higher-margin products and services through it. Distribution in this context is the right or the ability to sell to customers who are, in some cases, hard to reach.

When we're talking about the public sector and government in particular, it usually takes a special form of master service agreement called a contract vehicle. You might have the best capability in the market, but without a way for that government customer to procure through you, there's no practical way for you to get that capability into the hands of that customer.

Ultimately, if you hold one of those contract vehicles, then you have a path to that customer, and in many cases, the competition is narrowed as compared to other customers who are out there. Over the years, we have announced sales to numerous U.S. federal agencies, state agencies, as well as Canadian agencies and government customers. These include organizations such as the U.S. Navy, Department of Energy, Department of Transportation, Federal Trade Commission. In California, this has included the California State Legislature.

In Canada, organizations like Health Canada, Treasury Board, Privy Council, DND, et cetera. Now we'll get on to why we are here this morning. Two things happened over the last couple of months that are worth touching on and explaining. The first is that on July 20th, we announced that our Aurora subsidiary, our U.S. operating subsidiary, had been notified of its selection as an awardee under NASA's SEWP VI contract.

On August 6th, we announced that our Canadian operating subsidiary, Integra, had been selected as a contract holder under the NATO Communications and Information Agency's Cyber Security Dynamic Marketplace Lot 1, also known as the CSDM contract. I'll call that agency the NCIA agency for the rest of the call. Both of these wins are contract vehicles. I want to cover a couple of things this morning.

First is a reminder of our ultimate strategy, how our contract vehicles fit into that strategy, and why we are now a platform for both United States, Canadian, and NATO reach, which is both hard to assemble and highly valuable, both to us as well as prospective other partners out there in the industry. First we'll cover SEWP, which is NASA's Solutions for Enterprise-Wide Procurement program.

The SEWP vehicle, S-E-W-P, is what's known as a government-wide acquisition contract, which means agencies across the U.S. federal government can buy through it, not just NASA. NASA happens to be the agency that is administrating that contract. However, the SEWP contract is a GWAC, a Government-Wide Acquisition Contract. Our U.S. operating subsidiary, Aurora, is one of a limited group of pre-qualified SEWP contractors. It gives us a direct sales path to both civilian, defense, and intelligence agencies.

Our current SEWP contract, or what's known as SEWP V, we have been operating for a number of years, which is set to conclude towards the end of this year in advance of SEWP VI, the new win, going into effect. The way that contract vehicles work and the way that SEWP in particular works is that as a pre-qualified vendor, as a holder of the SEWP contract, we are eligible to compete for individual orders, sometimes called task orders.

The way this works is an agency, so a government customer, will identify some requirements. They'll issue a request. Sometimes it's an RFI, request for information, or an RFQ, request for quote. They'll send that to the pre-qualified holders, who will then respond, and ultimately somebody will usually win that piece of business.

We have been operating this vehicle, as I said, for a number of years, and if you look back at some of our press releases over the last few years, you'll see references to the SEWP vehicle and orders such as the software order with the U.S. Department of Defense Agency back in March. This is what it looks like in terms of the vehicle actually turning into task orders that then turn into revenue. Again, we have successfully been operating the SEWP V contract.

We have been named a winner under the SEWP VI, which is the successor contract, and the details of that SEWP VI contract are as follows. SEWP VI, as posted on NASA's site, is a 10-year indefinite- delivery, indefinite- quantity vehicle, or what's known in the industry as an IDIQ. It has an aggregate program ceiling of $60 billion.

That number is the program ceiling for the program. It will be shared across a group of contract holders, which will include us as one of them, over that 10-year program. Effectively, what that means is that there is a significant amount of budget that has been allocated to the program, and it gives the contract holders the ability to compete for business in that program itself.

The specific value of orders are ultimately then, it is up to the individual task orders in terms of how much those task orders are worth. That is the SEWP V and SEWP VI contract. Again, we are very excited about being named as a SEWP VI winner. I will turn now to the NATO contract. This is a new contract, both for us as well as for NATO.

Unlike the SEWP program, which was a successor, SEWP VI succeeding SEWP V, the NATO contract is a brand-new vehicle. Our Canadian operating subsidiary, Integra, has been selected as one of the winners under this contract. For the CSDM contract, it is a five-year multi-award IDIQ framework covering eight functional categories across cybersecurity.

