← Back to TENB filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Except for the risk factors disclosed below, there have been no material changes to the risk factors disclosed in Part I, Item 1A. "Risk Factors" of our Form 10-K for the year ended December 31, 2025 filed with the United States Securities and Exchange Commission ("SEC") on February 27, 2026. Our business is subject to risks and events that, if they occur, could adversely affect our financial condition and results of operations and trading price of our securities. In addition to the other information set forth in this Form 10-Q, you should carefully consider the factors described in Part I, Item 1A. “Risk Factors” of our Form 10-K for the year ended December 31, 2025. We may disclose additional changes to risk factors or disclose additional factors from time to time in our future filings with the SEC. Additional risks and uncertainties not presently known to us or that we currently deem immaterial also may impair our business operations.
Our brand, reputation and ability to attract, retain and serve our customers are dependent in part upon the reliability and accuracy of our data, solutions, infrastructure and those of third parties upon which we rely. If our information technology systems or data, or those of third parties upon which we rely, are or were compromised or disrupted, or if our solutions fail to detect vulnerabilities or incorrectly detect vulnerabilities, or if they contain undetected errors or defects, we could experience adverse consequences.
In the ordinary course of our business, we collect, store, use, transmit, disclose or otherwise process proprietary, confidential, and sensitive information, including personal data, intellectual property, and trade secrets.
We sell cybersecurity products and, as a result, may be at increased risk of being a target of cyberattacks designed to penetrate our platform or internal systems, to compromise our data, alter or modify our source code, or to otherwise impede the performance of our products. Threats to information systems and data come from a variety of sources. In addition to computer “hackers,” threat actors, personnel (such as through theft or misuse, or other insider threat listed below), "hacktivists," organized criminal threat actors, sophisticated nation-states and nation-state-supported actors now engage and are expected to continue to engage in cyber-attacks. Nation-state actors and nation-state-supported actors may engage in such attacks for geopolitical reasons and in conjunction with military conflicts and defense activities, around the world. During times of war and other major conflicts, we, third parties upon which we may rely, and our customers may be vulnerable to a heightened risk of these threats, including retaliatory cyber-attacks that could materially disrupt our systems and operations, supply chain, and ability to produce, sell and distribute our goods and services. We, our customers, and the third parties upon which we rely are subject to a variety of evolving threats, which are prevalent, continue to rise, and are increasingly difficult to detect. These threats include but are not limited to: social-engineering attacks (including through deep fakes, which may be increasingly more difficult to identify as fake, and phishing attacks); credential harvesting; malicious code (such as viruses, worms, and, increasingly, code injection in open source software); malware (including as a result of advanced persistent threat intrusions); denial-of-service attacks, credential stuffing; insider threats (including due to personnel misconduct, error or malicious activity); ransomware attacks; supply-chain attacks; software bugs; server malfunctions; software or hardware failures; loss of data or other information technology assets; adware; telecommunications failures; attacks enhanced or facilitated by artificial intelligence and other similar threats. Advances in artificial intelligence, including models capable of rapidly identifying and exploiting software vulnerabilities, may further increase the speed and effectiveness of cyberattacks. As a result, vulnerabilities or flaws in our products, systems or those of third parties upon which we rely may be discovered more quickly, reducing the time
31
Table of Contents
available for detection and remediation and increasing the likelihood or severity of security incidents. Ransomware attacks, including those from organized criminal threat actors, nation-states and nation-state supported actors, are becoming increasingly prevalent and severe and can lead to significant interruptions, delays, or outages in our operations, loss of data, loss of income, significant extra expenses to restore data or systems, reputational loss and the diversion of funds. To alleviate the financial, operational and reputational impact of a ransomware attack, it may be prudent to make extortion payments, but we may be unable to do so if, for example, applicable laws prohibit such payments.
Additionally, we are incorporated into the supply chain of a large number of companies worldwide and, as a result, if our solutions are compromised, a significant number or, in some instances, all of our customers and their data could be simultaneously affected. The potential liability and associated consequences we could suffer as a result of such a large-scale event could be catastrophic and result in irreparable harm.
