OTC: ATDS
Data443 Risk Mitigation, Inc.CIK 0001068689 · Prepackaged Software
Our company was incorporated as LandStar, Inc., a Nevada corporation, on May 4, 1998. We provide data security and privacy management solutions across the enterprise and in the cloud. Trusted by over 10,000 customers, we provide the visibility and control needed to protect data at scale, regardless… About this business →
Each report below shows a 3-bullet preview. Free accounts read 3 full reports a month — narrative summary, section diffs, and EDGAR-cited quotes.
Sign up freeWant to see a complete report first? Today's free report (THRM 10-Q) is open in full — no account needed.
Summary not yet generated.
Summary not yet generated.
Partner
Trade ATDS commission-free
Open an account, get a free stock.
Investing involves risk. Free stock terms apply.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Summary not yet generated.
Latest financial statements
From 10-Q filed May 14, 2026 (period ending Mar 31, 2026). SEC XBRL (companyfacts) — not generated by the model.
Consolidated Statements of Operations (Unaudited)
| Description | Q1 ended Mar 31, 2026 | Q3 ended Sep 30, 2025 |
|---|---|---|
| Revenue: | ||
| Total revenue / net sales | 1.0 | 0.9 |
| Cost of revenue / cost of sales | 0.9 | 0.4 |
| Gross profit | 0.2 | 0.5 |
| Operating expenses: | ||
| Sales and marketing | 0.02 | 0.05 |
| General and administrative | 0.9 | 1.1 |
| Total operating expenses | 0.9 | 1.1 |
| Operating income | (0.7) | (0.6) |
| Interest expense | 0.5 | |
| Other income/(expense), net | (0.3) | (0.04) |
| Income before income taxes | (1.0) | (0.6) |
| Net income | (1.0) | (0.6) |
| Basic earnings per share | (0.00) | (0.00) |
| Diluted earnings per share | (0.00) | (0.00) |
Consolidated Balance Sheets (Unaudited)
| Description | Mar 31, 2026 | Dec 31, 2025 |
|---|---|---|
| Current assets: | ||
| Cash and equivalents | 0.04 | 0.2 |
| Accounts receivable, net | 0.10 | 0.09 |
| Prepaid expenses and other current assets | 0.6 | 1.1 |
| Total current assets | 0.7 | 1.4 |
| Property, plant and equipment, net | 0.1 | 0.1 |
| Finite-lived intangible assets, net | 1.9 | |
| Other long-term assets | 2.7 | 4.8 |
| TOTAL ASSETS | 5.5 | 6.4 |
| Current liabilities: | ||
| Accounts payable | 2.5 | 2.6 |
| Accrued liabilities | 3.0 | 2.8 |
| Deferred revenue, current | 1.4 | 1.4 |
| Other current liabilities | 11.9 | 11.4 |
| Total current liabilities | 18.8 | 18.2 |
| Other long-term liabilities | 1.7 | 2.5 |
| Total liabilities | 20.6 | 20.7 |
| Shareholders' equity: | ||
| Common stock | 1.4 | 0.8 |
| Capital in excess of stated value | 48.8 | 49.2 |
| Retained earnings (deficit) | (65.3) | (64.3) |
| Total shareholders' equity | (15.1) | (14.3) |
| TOTAL LIABILITIES AND SHAREHOLDERS' EQUITY | 5.5 | 6.4 |
Consolidated Statements of Cash Flows (Unaudited)
| Description | Q1 ended Mar 31, 2026 | Nine months ended Sep 30, 2025 |
|---|---|---|
| Operating Activities: | ||
| Net cash from operating activities | (0.2) | 0.1 |
| Investing Activities: | ||
| Net cash from investing activities | (0.01) | |
| Financing Activities: | ||
| Net cash from financing activities | 0.03 | (0.2) |
| Net increase/(decrease) in cash | (0.2) | (0.1) |
Amounts in millions USD; EPS as reported. Line labels are presentation-friendly mappings of filer XBRL tags — not a re-audit of the full statements. Use EDGAR for interactive notes and detail. Interactive statements & notes on EDGAR ↗
About Data443 Risk Mitigation, Inc.
Source: Item 1 (Business) from the 10-K filed April 16, 2026. Description as filed by the company with the SEC.
Item
1. Business.
Our
company was incorporated as LandStar, Inc., a Nevada corporation, on May 4, 1998. We provide data security and privacy management solutions
across the enterprise and in the cloud. Trusted by over 10,000 customers, we provide the visibility and control needed to protect data
at scale, regardless of format, location, or consumer, and to facilitate compliance with fast-changing global data privacy requirements.
Our customers include established leaders and up-and-coming businesses spanning the private and public/government sectors across diverse
industries and fields, including financial services, healthcare, manufacturing, retail, technology, and telecommunications. We also provide
threat detection, brand protection and email phishing, spam and virus solutions for some of the world’s largest security providers,
managed service providers, e-gaming/media and ecommerce vendors on an Original Equipment Manufacturer (OEM) basis.
The
mounting ransomware landscape as well as other threats to data have accelerated the rate at which businesses are adopting data security
solutions and we believe that our portfolio of data security and privacy products provides an encompassing solution set such that we
are well positioned to capitalize on that increased adoption rate and establish our products as new data privacy and security standards.
Our offerings are anchored in reliable and comprehensive privacy management and equip organizations with a seamless approach to safeguard
data, protect against attacks, and otherwise mitigate the most critical risks.
