LATEST NEWS
20 AUG 2026 / EXOSTAR TECHNOLOGY POWERS FUJITSU SERVICE IN JAPAN07 APR 2026 / LOCKHEED MARTIN SIGNS FIVE-YEAR RENEWAL03 JUN 2026 / CMMC READY SUITE JOINS MICROSOFT MARKETPLACE20 AUG 2026 / EXOSTAR TECHNOLOGY POWERS FUJITSU SERVICE IN JAPAN07 APR 2026 / LOCKHEED MARTIN SIGNS FIVE-YEAR RENEWAL03 JUN 2026 / CMMC READY SUITE JOINS MICROSOFT MARKETPLACE
Company / The business of trust

Exostar: The rivals who built a shared front door

Aircraft makers compete fiercely. Their suppliers still need a safe way to work with all of them. Exostar turned that awkward arrangement into a business spanning defense contracts, clinical trials and electronic prescriptions.

The aircraft drawing has to leave the building. That is where the interesting trouble begins. A manufacturer needs its supplier to read it, work from it and perhaps discuss it with another partner. Every useful connection creates another question: who is allowed to see this, and how do we know?

Exostar has made a business out of those questions. Its origins sit in an unusually cooperative corner of an unusually competitive industry. Boeing, BAE Systems, Lockheed Martin and Raytheon helped establish it in 2000. They were building an online exchange for aerospace and defense. Rivals could disagree about the aircraft and still agree that dealing with suppliers ought to be less cumbersome.

The useful bits, first
  • What it does: verifies identities, controls partner access and organizes secure collaboration and supplier data.
  • Who needs it: defense supply chains, pharmaceutical sponsors, research sites and healthcare software providers.
  • Its distinguishing asset: a shared network the company says spans more than 200,000 organizations in 175 countries.
  • The buying lesson: map where sensitive information travels before deciding which tools and services to purchase.

An exchange meets the real world

The original proposition belonged to the dot-com era: bring buyers and sellers together online, cut purchasing friction and collect revenue from transactions. Rolls-Royce joined in 2001. The exchange had substantial industrial backing, but backing was not the same thing as a settled business model.

In September 2001, National Defense reported about 4,000 participating companies and 20,000 weekly transactions. It also reported that Exostar was years from profitability. Vice president Barry Lerner described an expansion into collaboration services. “Our revenue model over time will be far more than just transaction based,” he said.

The revealing detail is the incompleteness. Here was a business already used by thousands of companies, still working out which work would pay. Engineering collaboration and procurement tools offered another route. The early weakness was commercial: transaction activity alone had not yet produced a profitable company. It would be a mistake to turn that into a tidy tale of collapse and rescue.

The leak that changed the brief

A second problem sharpened the direction. A Boeing-Exostar case study published by NIST describes a turning point in 2007, when aerospace companies were brought together over concerns about critical information leaking through the supply chain. Intellectual property was escaping beyond the companies that created it.

The response included stronger access controls and shared identity management. Another tool, Partner Information Manager, developed through an industry working group over 18 months, established common cybersecurity information for suppliers. A supplier serving several buyers could complete a questionnaire once and reuse it.

That arrangement gives Exostar its most interesting economic feature. Each buyer has an interest in knowing its suppliers. Each supplier has an interest in avoiding another nearly identical administrative exercise. Shared infrastructure offers something to both sides. Exostar’s present business is cloud subscriptions, credentials, managed environments and services built around that recurring relationship.

“Connect Once, Collect Once, Certify Once, Share Many”

Exostar’s stated platform methodology

The phrase describes reuse of information and verification. It does not mean that one certificate grants universal permission or settles every buyer’s requirements. The attraction is a reduction in repeated introductions.

One identity, several locked rooms

Managed Access Gateway, or MAG, is the defense network’s identity hub. It supports federation, single sign-on, partner onboarding and credential management. Application owners retain control of who can enter their systems, including permissions at the individual-user level.

Think of the distinction as a recognized visitor with several possible appointments. Recognizing the person does not open every office. A shared identity makes the introduction reusable; the owner of each application still decides what access to approve. That combination is more useful than a universal key.

How the shared front door works
01Verified partnerOrganization + individual
02Shared identity hubMAG checks the credential
03Approved applicationOwner controls permission
One introduction. Several permission checks. The diagram shows the access model, not a promise that every application is connected.

Supplier Management tackles the neighboring problem: collecting and checking organizational information, onboarding companies and tracking risk. In April 2026, Exostar announced a new five-year Lockheed Martin contract supporting a community of nearly 20,000 suppliers. Its described work includes credential verification, identity proofing and risk assessments covering capabilities, financial health and denied-party screening.

That is a more concrete description of the company than “cybersecurity platform.” Exostar sits between a buyer and outside organizations that need access to the buyer’s business. Its expertise lies in making that relationship repeatable while preserving controls.