Remote work and use of remote devices has increased risks to our information technology systems and data, as more of our personnel utilize network connections, computers and devices outside of our premises or network, including working at home, while in transit and in public locations. Future or past business transactions, such as acquisitions or integrations, could expose us to additional cybersecurity risks and vulnerabilities, as our systems could be negatively affected by vulnerabilities present in acquired or integrated entities' systems and technologies. Furthermore, we may discover security issues that were not identified during due diligence of such acquired or integrated entities, and it may be difficult to integrate other companies into our information technology environment and security program.
We rely on third-party service providers and technologies to operate critical business systems, including processing confidential and sensitive information, including, without limitation, cloud-based infrastructure, data center facilities, encryption and authentication technology, employee email and other functions. We also rely on third-party service providers to provide other products, services, or otherwise, to operate our business and elements of our infrastructure, including endpoints. Our ability to monitor these third parties' information security practices is limited, and these third parties may not have adequate information security measures in place. Additionally, software errors or vulnerabilities in these third-party technologies could result in significant disruptions to our information technology systems, leading to downtime, data loss, or compromised data integrity. Our use of generative AI technologies may increase the risks associated with open source software and other third-party components, including where such technologies retrieve or recommend malicious or vulnerable code from public repositories or other third-party sources that may be used without appropriate review.
If our third-party service providers or partners experience a security incident or other interruption or cause an extended outage or disruption to our systems, we could experience adverse consequences. It is possible that our customers and potential customers would hold us accountable for any security incident affecting our third-party service providers’ or partners' infrastructure or other interruption caused by our third-party service providers or partners that impacts our infrastructure. We may incur significant liability from those customers and from other third parties with respect to any such incident. Because our agreements with certain third-party service providers, such as AWS and Snowflake, limit their liability for damages, we may not be able to recover a material portion of our liabilities to our customers and third parties arising from issues with such third-party service providers, such as AWS and Snowflake, in the event of an incident affecting the third parties’ systems. Moreover, while we may be entitled to damages from third-party service providers if they fail to satisfy their privacy or security-related obligations to us or if they cause a disruption in our infrastructure, any award may be insufficient to cover our damages, or we may be unable to recover such reward. In addition, supply-chain attacks have increased in frequency and severity and there have been high-profile incidents of third-party service providers causing widespread disruptions in their customers' infrastructures due to errors in their SaaS offerings. We cannot guarantee that third parties’ infrastructure in our supply chain or our third-party partners’ supply chains have not been compromised or that errors by our third-party service providers won’t cause disruptions in our infrastructure.
We have experienced, and may in the future experience, disruptions, outages, other performance problems and security threats due to a variety of factors, including infrastructure changes, deliberate or unintentional human actions (including by third parties), software defects and configuration errors, capacity constraints, fraud or security incidents. We take steps designed to detect, mitigate and remediate vulnerabilities and defects and configuration errors in our information technology systems (such as our hardware and software, including that of third parties upon which we rely) and in our software applications, products and services. We may not, however, be able to detect and remediate all such vulnerabilities, defects or configuration errors on a timely basis. For example, we have identified certain vulnerabilities in
32
Table of Contents
our information systems and software applications, and we take steps designed to mitigate the risks associated with known vulnerabilities. Despite our efforts, there can be no assurance that these vulnerability, defect and configuration error mitigation measures will be completely effective. Further, we may experience delays in developing and deploying remedial measures and patches designed to address any such identified vulnerabilities, defects or configuration errors. Additionally, as part of our business operations, employees and authorized personnel, or insiders, access our systems, applications, and data, including through the use of mobile devices, including personally-owned devices. Our business may be adversely affected if insiders cause cybersecurity incidents such as data breaches, intellectual property theft, ransom demands, or operational disruptions. We take steps designed to detect and mitigate insider threats, however, despite our efforts, there can be no assurance that these efforts will be completely effective and we have expended significant resources to prevent, detect and investigate such threats. Additionally, our ability to implement and enforce security measures on employee-owned mobile devices is more limited, which increases the risk of cybersecurity threats.