Read full description ↓
4
We
believe that sector-specific US laws, state-level legislation, and outside-the-United States regulations are confounding enterprises
of all sizes for whom safeguarding and stewarding data is key, but for whom becoming specialists in privacy and security is not feasible.
For many of these enterprises, we can bridge the gap between their need to protect data and their need to use their resources to grow
their core business, by offering turnkey solutions and related counseling and technical support to offset risks from data breaches and
security incidents of various types. We provide products and services for the marketplace that are designed to protect data that is stored
in the cloud, on-premises, and in hybrid cloud/on-premises environments, and data that is transmitted throughout the enterprise, including
but not limited to by remote employees. Our suite of security products focuses on protecting sensitive files and email, confidential
customer, patient and employee data, financial records, strategic and product plans, intellectual property and other proprietary information,
allowing our customers to create, share, and protect their sensitive data wherever it is stored and however it is used.
We
deliver solutions and capabilities that businesses can use in conjunction with their use of established cloud vendors such as Microsoft®
Azure, Google® Cloud Platform (GCP), and Amazon® Web Services (AWS), as well as with on-premises databases and database applications
and with virtualization platforms, such as those hosted or configured using VMWare®, Citrix®, and Oracle® products. In order
to deliver our services, we also operate two data centers in the United States, two data centers in Germany and one data center in Israel.
We
sell or plan to sell substantially all of our products and services through a sales model that combines the leverage of a channel sales
model or direct account management, thereby providing us with opportunities to grow our current customer base and deliver our value proposition
for data privacy and security. We endeavor to use subscription models to license products and services, commonly for a paid in-advance,
multiyear term that is auto-renewing. We also make use of channel partners, distributors, and resellers which sell to end-users of the
products and services. This approach allows us to maintain close relationships with our customers and benefit from the global reach of
our partners. Additionally, we are enhancing our product offerings and go-to-market strategy by establishing technology alliances within
the IT infrastructure and security vendor ecosystem. Our sales and marketing focus for new organic growth is on organizations with 500
or more users who are adopting cloud services and can make larger purchases with us over time and have a greater potential lifetime value.
We
continue to onboard to cloud-native technology adoption portals such as the Microsoft® Azure Marketplace and the Amazon® AWS
Marketplace. Vendors may offer incentives to us as a software and services provider to onboard and market via their marketplace portals.
We
strive to create new and innovative products and to improve existing products, proactively identifying and solving the data security
needs of our customers.
As
cloud adoption continues to accelerate, data privacy requirements get more complex, and data security becomes more challenging, we believe
we are well positioned to capture more market share, continue to lead in strategic data security technology development, and prepare
organizations for the next epoch in IT data privacy services.
Market
Opportunity
Threat
actors are increasingly targeting clouds and SaaS delivery infrastructure and identities with stealthy tactics via social engineering
and info-stealing malware. Malware and attacks continue to progress with even greater scale, sophistication and evasion techniques to
avoid detection.
We
expect that current market conditions, recent data thefts, ransomware shutdowns and continued variability in the worldwide worker and
retail marketplace will continue to position our product line front and center for many strategic IT and critical board-level opportunities
with customers.
The
competitive marketplace continues to consolidate via buyouts, take-private transactions and large ‘unicorn’ competitors being
acquired prior to their initial public offerings. We believe that these changes in ownership, closure of product lines and general turmoil
in certain product segments represent opportunities for us.
We
believe that the functionalities offered by our programs and services position us to benefit from this growing market. Furthermore, as
we continue to grow our business, we believe that we may have opportunities to expand into collateral growing markets, such IT operations
management, storage management and data integration.
5
Our
Products
Each
of our major product lines provides features and functionality that we believe enable our customers to optimally secure their data. Our
products are modular, giving our customers the flexibility to select what they require for their business needs and to expand their usage
by simply adding a license. We currently offer the following products and services:
●
Cyren®
Threat Intelligence Service (TIS), a well-established offering in emerging and active threats occurring around the world. With
large, velocity-based data sets, TIS provides unique data products for some of the world’s leading security, response, software
and service providers. Capabilities delivered within the Threat Intelligence suite include:
○
Email
Security Engine, protects against phishing, malware, and inbound and outbound spam. Our industry-leading detection provides real-time
blocking of email threats and abuse in any language or format with virtually no false positives.
○
Threat
InDepth, receives early threat information with real-time technical threat intelligence feeds of emerging malware and phishing
threats.
○
Web
Security Engine, an AI-driven tool that makes decisions aided by advanced heuristics and 24×7 analysts; covers 82 threat
categories, including web threats such as phishing, fraud. Malware integration options include an SDK, cloud API, daemon, and container.
○
Malware
Detection, a feature with approximately 100 mini engines that scan unique objects within a file, unpack files and defeat obfuscation
used by malware authors. This tool spots threats with heuristic analysis, advanced emulation, and intelligent signatures.
○
Hybrid
Analyzer, a feature that combines static malware analysis and advanced emulation technology that quickly uncovers behaviors without
executing files. File properties and behaviors are scored to indicate likelihood of maliciousness. Equally effective in connected
and air-gapped environments.
●
Data443®
Ransomware Recovery Manager (also known as SmartShield™), a unique offering designed to recover a workstation immediately
upon infection to the last known business-operable state, without requiring any end user or IT administrator intervention.
