OTC: SDCH

SideChannel, Inc.

CIK 0001022505 · Information Technology · SIC 7374 · Computer Processing & Data Preparation

Micro Revenue $7M Assets $3M as of Aug 9, 2026

SideChannel is a cybersecurity advisory services and software company. Our mission is to make cybersecurity simple and accessible for mid-market and emerging companies, a market that we believe is currently underserved. Our solutions provide effective cybersecurity risk management for our clients.… About this business →

Each report below shows a 3-bullet preview. Free accounts read 3 full reports a month — narrative summary, section diffs, and EDGAR-cited quotes.

Sign up free

Want to see a complete report first? Today's free report (NAVI 10-Q) is open in full — no account needed.

8-K Filed Aug 7, 2026 · Period ending Aug 2, 2026

Summary not yet generated.

8-K Filed Aug 3, 2026 · Period ending Jul 27, 2026

Summary not yet generated.

Partner

Trade SDCH commission-free

Open an account, get a free stock.

Sign up

Investing involves risk. Free stock terms apply.

10-Q Filed May 12, 2026 · Period ending Mar 31, 2026

Summary not yet generated.

8-K Filed May 12, 2026 · Period ending May 12, 2026

Summary not yet generated.

10-Q Filed Feb 17, 2026 · Period ending Dec 31, 2025

Summary not yet generated.

10-K Filed Dec 18, 2025 · Period ending Sep 30, 2025

Summary not yet generated.

10-K/A Filed Mar 13, 2025 · Period ending Sep 30, 2024

Summary not yet generated.

10-K Filed Dec 13, 2024 · Period ending Sep 30, 2024

Summary not yet generated.

424B3 Filed May 11, 2021

Summary not yet generated.

S-1 Filed Apr 30, 2021

Summary not yet generated.

10-Q/A Filed Feb 18, 2020 · Period ending Dec 31, 2019

Summary not yet generated.

Latest financial statements

From 10-Q filed May 12, 2026 (period ending Mar 31, 2026). SEC XBRL (companyfacts) — not generated by the model.

SEC XBRL

Consolidated Statements of Operations (Unaudited)

Description Q2 ended Mar 31, 2026 Q1 ended Dec 31, 2025
Revenue:
Total revenue / net sales 1.6 1.8
Cost of revenue / cost of sales 0.7 0.9
Gross profit 0.8 0.9
Operating expenses:
Sales and marketing 0.4 0.5
Research and development 0.2 0.2
General and administrative 0.7 0.7
Total operating expenses 1.3 1.3
Operating income (0.4) (0.4)
Other income/(expense), net 0.01 0.01
Income before income taxes (0.4) (0.4)
Income tax expense/(benefit)
Net income (0.4)
Basic earnings per share (0.10) (0.09)
Diluted earnings per share (0.10) (0.09)

Consolidated Balance Sheets (Unaudited)

Description Mar 31, 2026 Dec 31, 2025
Current assets:
Cash and equivalents 0.3 0.2
Accounts receivable, net 0.5 0.7
Prepaid expenses and other current assets 0.4 0.3
Other current assets 0.05 0.4
Total current assets 1.3 1.6
Property, plant and equipment, net 0.01 0.01
Goodwill 1.4 1.4
TOTAL ASSETS 2.6 3.0
Current liabilities:
Income taxes payable 0.01 0.01
Deferred revenue, current 0.9 0.7
Other current liabilities 0.3 0.4
Total current liabilities 1.2 1.1
Total liabilities 1.2 1.1
Shareholders' equity:
Common stock 0.01
Capital in excess of stated value 23.0 23.0
Retained earnings (deficit) (21.6) (21.1)
Total shareholders' equity 1.4 1.8
TOTAL LIABILITIES AND SHAREHOLDERS' EQUITY 2.6 3.0

Consolidated Statements of Cash Flows (Unaudited)

Description Six months ended Mar 31, 2026 Q1 ended Dec 31, 2025
Operating Activities:
Net cash from operating activities (0.9) (0.6)
Investing Activities:
Net cash from investing activities 0.1
Financing Activities:
Net increase/(decrease) in cash (0.8) (0.6)

Amounts in millions USD; EPS as reported. Line labels are presentation-friendly mappings of filer XBRL tags — not a re-audit of the full statements. Use EDGAR for interactive notes and detail. Interactive statements & notes on EDGAR ↗

About SideChannel, Inc.

Source: Item 1 (Business) from the 10-K filed December 18, 2025. Description as filed by the company with the SEC.