Any of these or similar threats could cause a security incident or other interruption that can result in unauthorized, unlawful, or accidental acquisition, modification, destruction, loss, alteration, encryption, disclosure of, or access to our proprietary, confidential, and sensitive information or our information technology systems, or those of the third parties upon whom we rely. For example, we have been the target of unsuccessful phishing attempts in the past and we expect such attempts will continue in the future. A security incident or other interruption could disrupt our ability (and that of third parties upon whom we rely) to provide our solutions. In some instances, we or our third-party service providers may not be able to identify the cause or causes of these security incidents or performance problems within an acceptable period of time. If our solutions are unavailable or if our customers are unable to access features of our solutions within a reasonable amount of time or at all, our business could be adversely affected. In addition, if we or any of the third-party providers we use were to experience or cause a significant or prolonged outage or security incident, our business could be adversely affected. We may expend significant resources or modify our business activities to try to protect against or recover from security incidents. Certain data privacy and security obligations may require us to implement and maintain specific security measures, industry-standard or reasonable security measures to protect our information technology systems and proprietary, confidential, and sensitive information, including personal data.
Data protection requirements may also require us or we may voluntarily choose to notify relevant stakeholders of security incidents, including affected individuals, partners, collaborators, customers, regulators, law enforcement agencies and others, or take other actions, such as providing credit monitoring and identity theft protection services. Such disclosures and related actions can be costly, and the disclosures or failure to comply with such applicable requirements could lead to adverse consequences.
Additionally, even if we have issued or otherwise made patches or information for vulnerabilities in our software applications, products or services, our customers may be unwilling or unable to deploy such patches and use such information effectively and in a timely manner. Vulnerabilities could be exploited and result in a security incident.
If we, our customers, or a third party upon which we rely, experience or cause a security incident or other interruption, or are perceived to have experienced or caused a security incident or other interruption, we may experience material adverse consequences, such as government enforcement actions (for example, investigations, fines, penalties, audits, and inspections); additional reporting obligations and/or oversight; restrictions on processing information (including personal data); litigation (including class claims); indemnification obligations; negative publicity; reputational harm; monetary fund diversions; interruptions of our operations (including availability of data); financial loss (including by issuing credits to our customers); diversion of management attention; and other similar harm. Security incidents or other disruptions and attendant material consequences may cause customers to stop using our solutions (including by not renewing their purchases of our solutions), deter new customers from using our solutions, and negatively impact our ability to grow and operate our business.
There can be no assurance that any limitations or exclusions of liabilities in our contracts would be enforceable or adequate or would otherwise protect us from liabilities or damages if we fail to comply with data protection requirements related to information security or security incidents. We cannot be sure that our insurance coverage will be adequate or otherwise protect us from or adequately mitigate liabilities or damages with respect to claims, costs, expenses, litigation, fines, penalties, business loss, data loss, regulatory actions or other impacts arising out of security incidents.
33
Table of Contents
In addition, we face unique risks as a SaaS company that sells products and services that involve protecting the information systems of our customers. If our solutions fail to detect vulnerabilities in our customers’ cybersecurity infrastructure, including for remote devices, or if our solutions fail to identify new and increasingly complex methods of cyberattacks, our business may suffer and our customers' businesses may be damaged, including by interrupting their networking traffic or operational technology environments. Furthermore, a security incident could heighten the impact of these material adverse consequences because of the nature of our business and expectations of our customers. There is no guarantee that our solutions will detect all vulnerabilities or threats in our customers' systems, especially in light of the rapidly changing security landscape to which we must respond. As cyber threats increasingly leverage artificial intelligence and other advanced techniques, customer expectations for rapid identification, prioritization and remediation of vulnerabilities continue to increase. If our solutions fail to keep pace with these evolving threats or do not effectively help customers address them, our reputation, competitive position and customer relationships could be adversely affected. Additionally, our solutions may falsely detect vulnerabilities or threats that do not actually exist. For example, our solutions rely on information provided by an active community of users who contribute information about new exploits, attacks and vulnerabilities. If the information from these third parties is inaccurate, the potential for false indications of vulnerabilities or threats increases. These false positives, while typical in the industry, may impair the perceived reliability of our offerings. Additionally, our business depends upon the appropriate and successful implementation of our product by our customers. If our customers fail to use our solutions according to our specifications, our customers may suffer a security incident on their own systems or other adverse consequences. Even if such an incident is unrelated to our security practices, it could result in our incurring significant economic and operational costs in investigating, remediating, and implementing additional measures to further protect our customers from their own vulnerabilities.