●
Data443®
Data Identification Manager (also known as ClassiDocs® and FileFacets®), our data classification and governance technology,
which supports the California Consumer Privacy Act (“CCPA”), the General Personal Data Protection Law (“LGPD”)
(Brazil) and the General Data Protection Regulation (“GDPR”) (Europe) compliance in a Software-as-a-Service (SaaS) platform
that performs sophisticated data discovery and content searching of structured and unstructured data within corporate networks, servers,
content management systems, email, desktops, and laptops.
●
Data443®
Data Archive Manager (also known as ArcMail®), a simple, secure, and cost-effective enterprise data retention management
and archiving.
●
Data443® Sensitive Content Manager (also known
as ARALOC®), a secure, cloud-based platform for managing, protecting and distributing digital content to desktop and mobile devices,
which protects an organization’s confidential content and intellectual property assets from accidental leakage or intentional
misappropriation - without impeding all other authorized users of the content and stakeholders from collaborating.
●
TacitRed Product Line - TacitRed™, a high-volume
data acquisition and intelligence platform, provides comprehensive ingestion, normalization, and enrichment of network telemetry
and external data sources for security and compliance applications. Utilizing scalable data pipelines and advanced correlation techniques,
TacitRed transforms raw data—such as NetFlow and related telemetry—into actionable intelligence that can be seamlessly
integrated with security information and event management (SIEM) and extended detection and response (XDR) systems. Designed for
cost efficiency and operational scalability, TacitRed enables organizations to enhance visibility, improve threat detection, and
support data-driven decision-making across complex environments, while maintaining flexibility in data sourcing, processing, and
delivery.
●
Vaikora
Product Line - Vaikora™, a next-generation platform for AI runtime governance and trust enforcement, is designed to monitor,
score, and control interactions between autonomous systems, applications, and data sources in real time. Leveraging advanced policy
frameworks and decentralized integration capabilities, Vaikora enables organizations to manage AI-driven processes with precision,
ensuring that decisions, data exchanges, and system actions adhere to defined security, compliance, and operational standards. The
platform supports flexible deployment models, including open-source components and enterprise-grade extensions, allowing customers
to integrate Vaikora into existing infrastructures while scaling usage based on evolving business and technical requirements.
6
●
Data443®
Data Placement Manager (also known as DATAEXPRESS®), a data transport, transformation, and delivery product trusted by leading
financial organizations worldwide.
●
Data443®
Access Control Manager (also known as “Resilient Access”), enables fine-grained access controls across a wide variety
of platforms at scale for internal client systems and commercial public cloud platforms like Salesforce®, Box.Net, Google®
G Suite, Microsoft® OneDrive, and others.
●
Data443®
Blockchain Protection Manager (also known as ClassiDocs® for Blockchain), provides an active implementation for the Ripple
XRP that protects blockchain transactions from inadvertent disclosure and data leaks.
●
Data443®
Global Privacy Manager, the privacy compliance and consumer loss mitigation platform which is integrated with Data443® Data
Identification Manager to do the delivery portions of GDPR and CCPA as well as process privacy-related requests under such laws,
and therefore enables customers to manage the full range of privacy-law driven requirements, such as responding to permitted consumer
demands for access or removal, as well as to remediate issues and monitor and report on status and compliance.
●
Data443®
IntellyWP, products for enhancing the user experience for the world’s largest content management platform, WordPress.
●
Data443®
Chat History Scanner, which scans chat messages for compliance, security, personally identifiable information (PII), personal
information (PI), payment card industry (PCI) information as well as any custom keywords selected by the customer, and which can
be used with third party platforms such as the Zoom Video Communications, Inc. video conferencing platform.
●
Data443®
- GDPR Framework, CCPA Framework, and LGPD Framework WordPress® Plugins, which help organizations of all sizes comply with
privacy rules and regulations from Europe, California, and Brazil, and are currently used by over 30,000 active site owners. We offer
the plugins with a “freemium” business model, i.e., basic features at no cost and additional or more advanced features
at a premium.
Growth
Strategy
Our
objective is to be a leading provider of data security products and services. The following are key elements of our growth strategy:
Acquisitions.
We intend to aggressively pursue acquisitions of other cybersecurity software and services providers focused on the data security sector.
We target companies with a steady client base, as well as companies with complementary product offerings.
7
Research
& Development; Innovation. We intend to increase our spending on research and development to drive innovation to improve existing
products and deliver new products. We intend to work towards proactively identifying and solving the data security needs of our clients.
Grow
Our Customer Base. We believe that the continued rise in enterprise data and increased cybersecurity concerns will increase demand
for our services and products. We intend to capitalize on this demand by targeting new customers.
Expand
Our Sales Capacity. We believe that continuing to expand our sales force will be a key to achieving our expansion and growth. We
intend to expand our sales capacity by adding sales and marketing employees, with heavy focus on customer success and leveraging our
existing customer relationships.
