Plurilock Security Inc. (PLUR) Earnings Call Transcript & Summary

August 20, 2026

TSXV CA Information Technology Software special 30 min

Earnings Call Speaker Segments

Ian Paterson

executive
#1

Good morning, and thank you for joining us. I know it is an early start for those on the West Coast, and I appreciate you being here. My name is Ian L. Paterson, and I am CEO of Plurilock Security. We're going to be covering a corporate update today on our growing defense platform, followed by a short question-and-answer session. A few notes on logistics. [Operator Instructions] I will take questions after the prepared remarks. A recording will be posted to the Investor Relations page on our website following today's presentation. One piece of housekeeping before we start. This is a business update only. Our second quarter 2026 financial results are due later this month. We're not going to be covering any details of that today, and we're not going to be taking any questions on that. I'd refer you to communications later this month. So before we get to business, I'll just draw your attention to the disclaimer on the screen and remind everybody that certain statements made on this call may be forward-looking in nature. Please take a moment to review and take a screenshot as needed. Okay. For anyone new to the story, we'll start with a quick orientation of us as a company, and then we'll get into the specifics around the growing defense platform. Plurilock Security is a cybersecurity solutions provider and systems integrator. We were founded in 2016, and we trade on the TSX Venture Exchange under the ticker PLUR and on the OTCQB under the ticker PLCKF. Last year, we generated over $60 million in revenue with increasing gross margins, driven by our growing critical services segment across our portfolio of customers, including both commercial and public sector. We maintain strong partnerships with some of the most consequential technology and cybersecurity companies in the world and are seeing strong tailwinds from the global trends of increasing defense spending, AI disruption and cyber risk. Our strategy since we went public has been easy to state, and that is to acquire distribution and then cross-sell higher-margin products and services through it. Distribution in this context is the right or the ability to sell to customers who are, in some cases, hard to reach. And when we're talking about the public sector and government, in particular, it usually takes a special form of master service agreement called a contract vehicle. You might have the best capability in the market, but without a way for that government customer to procure through you, there's no practical way for you to get that capability into the hands of that customer. Ultimately, if you hold one of those contract vehicles, then you have a path to that customer. And in many cases, the competition is narrowed as compared to other customers who are out there. Over the years, we have announced sales to numerous U.S. federal agencies, state agencies as well as Canadian agencies and government customers. And these include organizations such as the U.S. Navy, Department of Energy, Department of Transportation, Federal Trade Commission in California. This has included the California state legislature in Canada, organizations like Health Canada, Treasury Board, Privy Council, D&D, et cetera. Now we'll get on to why we are here this morning. So 2 things happened over the last couple of months that are worth touching on and explaining. The first is that on July 20, we announced that our Aurora subsidiary, our U.S. operating subsidiary, had been notified of its selection as an awardee under NASA's SEWP VI contract. Then on August 6, we announced that our Canadian operating subsidiary, Integra, had been selected as a contract holder under the NATO Communications and Information Agency's Cybersecurity Dynamic Marketplace Lot 1, also known as the CSDM contract. I'll call that agency the NCIA agency for the rest of the call. Both of these wins are contract vehicles. So I want to cover a couple of things this morning. First is a reminder of that -- of our ultimate strategy, how our contract vehicles fit into that strategy and why we are now a platform for both United States, Canadian and NATO [ reach, ] which is both hard to assemble and highly valuable both to us as well as prospective other partners out there in the industry. So first, we'll cover SEWP, which is NASA's Solution for Enterprise-Wide Procurement program. The SEWP vehicle, S-E-W-P, is what's known as a government-wide acquisition contract, which means agencies across the U.S. federal government can buy through it, not just NASA. NASA happens to be the agency that is administrating that contract. However, the SEWP contract is a GWAC, a government-wide acquisition contract. So our U.S. operating subsidiary, Aurora, is one of a limited group of prequalified SEWP contractors, and it gives us a direct sales path to both civilian, defense and intelligence agencies. And our current SEWP contract or what's known as SEWP V, we have been operating for a number of years, which is set to conclude towards the end of this year in advance of SEWP VI, the new win going into effect. The way that contract vehicles work and the way that SEWP in particular works is that as a prequalified vendor, as a holder of the SEWP contract, we are eligible to compete for individual orders, sometimes called task orders. The way this works is an agency -- so a government customer will identify some requirements. They'll issue a request. Sometimes it's an RFI, request for information or an RFQ, request for quote. They'll send that to the prequalified holders who will then respond and ultimately, somebody will usually win that piece of business. We have been operating this vehicle, as I said, for a number of years. And if you look back at some of our press releases over the last few years, you'll see references to the SEWP vehicle and orders