ITEM
1. BUSINESS

Business
Overview & Strategy

SideChannel
is a cybersecurity advisory services and software company. Our mission is to make cybersecurity simple and accessible for mid-market
and emerging companies, a market that we believe is currently underserved. Our solutions provide effective cybersecurity risk management
for our clients. We anticipate that our target customers will continue to need cost-effective security solutions. We continue to expand
our catalogue of services and solutions to address the cybersecurity needs of our customers, including virtual Chief Information Security
Officer (“vCISO”), cyber program strategy, zero trust, third-party risk management, compliance readiness, cloud security
and architecture services, privacy, threat intelligence, managed end-point security solutions, and awareness and training.

Our
Solutions

Our
efforts are focused on protecting and enabling the critical business functions of our clients and customers through comprehensive cybersecurity
programs. This specifically includes:


Deploying
Enclave, a proprietary software product simplifying the important cybersecurity tasks of segmenting and securing digital networks,
addressing the increased demand for remote worker technologies, and advancing zero trust strategies to better protect against threats such as ransomware and intrusions.


Embedding
vCISOs as a fractional resource into the leadership teams of our clients. The role of vCISOs is becoming increasingly pivotal, especially
among small and cloud-enabled companies. The flexibility and expertise offered by vCISOs make them an attractive option for companies
facing budget constraints, needing to establish a robust security posture quickly, and overseeing increasingly complex regulatory environments.

Read full description ↓


Assessing,
identifying, and mitigating cybersecurity and privacy risks through tech-enabled security engineering processes. We leverage AI-based
security operations for post-detection actions, including alert prioritization, augmented threat detection/hunting, playbook creation,
and automation of incident response processes.


Reselling
third-party cybersecurity services and software when appropriate, expanding our offerings to include a full range of cybersecurity
products and services delivered through our team of security engineers and a network of third-party service providers and value-added
resellers (VARs).

4

In
the context of SideChannel’s offerings, Enclave is well-positioned to address these challenges faced by enterprises in achieving
a zero trust environment:


Establishing
a clear scope,


Communicating
success through strategic and operational metrics, and


Anticipating
increase in staffing and costs without delays.

Enclave
simplifies crucial cybersecurity tasks such as asset inventory, vulnerability management, and microsegmentation. By integrating access
control, microsegmentation, encryption, machine identity management, and secure networking concepts into a unified solution, Enclave
provides a comprehensive solution for managing cybersecurity controls effectively. It allows IT professionals to segment enterprise networks
efficiently, allocate the right personnel to those segments, and direct traffic seamlessly. This alignment with zero trust principles
ensures that organizations can enhance their security posture and achieve measurable risk reduction.

By
combining zero trust network access with certificate management and machine identity, Enclave seamlessly creates a unified security architecture
that eliminates traditional network vulnerabilities. This integration enables IT teams to enforce precise access policies based on verified
machine identities. Certificate-based identities allow a simplified management for any certificate-based communication, while the zero
trust framework continuously validates every connection attempt. This powerful combination delivers robust security without the typical
management overhead, allowing organizations to implement sophisticated microsegmentation strategies with remarkable simplicity and minimal
resource requirements.

We
offer cybersecurity service solutions designed to address financial and espionage-driven breaches effectively, minimize end-user errors,
and ensure rapid incident response. With the increase in data transmission and connected intelligent devices through the prevalence of
Internet of Things, the scale of security risks and the attack surface are much larger. Our offerings in data security, application security,
network security, security operations, and risk management position us to meet these challenges.

Further
information about Enclave and our service offerings are available on our website (www.sidechannel.com).

Revenue
Categories

We
internally report our revenue using two categories:


vCISO
Services: This category captures the revenue from the Chief Information Security Officer services that we provide to our clients
on a “virtual” or outsourced basis. Embedded into the C-suite executive teams of our clients, our vCISOs deliver services
including assessing the cybersecurity risk profile, implementing policies and programs to mitigate risks, and managing the day-to-day
tasks to ensure compliance with the adopted cybersecurity framework. Most of our clients use our vCISO services. Engagements typically
include a fixed monthly subscription fee and exceed 12 months because of renewal options of 1, 3, 6, or 12 months.


Cybersecurity
Software and Services: This category encompasses an array of cybersecurity software and services that our clients deem necessary
to protect their digital assets, including Enclave. These augment our vCISO offering and include a full range of other cybersecurity
products and services delivered through a team of security engineers along with a network of third-party service providers and VARs.
Commercial relationships with third-party service providers and VARs provide SideChannel with additional internal capabilities to
mitigate cybersecurity risks. We earn licensing revenue from software contracts and commissions from third-party service provider
partnerships which are included in this revenue category.

5

Growth
Strategy

Our
growth strategy focuses on these three initiatives:


Increasing
adoption of Enclave: By promoting Enclave and our other cybersecurity solutions to our existing vCISO clients, we aim to deepen
our relationships and provide comprehensive, integrated security solutions. This supports the increased demand for zero trust strategies
and remote worker technologies.