Our
Customers
Our
current customer base is comprised primarily of two segments – commercial enterprises and open-source consumers. Our commercial
enterprise customers are generally focused within the U.S., range from 500 employees to over 150,000 employees, and use our data security
products. We have over 10,000 commercial enterprise customers. We have approximately 20 customers in the financial technology industry
that contract with us directly for products with subscriptions with terms of more than three years. We have more than 2,500 customers
comprising mid-market-sized organizations that also contract with us directly for products with subscriptions with terms of one to three
years. Our open-source consumers are more widely distributed geographically, include organizations of all sizes in terms of both number
of employees and revenues, and typically use our online GDPR/CCPA/GLPD Privacy plugins, our Privacy Badge solution, or our user experience
enhancement products. We have over 100,000 open-source consumers with active installations of our plugins, and we have 9,000 open-source
consumers that pay a premium for additional or advanced features. We expect that some of our open-source consumers will become commercial
customers over time. We provide anti-phishing, anti-spam and web security categorization services for hundreds of millions of end users
via our OEM and partner ecosystem. On a monthly basis, we process over 3 billion transactions for security classification, categorization
and guidance for some of the world’s leading IT and cyber security providers.
Services
Maintenance
and Support
Our
intended customers will typically purchase software maintenance and support as part of their initial purchase of our products. These
maintenance agreements provide customers the right to receive support and unspecified upgrades and enhancements when and if they become
available during the maintenance period and access to our technical support services. We will maintain a customer support organization
that provides all levels of support to our customers.
Professional
Services
While
users can easily download, install and deploy our software on their own, we anticipate that certain enterprises will use our professional
service team to provide fee-based services, which include training our customers in the use of our products, providing advice on deployment
planning, network design, product configuration, and implementation, automating and customizing reports and tuning policies and configuration
of our products for the particular characteristics of the customer’s environment.
Sales
and Marketing
We
intend to sell the majority of our products and services directly to our end users/clients. We will also propose to effect sales through
a network of channel partners, selling the products they purchase from us. We have a highly-trained professional sales force responsible
for overall market development, including the management of the relationships with our channel partners and supporting channel partners.
8
Marketing
Our
marketing strategy focuses on building our brand and product awareness, increasing customer adoption and demand, communicating advantages
and business benefits, and generating leads for our channel partners and sales force. We will market our products as a solution for securing
and managing file systems and enterprise data and protecting against cyber-attacks. Our internal marketing organization will be responsible
for branding, content generation, and product marketing. Our marketing efforts will also include public relations in multiple regions,
analyst relations, customer marketing, and extensive content development available through our website and social media outlets.
Seasonality
Our
business is not subject to seasonality.
Research
and Development
We
continue to invest and develop our capabilities in research and development. In addition to core software code, we have continued to
enhance our capabilities in user experience and design, which we believe benefits our product lines and further supports customer adoption.
We continue to increase the frequency, quality, and feature set of our products for our customers and to adopt advanced development,
quality assurance and deployment methodologies.
Intellectual
Property
Our
commercial success depends in part on our ability to obtain and maintain intellectual property protection for our products and services
and our brands, to prevent others from infringing, misappropriating, or otherwise violating our intellectual property rights, to defend
and enforce our intellectual property rights, and to operate without infringing, misappropriating, or otherwise violating valid and enforceable
intellectual property rights of others. We actively seek to protect intellectual property that we believe is important to our business,
which includes maintaining issued patents that we believe cover our products and services or features of the same, and pursuing new patents
through patent applications filed with the United States Patent and Trademark Office (the “USPTO”) for processes or
other inventions that are commercially or strategically important to developing and maximizing our value. We seek to protect the confidentiality
of trade secrets that may be important to our existing businesses or to developing and exploiting new opportunities. We take steps to
build and maintain the integrity of our brands, for example, with trademarks and service marks. We rely on a strategy that combines the
use of patents, trade secrets, and trademarks, know-how, and license agreements, as well as other intellectual property laws, employment
agreements imposing confidentiality and invention assignment obligations, and other contractual protections to establish and protect
our intellectual property rights.
9
Patents
We
own patents in several areas of IT technology capabilities. We continue to evaluate new capabilities for advanced protection as they
are built within our R&D and security posture management efforts. We also protect our IP during development with any partners - sales,
development, processes and support efforts. For new innovations, we intend to seek patent protection either to exclude others from practicing
its inventions or to leverage the patent rights for licensing/cross-licensing, whichever may be most appropriate, to further the interests
of the business.