such as the software order with the U.S. Department of Defense Agency back in March. This is what it looks like in terms of the vehicle actually turning into task orders that then turn into revenue. So again, we have successfully been operating the SEWP V contract. We have been named a winner under the SEWP VI, which is the successor contract. And the details of that SEWP VI contract are as follows: SEWP VI as posted on NASA's site is a 10-year indefinite quantity, indefinite quantity -- excuse me, 10-year indefinite delivery indefinite quantity vehicle or what's known in the industry as an IDIQ. It has an aggregate program ceiling of USD 60 billion. So that number is the program ceiling for the program. It will be shared across a group of contract holders, which will include us as one of them over that 10-year program. And effectively, what that means is that there's a significant amount of budget that has been allocated to the program, and it gives the contract holders the ability to compete for business in that program itself. The specific value of orders are ultimately then -- it is up to the individual task orders in terms of how much those task orders are worth. So that's the SEWP V and SEWP VI contract. Again, we are very excited about being named as a SEWP VI winner. I'll turn now to the NATO contract. This is a new contract, both for us as well as for NATO. So unlike the SEWP program, which was a successor, SEWP VI succeeding SEWP V, the NATO contract is a brand-new vehicle. And our Canadian operating subsidiary, Integra has been selected as one of the winners under those contracts. For the CSDM contract, it is a 5-year multi-award IDIQ framework covering 8 functional categories across cybersecurity. Similar to SEWP VI and SEWP V, this contract allows us to bid on individual task orders, which will get issued by the NCIA agency and then order values and revenue are determined ultimately by those task orders. So here's why I think these are an underappreciated component of the company. And that is really how difficult and competitive it is to get these contracts. So the way that we were successful in winning these contract vehicles is through working through a competitive process. So these competitions for contract vehicles are competitive. They are not always open. And in our experience, a company that is not positioned to compete for when one of these competitions runs is very limited in its ability to get it. And in many cases, they have to wait until the next cycle. That cycle might be years away. So these contracts don't come around all the time, and you have to be there with the right proposal in order to win them. Now eligibility is a second barrier. So in addition to the contract competitions being only open and closed for a certain period of time, you have to be eligible in order to win. Now in a lot of cases, these contract vehicles will ask for things like past performance, which means the company's prior experience working with a similar contract vehicle and having success in terms of delivering products and services to those customers. So you need both past performance and the window to be open in order to compete successfully. Third is that certification, just as a general statement, is usually a requirement and that burden has been growing steadily. So our Aurora subsidiary achieved CMMC Level 1 for the U.S. Department of Defense back in 2024. We also hold SOC 2, along with other prequalifications that, in many cases, are either required or can assist in showing that you are a strong bidder when you're going out and trying to approach these -- or compete, I should say, for these contracts. In Canada, there's also a new program called the CPCSC, which stands for the Canadian Program for Cyber Security Certification, which sets out mandatory controls for defense suppliers with enforcement beginning later this year. So these are things that are difficult to get. In some cases, in the case of past performance, as an example, you have to have experience of having done similar work. So it's difficult as a new entrant to be able to compete successfully and get access to these programs. But like we've talked about, if you do have access to them, in the case of the CSDM contract, it's a 5-year contract. And in the case of SEWP VI, it's a 10-year contract, which really provides a great competitive moat for us to be able to continue executing. So the last piece there is just time in market. In our case, Integra, our operating subsidiary, has actually been in the Canadian public sector since 1985. And Aurora has a multi-decade work experience as well. These were 2 companies that we had acquired in 2021 and 2022. And so it gives us really more than 3 decades of delivery history, which has been very, very useful for us in winning these contract vehicles. So if you put all this together, you have a reason that a company like us is able to punch above its weight. And it took us 2 acquisitions more than a decade to get to where we are. And the barrier for these types of contract vehicles is high. And so that means that these contract vehicles are prized, and we actually hear regularly from other operating businesses who are interested in them. Ultimately, if I think about what these things mean, if we add up all of these contract vehicles together, Plurilock is now a platform with the ability to reach U.S. federal, civilian defense intelligence customers, Canadian federal government -- Canadian federal customers and now NATO customers. And so for a company of our size, having all 3 is quite unusual. I'll talk a little bit about the types of revenue because with these contract vehicles, we can be selling multiple different types of things. So as a solutions provider and systems integrator, our revenue is composed of 3 segments: hardware, software and services. And I'll give you some examples of each one. So towards the end of June this year, we announced some data center sales to U.S. federal and state