Securing
new vCISO Services Clients: As organizations plan to increase security investments due to breaches and the rising complexity
of cyber threats, we aim to expand our client base by offering flexible, expert vCISO services that address budget constraints and
the need for rapid security posture establishment.


Adding
new Cybersecurity Software and Services offerings: We plan to enhance our portfolio by incorporating transformational technologies
such as AI-based security operations, data security posture management (“DSPM”), polymorphic encryption, cyber-physical system (“CPS”)
security, and application security posture management (“ASPM”). This aligns with industry trends and the anticipated incremental spend
on application and data security due to generative AI.

Industry
Standards and Compliance

Industry-standard
cybersecurity and risk management frameworks, such as the National Institute of Standards and Technology Cybersecurity Framework and Center for Internet Security Controls (“CIS”), prioritize inventory of assets and access control as top requirements for a sustainable
and compliant cybersecurity program. The first three controls in CIS version 8 call for organizations to:


Critical
Control 1: “Establish and maintain an accurate, detailed, and up-to-date inventory of all enterprise assets with the potential
to store or process data.”


Critical
Control 2: “Actively manage (inventory, track, and correct) all software (operating systems and applications) on the network
so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented
from installation or execution.”


Critical
Control 3: “Configure data access control lists based on a user’s need to know. Apply data access control lists, also
known as access permissions, to local and remote file systems, databases, and applications.”

We
built Enclave to primarily address these three extremely critical cybersecurity controls along with other controls in CIS version 8. Enclave seamlessly
combines access control, microsegmentation, encryption, and other secure networking concepts to create a comprehensive solution.
Through software, it allows IT professionals to easily segment the enterprise network, place the right staff in those segments, and
direct traffic. Unlike open, traditional models, Enclave allows for near-limitless micro-segmented networks to operate insulated
from one another.

6

Company
History

The
Company was originally incorporated in the State of Texas on June 22, 1953, as American Mortgage Company. During 1996, the Company
acquired the operations of Eden Systems, Inc. (“Eden”), which became a wholly owned subsidiary of the Company. Eden was
engaged in water treatment and the retailing of cleaning products. Eden’s operations were sold on October 1, 1997. On May 16,
1996, the Company changed its name to National Scientific Corporation. From September 30, 1997, through the year ended September 30,
2001, the company aimed its efforts in the research and development of semiconductor proprietary technology and processes and in
raising capital to fund its operations and research. Effective August 27, 2014, the Company changed its name to Cipherloc
Corporation (“Cipherloc”) after it began engaging in cybersecurity software development. The Company redomiciled and
became a Delaware corporation on September 30, 2021. A reverse merger was completed on July 1, 2022, between SCS, Inc., f.k.a.
SideChannel, Inc. and Cipherloc. The
combined entity changed its name to SideChannel, Inc., on July 5, 2022, and the acquiree is now named SCS, Inc. (“SCS”)
and for accounting purposes, is a subsidiary of the Company.

Research
and Development

Since
Enclave is a proprietary software product, we classify all our software development activities to be research and development. The success
of our software product, Enclave, depends on our ability to provide our customers with reliable, innovative features and benefits that
are delivered before, or at least no later than, our competitors. When the demands of product development exceed the capacity or knowledge
of our in-house staff, we retain temporary third-party consultants to assist us.

Our
research and development expenditures for the fiscal years ended September 30, 2025, and September 30, 2024, were $562 thousand and $546
thousand, respectively. These costs were incurred primarily to develop Enclave.

Selling
and Marketing

We
use four primary sources to identify prospective clients for our services and products including Enclave:


Digital
Marketing


Industry
Events and Conferences


Direct
Outreach


Referral
Partners

We
continue enhancing our digital marketing tactics and expanding our online presence. A growing list of referral partners recommend SideChannel
to their clients as the primary option to identify, assess, and mitigate cybersecurity risks. Certain referral partners receive a commission
upon a referral becoming a SideChannel client.

As
of September 30, 2025, we had three (3) employees dedicated to selling and marketing activities. Our selling and marketing expenditures
for the fiscal years ended September 30, 2025, and September 30, 2024, were $966 thousand and $771 thousand, respectively.

7

Competition

The
cybersecurity software and services market is highly competitive, subject to rapid change, and significantly affected by new product
introductions and other activities of market participants.

Some
of our competitors have greater financial, technical, sales, marketing, and other resources than we do. Because of these and other factors,
competitive conditions in the markets we operate in are likely to continue to intensify in the future, as participants compete for market
share. Increased competition could result in price reductions for our products and services, possibly reducing our net revenue and profit
margins and resulting in a loss of our market share, any of which would likely harm our business.

We
believe that our future results depend largely upon our ability to serve our clients and customers with the products and services described
earlier better than our competitors, and by offering new services and product enhancements, whether such product and service offerings
are developed internally or through acquisition. We also believe that we must provide product and service offerings that compete favorably
against those of our competitors with respect to ease of use, reliability, performance, range of useful features, reputation and price.