Number
Title
Application
Date
Grant
Date
Expire
Date
US
8,347,313
Method
and apparatus for automating organization of processes
2009-09-2022
2013-01-01
2025-09-11
US
8,752,069B1
Virtual
process collaboration
2012-12-17
2014-06-10
2024-05-21
US
9,390,275B1
System
and method for controlling hard drive data change
2015-01-27
2016-07-12
2035-01-27
2021-0011807A1
Methods
and systems for recognizing unintended file system changes
2020-07-08
Pending
2021-0012002A1
Methods
and systems for recognizing unintended file system changes
2020-07-08
2023-10-10
2041-04-27
US
10,482,243
Multi-threat
analyzer array system and method of use
Feb
27, 2017
Nov
19, 2019
2039
US
16,522,145
Phishing
detection system and method of use
2019-07-25
2022-10-25
2040-08-30
US
11,524,535
Device,
method and system for detecting unwanted conversational media session
2006-09-21
2010-12-07
2029-10-07
US
12,938,191
Device,
method and system for detecting unwanted conversational media session
2010-11-02
2012-05-29
2026-09-21
US
12,938,256
Device,
method and system for detecting unwanted conversational media session
2010-11-02
2012-05-29
2026-09-21
US
12,938,225
Device,
method and system for detecting unwanted conversational media session
2010-11-02
2012-06-05
2026-09-21
EP
19,187,516
PHISHING
DETECTION SYSTEM AND METHOD OF USE
2019-07-25
2022-10-25
2040-08-30
US
17,474,121
Phishing
detection system and method of use
2021-09-14
Pending
IL
268,279
PHISHING
DETECTION SYSTEM AND METHOD OF USE
2019-07-25
2023-11-20
US
8,347,313B2
Method
and apparatus for automating organization of processes
2009-09-22
2013-01-01
2025-09-11
US
8,752,069
Virtual
process collaboration
2012-12-17
2014-06-10
2024-05-21
US
8,347,313
Method
and apparatus for automating organization of processes
2009-09-22
2013-01-01
2025-09-11
US
20,100,169,888A1
Virtual
process collaboration
2009-09-22
2010-07-01
2025-09-11
US
6,330,590B1
Preventing
delivery of unwanted bulk e-mail
1999-01-05
2001-12-11
2019-01-05
US
11,524,535
Device,
method and system for detecting unwanted conversational media session
2006-09-21
2010-12-07
2029-10-07
US
12,938,191
Device,
method and system for detecting unwanted conversational media session
2010-11-02
2011-08-02
2026-09-21
US
8,347,313B2
Method
and apparatus for automating organization of processes
2009-09-22
2013-01-01
2025-09-11
US
8,752,069
Virtual
process collaboration
2012-12-17
2014-06-10
2024-05-21
US
8,347,313
Method
and apparatus for automating organization of processes
2009-09-22
2013-01-01
2025-09-11
US
20,100,169,888
Virtual
process collaboration
2009-09-22
2010-07-01
2025-09-11
EP19,187,516.0
PHISHING
DETECTION SYSTEM AND METHOD
2019-07-22
Being
transferred
Application No. 18/430,490
SYSTEMS AND METHODS FOR ANALYZING CYBER RISK OF CONNECTED ENTITIES
Application No. 18/781,708
co-patent of high-speed filtering (royalty-free, perpetual rights)
Trade
Secrets
We
also rely on trade secrets relating to our product and technology, and we maintain the confidentiality of such proprietary information
to protect aspects of our business that are not amenable to, or that we do not consider appropriate for, patent protection. We seek to
protect our trade secrets and know-how by entering into confidentiality and invention assignment agreements with employees, contractors,
consultants, suppliers, customers, and other third parties, who have access to such information. These agreements generally provide that
all confidential information concerning our business or financial affairs developed or made known to the individual during the course
of the individual’s relationship with us are to be kept confidential and not disclosed to third parties except in specific circumstances.
10
Trademarks
Our
trademark portfolio is designed to protect the brands of our products and services and any future products and services. As of
January 1, 2025, we own and presently intend to maintain 10 United States trademark registrations for word marks and logos including
for “DATA443”, and “ALL THINGS DATA SECURITY”, “CLASSIDOCS”, “DATAEXPRESS”,
“ARALOC”, “FILEFACETS”, “ENTERPRISE ID”, “ARCMAIL” , “DATAHOUND”,
“CYREN” and “TacitRed” in the USA and Europe.
We
also make use of, manage, and otherwise enforce the use of several graphical implementations of our service marks in various capacities,
including on our website, and with direct marketing and our product lines. These are also managed as part of our normal IP management
processes.
For
more information regarding the risks related to our intellectual property, please see “Risk Factors—Failure to protect
our proprietary technology and intellectual property rights could substantially harm our business.”
Competition
The
industry in which we compete is highly competitive. Many companies offer similar products and services for data security. We may be at
a substantial disadvantage to our competitors, who have more capital than we do to carry out operations and marketing efforts. We hope
to maintain our competitive advantage by offering quality at a competitive price and utilizing our management team’s experience,
knowledge, and expertise.
We
will face competition from more established companies that have competitive advantages, such as greater name recognition, larger sales,
marketing, research and acquisition resources, access to larger customer bases and channel partners, a longer operating history and lower
labor and development costs, which may enable them to respond more quickly to new or emerging technologies and changes in customer requirements
or devote greater resources to the development, promotion, and sale of their products than we do. Increased competition could result
in us failing to attract customers or maintain them. It could also lead to price cuts, alternative pricing structures, or the introduction
of products available for free or a nominal price, reduced gross margins, longer sales cycles, and loss of market share. If we are unable
to compete successfully against current and future competitors, our business and financial condition may be harmed.
Employees
As
of April 15,2026, we had 13 full-time employees, 2 part-time employee, and 5 independent contractors. We have not experienced any work
stoppages, and we consider our relations with our employees to be good. We believe that we will be successful in attracting experienced
and capable personnel. Our employees are not represented by any labor union.
Government
regulation
We
are subject to the laws and regulations of the jurisdictions in which we operate, which may include business licensing requirements,
income taxes and payroll taxes. In general, the development and operation of our business are not subject to special regulatory and/or
supervisory requirements.