Similar to SEWP VI and SEWP V, this contract allows us to bid on individual task orders, which will get issued by the NCIA agency, and then order values and revenue are determined ultimately by those task orders. Here is why I think these are an underappreciated component of the company, and that is really how difficult and competitive it is to get these contracts. The way that we were successful in winning these contract vehicles is through working through a competitive process. These competitions for contract vehicles are competitive.

They are not always open. In our experience, a company that is not positioned to compete for when one of these competitions runs is very limited in its ability to get it. In many cases, they have to wait until the next cycle. That cycle might be years away. These contracts do not come around all the time, and you have to be there with the right proposal in order to win them.

Eligibility is a second barrier. In addition to the contract competitions being only open and closed for a certain period of time, you have to be eligible in order to win. In a lot of cases, these contract vehicles will ask for things like past performance, which means the company's prior experience working with a similar contract vehicle and having success in terms of delivering products and services to those customers.

You need both past performance and the window to be open in order to compete successfully. Third is that certification, just as a general statement, is usually a requirement, and that burden has been growing steadily. Our Aurora subsidiary achieved CMMC Level 1 for the U.S. Department of Defense back in 2024.

We also hold SOC 2 along with other pre-qualifications that in many cases are either required or can assist in showing that you are a strong bidder when you are going out and trying to approach these or compete, I should say, for these contracts. In Canada, there is also a new program called the CPCSC, which stands for the Canadian Program for Cyber Security Certification, which sets out mandatory controls for defense suppliers with enforcement beginning later this year. These are things that are difficult to get in some cases.

In the case of past performance, as an example, you have to have experience of having done similar work. It's difficult as a new entrant to be able to compete successfully and get access to these programs.

But like we've talked about, if you do have access to them, in the case of the CSDM contract, it's a five-year contract, and in the case of SEWP VI, it's a 10-year contract, which really provides a great competitive moat for us to be able to continue executing. The last piece there is just time and market. In our case, Integra, our operating subsidiary, has actually been in the Canadian public sector since 1985. And Aurora has a multi-decade work experience as well.

These were two companies that we had acquired in 2021 and 2022, and it gives us really more than three decades of delivery history, which has been very useful for us in winning these contract vehicles. If you put all this together, you have a reason that a company like us is able to punch above its weight. And it took us two acquisitions, more than a decade to get to where we are. And the barrier for these types of contract vehicles is high. That means that these contract vehicles are prized, and we actually hear regularly from other operating businesses who are interested in them.

Ultimately, if I think about what these things mean, if we add up all of these contract vehicles together, Plurilock is now a platform with the ability to reach U.S. federal civilian defense intelligence customers, Canadian federal customers, and now NATO customers. For a company of our size, having all three is quite unusual. I'll talk a little bit about the types of revenue, because with these contract vehicles, we can be selling multiple different types of things.

As a solutions provider and systems integrator, our revenue is composed of three segments: Hardware, Software, and Services, and I'll give you some examples of each one. Towards the end of June this year, we announced some data center sales to U.S. federal and state customers totaling CAD 1.1 million.

Inside that number were some high-performance server components for a U.S. DOD agency, and data center infrastructure and support service for a U.S. federal agency. We've also delivered network infrastructure for the Department of Energy. Earlier this spring in May, on the commercial side, we announced on-site engineering for a national consumer storage company around their data center modernization, and that is both people as well as hardware, and providing integration.

Effectively, what this shows is that we are able to deliver whole solutions, so not just one piece of hardware, not just one piece of software, not just one service, but we're really delivering multiple elements, which for our customers, they appreciate being able to go and do a one-stop shop, if you will.

This also speaks to the growth that we are seeing supporting some of the tailwinds, like data centers, which we are seeing certainly as a key component for some of the new AI boom that we are experiencing. We have talked about hardware. We also sell software and licensing. Some examples of that this year. Earlier, we had a state legislature data center where we supplied endpoint detection response software, data security application control.