customers totaling $1.1 million. Inside that number were some high-performance server components for a U.S. DoD agency and data center infrastructure and support service for a federal -- for a U.S. federal agency. We've also delivered network infrastructure for the Department of Energy. Earlier this spring in May on the commercial side, we announced on-site engineering for a national consumer storage company around their data center modernization. And that is both people as well as hardware and providing integration. So effectively, what this shows is that we are able to deliver whole solutions, so not just one piece of hardware, not just one piece of software, not just one service, but we're really delivering multiple elements, which for our customers, they appreciate being able to go and do kind of a one-stop shop, if you will. This also speaks to the growth that we're seeing supporting some of the tailwinds like data centers, which we're seeing certainly as a key component for some of the new AI boom that we're experiencing. So we talked about hardware. We also sell software and licensing. So some examples of that this year. Earlier, we had a state legislature data center where we supplied endpoint detection response software, data security application control as well for a DoD agency, we provided e-mail solutions on a 5-year agreement. In Canada, we did some work with Health Canada as well as the Canadian law enforcement agency around virtualization, cloud platform licensing. And then for a state-level law enforcement agency, intrusion prevention, detection. And then in February, we also announced a data security licensing agreement inside a national security-focused government agency. So we've talked about hardware, and I've just given you some examples of software capabilities. Last and not least, and certainly, this is where we've really been focusing our time is around services. So we call our team critical services, although it shows up on our financial statements under the line item professional services. So in May, we announced critical services contracts totaling $1.3 million and $1.1 million. The work inside those contracts included engineering support for a customer's security operations center, enhancements to a data loss prevention program, some security change management, AI operations support and security assessment work. Then slightly earlier than that in February, we renewed and expanded engagements covering insider risk, security information and event management operations and some security comms programs. We also delivered some firewall security and automation for a Canadian company through one of our alliance partners. And as well, we -- with our critical services team, we are running readiness programs for certification regimes similar to what I mentioned before. So CMMC in the United States and CPCSC in Canada. And I'll just take a moment to touch on both of those because we are seeing with this large defense tailwind, more and more companies are looking for CMMC help in the United States and CPCSC help in Canada. Both of these are areas that we work with customers on, and we're certainly looking for more to be working with. So maybe one last point, and it follows from what we just talked about, which is that the assembling of this platform has taken time. It's been hard to do. And it's valuable not only just to us, but also to other technology companies who might not have similar experience past performance credentials or qualifications in order to win these contracts themselves. So when we announced our SEWP V extension in June, we said that technology vendors, systems integrators and partners that lack their own procurement vehicles can partner with us to reach U.S. federal clients. That invitation is open, and it's one of the reasons that the vehicles matter beyond just the orders we win for ourselves, but also for partners. And we can see a live example of a partnership from last year, where we announced in July that Forcepoint named Plurilock a certified services partner, which puts our critical services team in front of Forcepoint's own customers and implementation. And this is a great example of a partnership that can run in both directions. not only us with our procurement vehicles, but also Plurilock being recognized as a key provider of capability in, as I say, running in both directions. So why does this matter now more than it did before? And the answer is that the set of companies that need a route into government keeps growing, and it's looking a lot less and less traditional. So defense and security buyers are procuring categories of technology that barely existed as a procurement line item a decade ago or even 5 years ago. So think about autonomous systems, artificial intelligence, quantum capabilities, robotics. Many of the companies building in those categories are young. They might have the tech, but they don't have the vehicle. They don't have the past performance. They don't have the certifications. And this is really where partners like Plurilock can provide a lot of value. So let me close with a summary, and then we will get into questions. So here is what we are working with against that backdrop. A 10-year U.S. federal purchasing vehicle where we have been notified of our selection as an awardee, 5-year NATO framework, an established Canadian federal position and a services practice with growing margins. On top of that, a platform other tech companies have reason to want access to. Now none of this is guarantees of orders, and none of this is a guarantee that we'll be able to win those orders and convert to revenue. However, we have a really good track record. And while the work is in front of us, it is work that we're excited to go after. So with that, I would encourage if you have questions do use the Q&A function. So it should be at the bottom of your screen. I've got a couple of questions that have already popped up, and happy to take them as they come in.