Implications
of Being an Emerging Growth Company
We
qualify as an “emerging growth company” as defined in the Jumpstart Our Business Startups Act of 2012, or the “JOBS
Act.” An emerging growth company may take advantage of certain reduced disclosure and other requirements that are otherwise generally
applicable to public companies. As a result, the information that we provide to stockholders may be different than the information you
may receive from other public companies in which you hold equity. For example, as long as we are an emerging growth company:
●
we
are not required to engage an auditor to report on our internal control over financial reporting pursuant to Section 404(b) of the
Sarbanes-Oxley Act of 2002, or the Sarbanes-Oxley Act;
●
we
are not required to comply with any requirement that may be adopted by the Public Company Accounting Oversight Board, or the PCAOB,
regarding mandatory audit firm rotation or a supplement to the auditor’s report providing additional information about the
audit and the financial statements (i.e., an auditor discussion and analysis);
●
we
are not required to submit certain executive compensation matters to stockholder advisory votes, such as “say-on-pay,”
“say-on-frequency” and “say-on-golden parachutes”; and
●
we
are not required to comply with certain disclosure requirements related to executive compensation, such as the requirement to disclose
the correlation between executive compensation and performance and the requirement to present a comparison of our Chief Executive
Officer’s compensation to our median employee compensation.
11
We
may take advantage of these reduced disclosure and other requirements until the last day of our fiscal year following the fifth anniversary
of the completion of our IPO, or such earlier time that we are no longer an emerging growth company. For example, if certain events occur
before the end of such five-year period, including if we have more than $1.07 billion in annual revenue, have more than $700 million
in market value of our common stock held by non-affiliates, or issue more than $1.0 billion of non-convertible debt over a three-year
period, we will cease to be an emerging growth company.
As
mentioned above, the JOBS Act permits us, as an emerging growth company, to take advantage of an extended transition period to comply
with new or revised accounting standards applicable to public companies. We have elected not to opt out of the extended transition period
which means that when an accounting standard is issued or revised, and it has different application dates for public or private companies,
as an emerging growth company, we can adopt the new or revised standard at the time private companies adopt the new or revised standard.
This may make it difficult or impossible because of the potential differences in accounting standards used to compare our financial statements
with the financial statements of a public company that is not an emerging growth company, or the financial statements of an emerging
growth company that has opted out of using the extended transition period.
Recent
Developments
Amendment
and Restatement of Articles of Incorporation
In
connection with our plans to list our common stock on Nasdaq, our board of directors reviewed and evaluated our existing corporate governance
documents, including our Amended and Restated Articles of Incorporation, and determined that an updated certificate of incorporation
(the “Second A&R Certificate of Incorporation”) is advisable to clarify and modernize our governance documents and more
closely align our governance with the current provisions of the Nevada Revised Statutes. Our board of directors believes that the Second
A&R Charter also provides a governance structure that is more appropriate for a corporation with a class of shares listed on Nasdaq.
On December 22, 2023 our board of directors approved, and recommended the approval by our stockholders, the Second A&R Certificate
of Incorporation, and on the same date one stockholder holding the majority of the voting power of our common stock approved the Second
A&R Certificate of Incorporation in lieu of a meeting of stockholders. The Second A&R Certificate of Incorporation became effective
on January 26, 2024. A form of the Second A&R Certificate of Incorporation is incorporated by reference as Exhibit 3.2 hereto.
12
Amendment
and Restatement of Bylaws
In
connection with our plans to list our common stock on Nasdaq, our board of directors reviewed and evaluated our existing corporate governance
documents, including our Bylaws and determined that updated Bylaws (the “New Bylaws”) are advisable to clarify and modernize
our governance documents and more closely align our governance with the current provisions of the Nevada Revised Statutes. Our board
of directors believes that the New Bylaws also provide a governance structure that is more appropriate for a corporation with a class
of shares listed on Nasdaq than our Current Bylaws. On December 22, 2023 our board of directors approved the New Bylaws, and the New
Bylaws became effective on January 25, 2024. A form of the New Bylaws is incorporated by reference as Exhibit 3.7 hereto.
Amendment
to Certificate of Designation of Series A Preferred Stock
On
December 20, 2023, we amended our Certificate of Designation of Series A Convertible Preferred Stock (“Series A Stock”)
in order (i) to add a beneficial ownership limitation to the Series A Stock, such that a holder of Series A Stock may not convert such
stock into common stock to the extent that the holder would beneficially own more than 9.99% of the common stock outstanding immediately
after giving effect to the conversion of Series A Stock and (ii) to revert the conversion ratio of our Series A Stock to its pre-Reverse
Stock Split conversion ratio of 1,000 shares of common stock, for each one share of Series A Stock. The foregoing is a summary only and
is qualified in its entirety by the full text of the amendment, the form of which is incorporated by reference as Exhibit 3.5 hereto.
Approval
and Adoption of Data443 Risk Mitigation, Inc. 2023 Equity Incentive Plan
On
December 22, 2023 our board of directors approved, and recommended the approval by our stockholders, our 2023 Equity Incentive Plan (the
“2023 Plan”) and on the same date, one stockholder holding the majority of the voting power of our common stock approved
the 2023 Plan in lieu of a meeting of stockholders. The 2023 Plan became effective on January 22, 2024. The following is a summary of
the material features of the 2023 Plan. The following summary of the 2023 Plan is qualified in its entirety by the full text of the 2023
Plan, the form of which is incorporated by reference as Exhibit 10.43 hereto.
Purpose
The
purpose of the 2023 Plan is to enhance our ability to attract, retain and motivate persons who make (or are expected to make) important
contributions to our company by providing these individuals with equity ownership opportunities and/or equity-linked compensatory opportunities.
Eligibility
Persons
eligible to participate in the 2023 Plan will be the officers, employees, non-employee directors and consultants our company and our
subsidiaries as selected from time to time by the plan administrator in its discretion.