The reliability and continuous availability of our solutions is critical to our success. We have experienced errors or defects in the past in connection with the release of new solutions and product upgrades, and we expect that these errors or defects will be found from time to time in the future in new or enhanced solutions after commercial release. For example, on December 31, 2024, we identified Nessus agents versions 10.8.0 and 10.8.1 going offline under certain conditions which impacted the availability of our Vulnerability Management and Security Center solutions for certain customers. Upon discovery of the incident, we developed and released a version 10.8.2 of our Nessus agent on January 2, 2025, which enabled affected customers to resolve the issue. Although the financial impacts of this incident have not been significant, similar incidents in the future could result in costs associated with service-level credits and loss of customer trust, which could have a material adverse effect on our business and financial performance. In addition, we use third parties to assist in the development of our products and these third parties could be a source of errors or defects. Some defects may cause our solutions to be vulnerable to attacks, cause them to fail to detect vulnerabilities, or temporarily interrupt customers’ networking traffic or operational technology environments, any of which may damage our customers’ business and could hurt our reputation.
As a result of any of the risks associated with our SaaS business, we may experience material adverse consequences. We may also be subject to liability claims for damages related to errors or defects in our solutions.
We have incorporated and expect to continue to incorporate and further expand our use of AI technologies, including generative AI, into certain of our products and services. These technologies are subject to new and developing regulatory frameworks and may create operational, financial, regulatory, and reputational risks based on development practices or reliance on AI outputs that are inaccurate or flawed. These technologies may not achieve market acceptance and may pose other adverse consequences to our business, some of which we may not know or be able to quantify at this time.
We have incorporated and expect to continue to incorporate and further expand our use of AI features in certain of our products and services, including ExposureAI, Tenable AI Assistant and Hexa AI within Tenable One. The use of AI technologies, including generative AI processes, at scale is relatively new, and may lead to challenges, concerns and risks, including various privacy and security risks that are significant or that we may not be able to predict, especially if our use of these technologies in our products and services becomes more important to our operations over time. The technologies underpinning these features are in the early stages of commercial use and exist in an emerging regulatory environment with heightened regulatory scrutiny, which presents regulatory, litigation, ethical, safety, reputational, operational and financial risks. AI in our products and services may be complex to deploy successfully due to operational issues inherent to the nature of such technologies, including the availability, development, maintenance and operation of deep learning datasets and third-party dependencies.
34
Table of Contents
Datasets used in AI training, development, and operations may be insufficient, of poor quality, not fit for purpose, contain sensitive information, or reflect unwanted bias. If we do not have adequate rights to utilize the data or other materials and content that our AI technologies depend on, we may face legal consequences for violating applicable laws, third-party intellectual property, privacy or other rights, or contracts to which we are a party. The use of certain types or sources of data for AI training or development may require consent from data subjects, customers, or other data owners or custodians. We may not have insight into, or control over, the provenance of certain data that our AI technologies ingest. As laws evolve, we may be obligated to obtain certain consents for AI development that we had not previously sought and seeking any type of consent may be costly, impractical, and hinder competitive development or deployment of AI technologies. Customers are increasingly concerned about how their data may interact with AI technologies and may require us to make stronger assurances or contractual commitments to refrain or limit the use of customer data with AI technologies. This may adversely impact our ability to develop or improve AI technologies, which rely on a large volume of diverse and relevant data, including customer data, to produce more accurate, reliable, and predictable outputs.