As well for a DOD agency, we provided email solutions on a five-year agreement. In Canada, we did some work with Health Canada, as well as a Canadian law enforcement agency around virtualization, cloud platform licensing, and then for a state-level law enforcement agency, intrusion prevention, detection. In February, we also announced a data security licensing agreement inside a national security-focused government agency.

We have talked about hardware, and I have just given you some examples of software capabilities. Last and not least, and certainly this is where we have really been focusing our time is around services. We call our team Critical Services, although it shows up on our financial statements under the line item professional services. In May, we announced Critical Services contracts totaling CAD 1.3 million and CAD 1.1 million.

The work inside those contracts included engineering support for a customer's security operations center, enhancements to a data loss prevention program, some security change management, AI operations support, and security assessment work. Then, slightly earlier than that, in February, we renewed and expanded engagements covering insider risk, security information and event management operations, and some security comms programs. We also delivered some firewall security and automation for a Canadian company through one of our alliance partners.

As well, with our Critical Services team, we are running readiness programs for certification regimes similar to what I mentioned before, so CMMC in the U.S. and CPCSC in Canada. I will just take a moment to touch on both of those, because we are seeing with this large defense tailwind. More and more companies are looking for CMMC help in the U.S. and CPCSC help in Canada.

Both of these are areas that we work with customers on, and we are certainly looking for more to be working with. Maybe one last point, and it follows from what we have just talked about, which is that the assembling of this platform has taken time.

It has been hard to do, and it is valuable not only just to us, but also to other technology companies who might not have similar experience, past performance, credentials, or qualifications in order to win these contracts themselves. When we announced our SEWP V extension in June, we said that technology vendors, systems integrators, and partners that lack their own procurement vehicles can partner with us to reach U.S. federal clients.

That invitation is open, and it is one of the reasons that the vehicles matter beyond just the orders we win for ourselves, but also for partners. We can see a live example of partnership from last year, where we announced in July that Forcepoint named Plurilock a Certified Services Partner, which puts our Critical Services team in front of Forcepoint's own customers and implementation.

This is a great example of a partnership that can run in both directions. Not only us with our procurement vehicles, but also Plurilock being recognized as a key provider of capability, as I say, running in both directions. Why does this matter now more than it did before? The answer is that the set of companies that need a route into government keeps growing, and it's looking a lot less and less traditional.

Defense and security buyers are procuring categories of technology that barely existed as a procurement line item a decade ago, or even five years ago. Think about autonomous systems, artificial intelligence, quantum capabilities, robotics. Many of the companies building in those categories are young. They might have the tech, but they don't have the vehicle, they don't have the past performance, they don't have the certifications.

This is really where partners like Plurilock can provide a lot of value. Let me close with a summary, and then we will get into questions. Here is what we are working with against that backdrop. A 10-year U.S. federal purchasing vehicle where we have been notified of our selection as an awardee, a five-year NATO framework, an established Canadian federal position, and a services practice with growing margins.

On top of that, a platform other tech companies have reason to want access to. None of this is guarantees of orders, and none of this is a guarantee that we'll be able to win those orders and convert to revenue. However, we have a really good track record, and while the work is in front of us, it is work that we're excited to go after.

With that, I would encourage, if you have questions, to use the Q&A function. It should be at the bottom of your screen. I've got a couple questions that have already popped up, and happy to take them as they come in. The first question is, I'll read off the question first here. Considering your list of partners, is Plurilock categorized as an MSP, an MSSP, or a reseller?

That's a great question. The reality is that Plurilock is a solutions provider. In some cases, we might provide a piece of hardware or software, and so from that perspective, we would be reselling that technology. In other cases, we might be providing a one-off service through our Critical Services practice, and so from that perspective, you could think of us as a systems integrator.

It might be the case that we're providing a managed capability, and so that would be more of an MSSP. The answer is, it depends on the situation. Broadly speaking, we consider ourselves a systems integrator because that usually encompasses both resell, one-time services, and managed services. It kind of bridges all those different components. I think the other thing that I would note is that as a company, we have been growing our services practice as a percentage of revenue.

If you look at Critical Services revenue from last year and you compare that to where it was a couple of years prior, you'll note that the services revenue has really increased as a percentage of revenue. Short answer, solutions provider and systems integrator. It can encompass multiple items.