Administration
The
2023 Plan will be administered by the compensation committee of our board of directors, our board of directors or such other similar
committee pursuant to the terms of the 2023 Plan. The plan administrator, which initially will be the compensation committee of our board
of directors, will have full power to select, from among the individuals eligible for awards, the individuals to whom awards will be
granted, to make any combination of awards to participants, and to determine the specific terms and conditions of each award, subject
to the provisions of the 2023 Plan. The plan administrator may delegate to one or more of our officers the authority to grant awards
to individuals who are not subject to the reporting and other provisions of Section 16 of the Exchange Act.
13
Share
Reserve
An
aggregate of 800,000 shares of Common Stock may be issued under the 2023 Plan. Shares underlying any awards under the 2023 Plan that
are forfeited, cancelled, held back to cover the exercise price or tax withholding, satisfied without the issuance of stock or otherwise
terminated (other than by exercise) will be added back to the shares available for issuance under the 2023 Plan. The payment of dividend
equivalents in cash shall not count against the share reserve.
Annual
Limitation on Awards to Non-Employee Directors
The
2023 Plan contains a limitation whereby the grant date value of all awards under the 2023 Plan and all other cash compensation paid by
the Company to any non-employee director may not exceed $250,000 in any calendar year, although the Company’s board of directors
may, in its discretion, make exceptions to the limit in extraordinary circumstances.
Types
of Awards
The
2023 Plan provides for the grant of stock options, stock appreciation rights, restricted stock, restricted stock units, dividend equivalents,
and other stock or cash based awards, or collectively, awards. Unless otherwise set forth in an individual award agreement, each award
shall vest over a two-year period, with one-half of the award vesting on the first annual anniversary of the date of grant, with the
remainder of the award vesting monthly thereafter.
Stock
Options
The
2023 Plan permits the granting of both options to purchase shares of common stock intended to qualify as incentive stock options under
Section 422 of the Code and options that do not so qualify. Options granted under the 2023 Plan will be nonqualified options if they
fail to qualify as incentive stock options or exceed the annual limit on incentive stock options. Incentive stock options may only be
granted to employees of the Company and its subsidiaries. Nonqualified options may be granted to any persons eligible to receive awards
under the 2023 Plan.
The
exercise price of each option will be determined by the plan administrator but generally may not be less than 100% of the fair market
value of the Common Stock on the date of grant or, in the case of an incentive stock option granted to a 10% stockholder, 110% of such
share’s fair market value. The term of each option will be fixed by the plan administrator and may not exceed ten years from the
date of grant (or five years for an incentive stock option granted to a 10% stockholder). The plan administrator will determine at what
time or times each option may be exercised, including the ability to accelerate the vesting of such options.
Upon
exercise of options, the exercise price must be paid in full either in cash, check, or, with the approval of the plan administrator,
by delivery (or attestation to the ownership) of shares of Common Stock that are beneficially owned by the optionee free of restrictions
or were purchased in the open market. Subject to applicable law and approval of the plan administrator, the exercise price may also be
made by means of a broker-assisted cashless exercise. In addition, the plan administrator may permit nonqualified options to be exercised
using a “net exercise” arrangement that reduces the number of shares issued to the optionee by the largest whole number of
shares with fair market value that does not exceed the aggregate exercise price.
Stock
Appreciation Rights
The
plan administrator may award stock appreciation rights subject to such conditions and restrictions as it may determine. Stock appreciation
rights entitle the recipient to shares of common stock, or cash, equal to the value of the appreciation in the Company’s stock
price over the exercise price. The exercise price generally may not be less than 100% of the fair market value of common stock on the
date of grant. The term of each stock appreciation right will be fixed by the plan administrator and may not exceed ten years from the
date of grant. The plan administrator will determine at what time or times each stock appreciation right may be exercised, including
the ability to accelerate the vesting of such stock appreciation rights.
Restricted
Stock
The
plan administrator may award restricted shares of common stock subject to such conditions and restrictions as it may determine. These
conditions and restrictions may include the achievement of certain performance goals and/or continued employment with the Company or
its subsidiaries through a specified vesting period. Unless otherwise provided in the applicable award agreement, the participant generally
will have the rights and privileges of a stockholder as to such restricted shares, including without limitation the right to vote such
restricted shares and the right to receive dividends, if applicable.
14
Restricted
Stock Units and Dividend Equivalents
The
plan administrator may award restricted stock units which represent the right to receive common stock at a future date in accordance
with the terms of such grant upon the attainment of certain conditions specified by the plan administrator. Restrictions or conditions
could include, but are not limited to, the attainment of performance goals, continuous service with the Company or its subsidiaries,
the passage of time or other restrictions or conditions. The plan administrator determines the persons to whom grants of restricted stock
units are made, the number of restricted stock units to be awarded, the time or times within which awards of restricted stock units may
be subject to forfeiture, the vesting schedule, and rights to acceleration thereof, and all other terms and conditions of the restricted
stock unit awards. The value of the restricted stock units may be paid in common stock, cash, other securities, other property, or a
combination of the foregoing, as determined by the plan administrator.
A
participant holding restricted stock units will have no voting rights as stockholders. Prior to settlement or forfeiture, restricted
stock units awarded under the 2023 Plan may, at the plan administrator’s discretion, provide for a right to dividend equivalents.