Uncertainty in the legal regulatory regime relating to AI and emerging ethical issues surrounding the use of AI may require significant resources to modify and maintain business practices to comply with U.S. and non-U.S. laws, the nature of which cannot be determined at this time. Existing laws and regulations may apply to us or our suppliers, vendors, partners and customers in new ways, and new laws and regulations may be instituted. Many U.S. and international governmental bodies and regulators have proposed, enacted or are in the process of developing, new regulations related to the use of AI and machine learning technologies, including the EU AI Act, Colorado AI Act, California Bot Disclosure Law, and Utah AI Policy Act, as well as regulations on certain high-risk automated decisions, such as those in the employment context. For example, the EU AI Act, which applies beyond the European Union’s borders and establishes obligations for AI providers and those deploying AI systems, sets out a risk-based framework that subjects certain AI technologies to numerous compliance obligations, such as transparency, conformity and risk assessment, monitoring and human oversight requirements. Under the EU AI Act, non-compliant companies may be subject to administrative fines of up to 35 million Euros or 7% of a company's total worldwide annual turnover for the preceding financial year, whichever is higher. Certain of our activities subject us to the EU AI Act and other U.S. and non-U.S. laws governing AI or data processed in connection with AI. We expect other jurisdictions may adopt similar or potentially more restrictive laws, which may render the use of such technologies challenging. The final form of these may impose obligations related to our development, offering (including import and export thereof) and use of AI technologies and expose us to increased risk of regulatory enforcement and litigation. We may have to amend our business practices, contractual arrangements, products and/or services to comply with such obligations. In addition to formal legislation, governmental authorities may take enforcement or administrative actions that restrict the use of specific AI technologies. For example, federal agencies have designated Anthropic as a supply chain risk, a designation Anthropic has challenged in ongoing federal litigation and whose ultimate scope and enforceability remains uncertain. This or similar enforcement or administrative actions or changes in export controls, trade sanctions or other regulatory restrictions impacting AI technologies and frontier models could result in prohibitions on the use of Anthropic's and/or other frontier AI models in our solutions. Such actions could force us to decouple or replace integrated technologies on short notice, resulting in significant engineering costs, service disruptions, and the loss of critical product functionality.
Our customers deploy AI technologies in their environments where the AI technologies may encounter sensitive information (including confidential, competitive, proprietary, or personal data) or our customers may input sensitive information into our AI-powered offerings, regardless of any prohibitions in our terms of service. Any sensitive information that our AI technologies ingest could be leaked or disclosed to others. Additionally, many of our AI technologies are powered by third-party AI providers, which may heighten the risk of inadvertent or unwanted disclosure of sensitive information, including if sensitive information is used to train the third party's AI model. Additionally, where an AI model ingests personal data and makes connections using such data, those technologies may reveal other personal or sensitive information generated by the model. This could create legal or contractual liability for us in light of the model's ability to output sensitive information.
Our AI technology features may also generate output that is misleading, insecure, inaccurate, harmful or otherwise flawed. Agentic AI solutions may compound those risks by taking or implementing actions or outputs, which themselves may be based on flawed outputs, that further increase the risk of misleading, insecure, inaccurate, harmful or otherwise flawed outcomes. This risk extends to our enterprise operations, as employee use of third-party agentic AI solutions, such as browser plug-ins or other automated applications, could result in actions being taken without adequate human review or monitoring. Such unauthorized automated actions could, for example, lead to the inadvertent disclosure or modification
35
Table of Contents
of corporate data or other sensitive information, flawed communications to customers or partners, or the creation of unintended legal or financial obligations on behalf of the company. Our customers or others may rely on or use such misleading, insecure, harmful or otherwise flawed content to their detriment, which may harm our brand, reputation, business or customers, cause competitive harm or expose us to legal liability. For example, AI algorithms use machine learning and predictive analytics which may be insufficient or of poor quality and reflect inherent biases and could lead to flawed, biased, and inaccurate results. Deficient or inaccurate recommendations, forecasts, or analyses that generative AI applications assist in producing could lead to customer rejection or skepticism of our products, affect our reputation or brand, and negatively affect our financial results. Further, unauthorized use or misuse of AI by our employees or others may result in disclosure of confidential company and customer data, reputational harm, privacy law violations and legal liability. Our use of generative AI may also lead to novel and urgent cybersecurity risks, including those related to personal data, which may adversely affect our operations and reputation, and these risks likely are compounded by our use of agentic AI.
While AI features are presently increasing in popularity, we have no assurance that our AI technologies will continue to be accepted and sought by customers. The development of generative and agentic AI technologies is complex, and there are technical challenges associated with achieving the desired level of accuracy, efficiency, and reliability. The algorithms and models utilized in generative or agentic AI systems may have limitations, including biases, errors, or inability to handle certain data types or scenarios. Furthermore, there is a risk of system failures, disruptions, or vulnerabilities that could compromise the integrity, security or privacy of the generated content. These limitations or failures could result in reputational damage, legal liabilities, or loss of customer confidence, which, in turn, could result in lower than anticipated demand from customers to adapt our AI features. We have, and will continue, to dedicate significant resources to developing and deploying generative, agentic, or other AI features in our products and services, without assurances that we will, or will continue to, see customer demand and market conditions to support those investments.