We
anticipate that we will face increasing pricing pressures from our competitors in the future. Since there are low barriers to entry into
the cybersecurity services and software markets, we believe competition in these markets will persist and intensify in the future.

Our
chief services competitors include companies such as Optiv, NCC, Coalfire, PwC, EY, Deloitte, and GuidePoint. Our primary software competitors
are companies such as Check Point, Cisco, CrowdStrike, F5 Networks, HPE, Huawei, Illumio, Juniper,
Microsoft, Netskope, Palo Alto Networks, SonicWALL, Sophos, and zScaler.

Intellectual
Property

Protective
Measures

We
believe that our intellectual property is an important and vital asset, which enables us to develop, market, and sell our products and
services and enhance our competitive position. Our intellectual property includes our proprietary business and technical know-how, inventions,
works of authorship, and confidential information. To protect our intellectual property, we rely primarily upon legal rights in trade
secrets, patents, copyrights, and trademarks, in addition to our policies and procedures, security practices, contracts, and relevant
operational measures.

We
protect the confidentiality of our proprietary information by entering into non-disclosure agreements with our employees, contractors,
and other entities with which we do business. In addition, our license agreements related to our software and proprietary information
include confidentiality terms. These agreements are generally non-transferable. We also employ access controls and associated security
measures to protect our facilities, equipment, and networks.

Patents,
Copyrights, Trademarks, and Licenses

Our
products, particularly our software and related documentation, are protected under domestic and international copyright laws and other
laws related to the protection of intellectual property and proprietary rights. Currently, we have six active patents registered with
the U.S. Patent and Trademark Office. We employ procedures to label copyrightable works with the appropriate proprietary rights notices,
and we actively enforce our rights in the United States and abroad. However, these measures may not provide us with adequate protection
from infringement, and our intellectual property rights may be challenged.

Our
SideChannel and Enclave logos are registered with the U.S. Patent and Trademark Office (“USPTO”). In the United States, we
can maintain our trademark rights and renew trademark registrations for as long as the trademarks are in use.

8

Government
Regulation

Export
Control Regulations

We
expect that all our products will be subject to U.S. export control laws and applicable foreign government import, export and/or use
requirements. The level of such control generally depends on the nature of the products in question. Often, the level of export
control is impacted by the nature of the software and cybersecurity incorporated into our products. In those countries where such
controls apply, the export of our products may require an export license or authorization. However, even if a transaction qualifies
for a license exception or the equivalent, it may still be subject to corresponding reporting requirements. For the export of some
of our products, we may be subject to various post-shipment reporting requirements. Minimal U.S. export restrictions apply to all
our products, whether or not they perform cybersecurity functions. If we become a Department of Defense prime contractor in the
future, certain registration requirements may be triggered by our sales. In addition, certain of our products and related services
may be subject to the International Traffic in Arms Regulations (ITAR) if our software or services are specifically designed or
modified for defense purposes. If we become engaged in manufacturing or exporting ITAR-controlled goods and services (even if we do
not export such items), we will be required to register with the U.S. State Department.

To
date, Export Control Regulations have had no material impact on our business.

Enhancements
to our existing products may be subject to review under the Export Administration Act to determine what export classification they will
receive. In addition, any new products that we release in the future will also be subject to such review before we can export them. The
U.S. Congress continues to discuss the correct level of export control in possible anti-terrorism legislation. Such export regulations
may be modified at any time. Modifications to these export regulations could reduce or eliminate our ability to export some or all of
our products from the United States in the future, which could put us at a disadvantage in competing with companies located outside of
the U.S. Modifications to U.S. export regulations could restrict us from exporting our existing and future products. Any such modifications
to export regulations may put us at a competitive disadvantage with respect to selling our products internationally.

Privacy
Laws

We may be subject to various international, federal and state regulations regarding the treatment and protection of personally
identifying and other regulated information. Applicable laws may include U.S. federal laws and implementing regulations, such as the
GLBA and HIPAA, as well as state and international laws and regulations, including the California Consumer Privacy Act (CCPA) and the
European Union General Data Protection Regulation (GDPR). Some of these laws have requirements on the transmittal of data from one jurisdiction
to another. In the event our systems are compromised, many of these privacy laws require that we provide notices to our customers whose
personally identifiable data may have been compromised. Additionally, if we transfer data in violation of these laws, we could be subjected
to substantial fines. To mitigate the risk of having such data compromised, we use cybersecurity, software and other security procedures
to protect our databases.

Personnel

As
of September 30, 2025, we had 23 full-time employees. We also had approximately 15 independent contractors that provide services to us.
We anticipate that we will need to increase our staffing in the foreseeable future.