Such right entitles the holder to be credited with an amount equal to all dividends paid on one share of common stock while each restricted
stock unit is outstanding. Dividend equivalents may be converted into additional restricted stock units. Settlement of dividend equivalents
may be made in the form of cash, common stock, other securities, other property, or a combination of the foregoing. Prior to distribution,
any dividend equivalents will be subject to the same conditions and restrictions as the restricted stock units to which they attach.
Other
Stock or Cash Based Awards
Other
stock or cash based may be granted either alone, in addition to, or in tandem with, other awards granted under the 2023 Plan and/or cash
awards made outside of the 2023 Plan. The plan administrator shall have authority to determine the persons to whom and the time or times
at which such awards will be made, the amount of such awards, and all other conditions, including any dividend and/or voting rights.
Changes
in Capital Structure
The
2023 Plan requires the plan administrator to make appropriate adjustments to the number of shares of Common Stock that are subject to
the 2023 Plan, to certain limits in the 2023 Plan, and to any outstanding awards to reflect stock dividends, stock splits, extraordinary
cash dividends and similar events.
Change
in Control
Except
as set forth in an award agreement issued under the 2023 Plan, in the event of a change in control (as defined in the 2023 Plan), each
outstanding stock award (vested or unvested) will be treated as the plan administrator determines, which may include (i) the Company’s
continuation of such outstanding stock awards (if the Company is the surviving corporation); (ii) the assumption of such outstanding
stock awards by the surviving corporation or its parent; (iii) the substitution by the surviving corporation or its parent of new stock
options or other equity awards for such stock awards; (iv) the cancellation of such stock awards in exchange for a payment to the participants
equal to the excess of (A) the fair market value of the shares subject to such stock awards as of the closing date of such corporate
transaction over (B) the exercise price or purchase price paid or to be paid (if any) for the shares subject to the stock awards (which
payment may be subject to the same conditions that apply to the consideration that will be paid to holders of shares in connection with
the transaction, subject to applicable law); (v) provide that such award shall vest and, to the extent applicable, be exercisable as
to all shares covered thereby, notwithstanding anything to the contrary in the 2023 Plan or the provisions of such Award; or (vi) provide
that the award will terminate and cannot vest, be exercised or become payable after the applicable event.
The
2023 Plan provides that a stock award may be subject to additional acceleration of vesting and exercisability upon a change in control
as may be provided in the award agreement for such stock award, but in the absence of such provision, no such acceleration will occur.
Tax
Withholding
Participants
in the 2023 Plan are responsible for the payment of any federal, state or local taxes that the Company or its subsidiaries are required
by law to withhold upon the exercise of options or stock appreciation rights or vesting of other awards. The plan administrator may cause
any tax withholding obligation of the Company or its subsidiaries to be satisfied, in whole or in part, by the applicable entity withholding
from shares of Common Stock to be issued pursuant to an award a number of shares with an aggregate fair market value that would satisfy
the withholding amount due. The plan administrator may also require any tax withholding obligation of the Company or its subsidiaries
to be satisfied, in whole or in part, by an arrangement whereby a certain number of shares issued pursuant to any award are immediately
sold and proceeds from such sale are remitted to the Company or its subsidiaries in an amount that would satisfy the withholding amount
due.
15
Transferability
of Awards
The
2023 Plan generally does not allow for the transfer or assignment of awards, other than by will or by the laws of descent and distribution;
however, the plan administrator has the discretion to permit awards (other than incentive stock options) to be transferred by a participant.
Term
The
2023 Plan became effective on January 22, 2024, and unless terminated earlier, the 2023 Plan will continue in effect for a term of ten
(10) years, after which time no awards may be granted under the 2023 Plan.
Amendment
and Termination
The
Company’s board of directors and the plan administrator may each amend, suspend, or terminate the 2023 Plan and the plan administrator
may amend or cancel outstanding awards, but no such action may materially and adversely affect rights under an award without the holder’s
consent. Certain amendments to the 2023 Plan will require the approval of the Company’s stockholders. Generally, without stockholder
approval, (i) no amendment or modification of the 2023 Plan may reduce the exercise price of any stock option or stock appreciation right,
(ii) the plan administrator may not cancel any outstanding stock option or stock appreciation right where the fair market value of the
common stock underlying such stock option or stock appreciation right is less than its exercise price and replace it with a new option
or stock appreciation right, another award or cash and (iii) the plan administrator may not take any other action that is considered
a “repricing” for purposes of the stockholder approval rules of the applicable securities exchange.
All
stock awards granted under the 2023 Plan will be subject to recoupment in accordance with any clawback policy that the Company is required
to adopt pursuant to the listing standards of any national securities exchange or association on which the Company’s securities
are listed or as is otherwise required by the U.S. Dodd-Frank Wall Street Reform and Consumer Protection Act or other applicable law.
In addition, the Company’s board of directors may impose such other clawback, recovery or recoupment provisions in a stock award
agreement as the board of directors determines necessary or appropriate.
Available
Information
We
file annual reports on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K, proxy statements and other information
with the SEC. Any materials that we file with the SEC are available free of charge on the website maintained by the SEC. The Internet
address of the SEC’s website is http://www.sec.gov. We also make our reports and other information available, free of charge,
on our website at www.data443.com. Our corporate offices are located at 600 Park Offices Drive, Suite 300-4133, Durham, North Carolina
27713. Our telephone number is 919-858-6542.