We rely, and likely will continue to rely, on third parties to support our use of AI in our products and services. Our ability to offer AI-powered products and services may be adversely impacted if any of our third-party AI providers, or other AI-related third-party vendors, develops or deploys AI tools that are unlawful, unreliable, unsecure, or unavailable. If we cannot use third-party AI, or that use is restricted, our business may be less efficient or we may be at a competitive disadvantage, which could adversely affect our business, financial condition, customer loyalty, and reputation.
We rely on third parties to maintain and operate certain elements of our network infrastructure.
We utilize data centers located in North America, Europe and Asia to operate and maintain certain elements of our own network infrastructure. Some elements of this complex system are operated by third parties that we do not control and that could require significant time to replace. We expect this dependence on third parties to continue. For example, Tenable One is hosted on AWS which provides us with computing and storage capacity. Interruptions in our systems or the third-party systems on which we rely, particularly AWS, whether due to system failures, computer viruses or cyber threats, physical or electronic break-ins or other factors, could affect the security or availability of our solutions, network infrastructure and website. In addition, outages or operational failures at major cloud infrastructure providers, including data center failures, regional service disruptions, service degradation, or provider configuration errors, or disruptions caused by geopolitical instability, military conflict or other regional hostilities, such as escalating tensions involving Iran or across the broader Middle East, could materially impair the availability and performance of our solutions, particularly where we rely on limited regional infrastructure or do not have localized backup or failover capacity. For example, recent disruptions affecting AWS data centers in the UAE and Bahrain in connection with escalating regional hostilities involving Iran highlighted the risk that disruptions affecting a single facility could compromise business continuity for customers in that region and result in downtime, delayed customer access, reputational harm and financial loss.
Our existing data center facilities and third-party hosting providers have no obligations to renew their agreements with us on commercially reasonable terms or at all, and certain of the agreements governing these relationships may be terminated by either party with notice or access to hosting services may be restricted by the provider at any time, with no or limited notice. For example, our agreement with AWS allows AWS to terminate the agreement with two years' written notice and allows AWS, under certain circumstances, to temporarily restrict access to hosting services provided by AWS without prior notice. Although we expect that we could receive similar services from other third parties, if any of our arrangements with third parties, including AWS, are terminated, we could experience interruptions on our platform and in
36
Table of Contents
our ability to make our platform available to customers, as well as downtime, delays and additional expenses in arranging alternative cloud infrastructure services.
A portion of our revenue is generated from subscriptions and perpetual licenses sold to domestic governmental entities, foreign governmental entities and other heavily regulated organizations, which are subject to a number of challenges and risks.
A portion of our revenue is generated from subscriptions and perpetual licenses sold to governmental entities in the United States. Additionally, many of our current and prospective customers, such as those in the financial services, energy, insurance and healthcare industries, are highly regulated and may be required to comply with more stringent regulations in connection with subscribing to and implementing our enterprise platform. Selling licenses to these entities can be highly competitive, expensive and time-consuming, often requiring significant upfront time and expense without any assurance that we will successfully complete a sale. Governmental demand and payment for our enterprise platform may also be impacted by public sector budgetary cycles, funding authorizations and budget shortfalls, the operational stability of government agencies, and the prioritization of cybersecurity and digital infrastructure initiatives. Funding reductions or delays, including those resulting from a U.S. government shutdown, reductions or eliminations of agency operating budgets or deprioritization of cybersecurity digital infrastructure related initiatives would adversely affect public sector demand for our enterprise platform. For example, the U.S. presidential administration's priorities and actions to reduce government spending, including, but not limited to, those previously driven by the Department of Government Efficiency, may impact the availability of funding for U.S. government customers as a result of the elimination of departments and personnel. These actions may lead to elongated sales cycles and procurement decisions and could result in fewer contract opportunities or reduced funding for existing initiatives, all of which would adversely affect our business and financial performance. In addition, governmental entities have the authority to terminate contracts at any time for the convenience of the government, which creates risk regarding revenue anticipated under our existing government contracts.