Aircraft drawings meet clinical passwords

Life sciences might appear a peculiar destination for an aerospace exchange. Look at the workflow, though, and the resemblance becomes plain. A research site needs access to systems run by pharmaceutical sponsors. Sponsors need to know who the user is and what that person should be permitted to do.

Exostar’s Secure Access Manager, or SAM, offers single sign-on, delegated administration, automated provisioning and access reporting for clinical trials. Its current product page reports more than 750,000 users, 36,000 sites and over 122 applications. Customer listings include AstraZeneca, Merck, Pfizer and Roche.

Clinical access / company-reported scale
750k+users
36ksites
122+applications

Product figures overlap with the wider platform network. They are not separate totals to add together.

There is another adjacent business in ProviderPass, which supplies identity proofing, two-factor authentication and digital signing for electronic prescribing of controlled substances. It integrates with electronic health record systems; its product page reports more than 100,000 users. Access One extends identity management into financial services.

The common thread is a specific administrative burden. People must move between organizations’ systems, with identities and permissions that can withstand scrutiny. Exostar sells ways to make that movement less laborious.

People discussing work around a table, in an illustrative photograph from Exostar’s careers page
Everyone brought a laptop. Ideally, nobody brought a spreadsheet of passwords. An illustrative photograph from Exostar’s careers page.

Buying a smaller security problem

For a defense supplier, the CMMC Ready Suite offers a more involved purchase. It combines a managed collaboration environment, identity controls, documentation tools and readiness services. Exostar Managed on Microsoft 365 uses a GCC High enclave for sensitive information. Managed Secure Desktop adds a controlled virtual workspace.

The idea is to contain the work. If controlled unclassified information, or CUI, stays in a managed environment, fewer other systems may need to sit inside the assessment boundary. The benefit depends on actual data flows. A drawing copied to an unmanaged device changes the problem again.

Certification Assistant organizes evidence, self-assessments, scores, system security plans and remediation plans. PolicyPro helps with policies. Services address gaps that software cannot close. In December 2025, Exostar announced its own CMMC Level 2 certification with a perfect assessment score and no remediation plan required. That status belongs to Exostar’s assessed scope; it does not certify a customer by association.

The boundary matters
Managed environment

Identity controls, collaboration, protected storage and activity logs.

Customer organization

Policies, training, personnel, physical security and the routes data takes.

Conceptual division of responsibilities. The contract and assessment scope determine the details.

Cost has several moving parts. A MyExostar help page updated in December 2024 listed legacy Certification Assistant Standard at $3,500 a year. That is a dated price for a particular tool, rather than a price for the complete suite. Current suite materials describe technology packages for up to 10, 20 or 50 users and service packages based on the complexity of CUI workflows. The practical comparison is the combined cost of technology, implementation and continuing work.

Alternatives include assembling an external-identity system, a GCC High environment and compliance advisers separately, or using existing buyer-operated portals. Exostar’s case rests on the value of bringing those tasks into an established partner network. A company whose partners use different applications, or whose sensitive workflows extend well beyond the enclave, must account for integration and scope before expecting the same savings.

The orders join the identities

Ownership has changed as the product set has grown. Thoma Bravo announced a strategic investment in 2020. Arlington Capital Partners completed its purchase from Thoma Bravo in November 2023. In December 2024, Exostar acquired Robot Morning and ComplyUp, adding supply chain automation and compliance capabilities.

SupplyLine automates procurement exchanges such as purchase orders, acknowledgments and shipping notices. DemandLine brings customer demand information into a supplier’s ERP system. SourcePass supports sourcing requests and auctions. These products bring Exostar closer to the everyday movement of orders, alongside its work on identity and supplier assurance.

Richard Addi, Exostar president and chief executive officer
Richard Addi joined as CFO in 2007 and became CEO in 2011. A finance seat with a rather extensive view of the supplier network.

Recent announcements show that expansion continuing. In May 2026, Exostar announced an assessment partnership with A-LIGN and selection for the U.S. Army’s NCODE contract vehicle. In June, its Azure-based CMMC suite became available through Microsoft Marketplace. In August, it announced technology for Fujitsu’s Trusted Supplychain Service in Japan, combining its secure collaboration approach with Japanese infrastructure and local data residency.

A network worth borrowing from

The useful lesson reaches beyond defense. Start with information that several partners repeatedly need. Standardize its collection. Make the identity reusable. Leave access decisions with the people responsible for the application. Then examine where sensitive information actually goes, including the inconvenient side trips.

Exostar’s careers materials emphasize development, inclusion and customer relationships. The business itself rewards a less theatrical habit: knowing a regulated workflow well enough to remove an unnecessary step without removing a necessary control. The drawing still has to leave the building. The supplier still has to do the work. A better front door makes that ordinary exchange easier to manage.

Keep exploring