The next question is, what other industries are you seeing potential collaboration opportunities given the channels and infrastructure you have across Canada, the U.S., and NATO? This is a great question. We generally are a cybersecurity and cyber defense company. What that means, though, is that really every piece of technology has chips in it these days.

Our ability to create value for customers is actually quite broad. If I think about some newer emerging technologies that might not have existed five, 10 years ago, I think about things like quantum. I also think about the growth in autonomous vehicles. UAS, unmanned autonomous vehicles, has also been a big growth. Cyber itself really applies to every segment of IT. You do not really have to go very far to find a cyber use case within most technology products.

I would just summarize that to say emerging technology, quantum, AI drones as probably being the three that you might not immediately think about, but those certainly have a huge cyber application, particularly for where the world is today and where the world appears to be going. Follow-up question, are you doing any work in the private sector? Yeah, that is a great question. The presentation today has really focused on the public sector contract vehicles.

Depending on the year, the percentage of revenue from the public sector to the private has been around 50/50. It goes up and down a little bit depending on the year. We absolutely do a lot of work in the private sector. I would say that the three main verticals within the private sector include financial services, healthcare, and industrials. Within industrials, this includes things like semiconductors, aerospace, and defense.

Usually within the industrial segment, it is folks who have both IT technology as well as OT technology or what is called operational technology. Certainly we do a lot of work there. We tend to skew more towards larger organizations. Think Global 2000 type of organizations, enterprises, or organizations that have a disproportionate amount of risk from cybersecurity. Again, that is where we tend to focus.

If you were to look through our corporate presentation, within the first couple of slides, you will see some examples of the types of industries, types of customers, and then certainly, you can refer back to previous press releases where we have talked about, not specific names of clients, which is a lot of times difficult in the cybersecurity industry to name, but certainly, we talk about kind of the industry that those customers are operating in.

The next question here is, SEWP V runs out in September with options through to April of next year. Is there a gap between when SEWP V ends and when SEWP VI starts? Great question. The answer is we do not believe there is going to be any gap. The good news is that we are holders of both contracts, so our current SEWP V contract, as well as SEWP VI.

There have been a number of announcements in regards to SEWP V being extended. My belief is the government does not want there to be any gaps. Because we have both SEWP V, as well as SEWP VI, we believe that we are in a good spot, and it is ultimately up to NASA and the government to transition that program. I think we have time for maybe one or two more questions.

I will try and get to these. The question is, you are a small company. How do you deliver against a NATO framework? Great question. A couple of things that I would say. First is that, again, because of our past performance that I had listed, we are in a really good position to be able to bring experience to NATO. We have also spent a good amount of time both with our NATO reps in Canada.

I was also in Brussels, I think last year, at NATO headquarters. We feel that we are in a good position. I also think just from a macro perspective, Canada has really tried to raise its standing as increasing Canada's own investment in defense and ultimately its NATO 2% of GDP commitment. I think that both Canada is well-positioned.

I think that we are positioned well in Canada, and we have the benefit of being able to leverage a lot of the experience that we have done internationally, to be able to bring to bear. I think that we are in a good spot, and I think that there is great opportunity for us to pursue. I think that there is probably time for one more question.

If you have a question and you were not able to get it answered, happy to take questions via email as well. The last question here that I have is, do you have a partnership program with other consultants, I think is the question. The short answer is yes. Cybersecurity is a team sport. We do have a couple of different partnership programs.

We have talked a little bit about some of the vendors that we work with, so companies like CrowdStrike and Forcepoint. We also have alliance partners who are actually bringing our Critical Services team into their customers, and then we also work with other consultants as well. The short answer is yes. Details can be found further on the plurilock.com website, as well as through conversation with some of our business development folks.

Thank you very much for joining the session today. As I said, if we did not get to your question or if something comes up afterwards, please reach out through the investor relations page on our website, and we will be glad to answer those. Thank you for joining this morning, and thank you for following our story.

It took us multiple years, a couple of acquisitions, to build this platform to be able to reach government buyers across the United States, Canada, and now NATO. The barriers that made it slow for us to do are the same ones that make it hard for others to copy. We are just getting started here, and our job now is to convert that into dollars at the end of the day. Thank you for your time, and we will talk to you soon. Bye-bye.