Further, governmental and highly regulated entities often require contract terms that differ from our standard customer arrangements, including terms that can lead to those customers obtaining broader rights in our solutions than would be expected under a standard commercial contract and terms that can allow for early termination. The U.S. government will be able to terminate any of its contracts with us either for its convenience or if we default by failing to perform in accordance with the contract schedule and terms. Termination for convenience provisions would generally enable us to recover only our costs incurred or committed, settlement expenses, and profit on the work completed prior to termination. Termination for default provisions do not permit these recoveries and would make us liable for excess costs incurred by the U.S. government in procuring undelivered items from another source. Contracts with governmental and highly regulated entities may also include preferential pricing terms. In the United States, federal government agencies may promulgate regulations, and the President may issue executive orders, requiring federal contractors to adhere to different or additional requirements after a contract is signed. If we do not meet applicable requirements of law or contract, we could be subject to significant liability from our customers or regulators. Even if we do meet these requirements, the additional costs associated with providing our enterprise platform to government and highly regulated customers could harm our operating results. Moreover, changes in the underlying statutory and regulatory conditions that affect these types of customers could harm our ability to efficiently provide them access to our enterprise platform and to grow or maintain our customer base. In addition, engaging in sales activities to foreign governments introduces additional compliance risks, including risks specific to anti-bribery regulations, including the U.S. Foreign Corrupt Practices Act of 1977, as amended, or the FCPA, the U.K. Bribery Act 2010 and other similar statutory requirements prohibiting bribery and corruption in the jurisdictions in which we operate. Further, in some jurisdictions we may be required to obtain government certifications, which may be costly to maintain and, if we lost such certifications in the future or if such certification requirements changed, would restrict our ability to sell to government entities until we have attained such certifications. Furthermore, our ability to maintain or expand our business with government customers depends on our continued ability to comply with rapidly evolving restrictions on the use of and rights to certain artificial intelligence models, features, or output, such as those which may evolve from draft acquisition regulations and supplements clauses, such as Proposed GSAR Clause 552.239-700; proposed updates to NIST frameworks; and/or supply chain security designations, such as recent federal actions identifying specific third-party AI providers and models as supply chain risks. Any future adverse regulatory designation against our third-party AI providers could require us to rapidly re-engineer our solutions at significant cost, disrupt existing government contracts, or disqualify us from future solicitations. Future changes to acquisition regulations
37
Table of Contents
and NIST frameworks could require us to alter what rights we grant in the use of our products, what intellectual property rights we grant customers, how we track code generation, and how humans are in the loop for code review and approval.
Some of our revenue is derived from contracts with U.S. government entities, as well as subcontracts with higher-tier contractors and customers who receive government funding. As a result, we are subject to federal contracting regulations, including the Federal Acquisition Regulation, or the FAR. Under the FAR, certain types of contracts require pricing that is based on estimated direct and indirect costs, which are subject to change.
In connection with our U.S. government contracts, we may be subject to government audits and review of our policies, procedures, and internal controls for compliance with contract terms, procurement regulations, and applicable laws. In certain circumstances, if we do not comply with the terms of a contract or with regulations or statutes, we could be subject to contract termination or downward contract price adjustments or refund obligations, could be assessed civil or criminal penalties, or could be debarred or suspended from obtaining future government contracts for a specified period of time. Any such termination, adjustment, sanction, debarment or suspension could have an adverse effect on our business.
Moreover, as a U.S. government contractor, we maintain plans to ensure compliance with applicable legal and contractual requirements related to nondiscrimination. Consequently, we may be subject to executive orders and regulatory changes affecting various aspects of our operations. Any required elimination or modification of such plans in response to new or changes to existing executive orders or legal or contractual requirements could pose challenges in hiring or retaining employees and may lead to other adverse operational impacts. Failure to comply with these requirements could expose us to administrative, civil, or criminal liabilities, including fines, penalties, repayments or suspension or debarment from eligibility for future U.S. government contracts. Further, as a U.S. government contractor, we are subject to an increased risk of investigations, criminal prosecution, civil fraud claims, whistleblower lawsuits and other legal actions and liabilities as compared to solely private sector commercial companies.
In the course of providing our solutions and professional services to governmental entities, our employees and those of our channel partners may be exposed to sensitive government information. Any failure by us or our channel partners to safeguard and maintain the confidentiality of such information could subject us to liability and reputational harm, which could materially and adversely affect our results of operations and financial performance.