Ian Paterson

executive
#2

So the first question is -- I'll read off the question first here. So considering your list of partners, is Plurilock categorized as an MSP, an MSSP or a reseller? So that's a great question. And so the reality is that Plurilock is a solutions provider. In some cases, we might provide a piece of hardware or software. And so from that perspective, we would be reselling that technology. In other cases, we might be providing a one-off service through our critical services practice. And so from that perspective, you can think of us as a systems integrator or it might be the case that we're providing a managed capability. And so that would be more of an MSSP. So the answer is it depends on the situation. Broadly speaking, we consider ourselves a systems integrator because it usually encompasses both resell onetime services and managed services. So it kind of bridges all those different components. And I think the other thing that I would note is that as a company, we have been growing our services practice as a percentage of revenue. So if you look at critical services revenue from last year and you compare that to where it was a couple of years prior, you'll note that the services revenue has really increased as a percentage of revenue. So short answer, solutions provider and systems integrator, it can encompass multiple items. So the next question is, what other industries are you seeing potential collaboration opportunities given the channels and infrastructure you have across Canada, the U.S. and NATO? This is a great question. So we generally are a cybersecurity and cyber defense company. What that means, though, is that really every piece of technology has chips in it these days. And so our ability to create value for customers is actually quite broad. If I think about some newer emerging technologies that might not have existed 5, 10 years ago, I think about things like quantum. I also think about the growth in autonomous vehicles, so UAS, so unmanned autonomous vehicles has also been a big growth. Cyber itself really applies to every segment of IT. And so you don't really have to go very far to find a cyber use case within most technology products. So I would just summarize that to say emerging technology, quantum AI drones as probably being the 3 that you might not immediately think about, but those certainly have a huge cyber application, particularly for where the world is today and where the world appears to be going. So a follow-up question, are you doing any work in the private sector? Yes. So that's a great question. So the presentation today has really focused on the public sector contract vehicles. Depending on the year, the percentage of revenue from the public sector to the private has been around 50-50, goes up and down a little bit depending on the year. So we absolutely do a lot of work in the private sector. I would say that the 3 main verticals within the private sector include financial services, health care and industrials. Within industrials, this includes things like semiconductors, aerospace and defense. Usually within the industrial segment, it's folks who have both IT technology as well as OT technology or what's called operational technology. So certainly, we do a lot of work there, and we tend to skew more towards larger organizations. So think Global 2000 type of organizations, enterprises or organizations that have a disproportionate amount of risk from cybersecurity. So again, that's where we tend to focus. If you were to look through our corporate presentation within the first couple of slides, you'll see some examples of the types of industries, types of customers. And then certainly, you can refer back to previous press releases where we've talked about not specific names of clients, which is a lot of times difficult in the cybersecurity industry to name. But certainly, we talk about kind of the industry that those customers are operating in. So the next question here is SEWP V runs out in September with options through to April of next year. Is there a gap between when SEWP V ends and when SEWP VI starts? So great question. So the answer is we don't believe there's going to be any gap. The good news is that we are holders of both contracts. So our current SEWP V contract as well as SEWP VI. There have been a number of announcements in regards to SEWP V being extended. My belief is the government doesn't want there to be any gaps. And so because we have both SEWP V as well as SEWP VI, we believe that we're in a good spot, and it's ultimately up to NASA and the government to transition that program. I think we have time for maybe 1 or 2 more questions. So I'll try and get to these. So question is, you are a small company, how do you deliver against a NATO framework? So great question. I mean, a couple of things that I would say. First is that, again, because of our past performance that I had listed, we're in a really good position to be able to bring experience to NATO. We've also spent a good amount of time both with the -- with our NATO reps in Canada. I was also in Brussels, I think, last year at NATO headquarters. So we're -- we feel that we're in a good position. I also think just macro -- from a macro perspective, Canada has really tried to raise its standing as increasing Canada's own investment in defense. And ultimately, its NATO 2% of GDP commitment. So I think that both Canada is well positioned. I think that we are positioned well in Canada. And we have the benefit of being able to leverage a lot of the experience that we've done internationally to be able to bring to bear. So I think that we're in a good spot, and I think that there's great opportunity for us to pursue. So I think that there's probably time for one more question. And if you have a question and you weren't able to get it answered, happy to take questions via e-mail as well. So the last question here that I have is, do you have a partnership program with others, other consultants, I think, is the question. So the short answer is yes. I mean, we do have -- cybersecurity is a team sport. And so we do have a couple of different partnership programs. We've talked a little bit about some of the vendors that we work with, so companies like CrowdStrike and Forcepoint. We also have alliance partners who are actually bringing our critical services team into their customers. And then we also work with other consultants as well. So the short answer is yes. Details can be found further on the Plurilock.com website as well as through conversation with some of our business development folks. So thank you very much for joining the session today. As I said, if we didn't get to your question or something comes up afterwards, please reach out through the Investor Relations page on our website. We'll be glad to answer those. And thank you for joining this morning, and thank you for following our story. It took us multiple years, a couple of acquisitions to build a platform to be able to reach government buyers across the United States, Canada and now NATO. The barriers that made it slow for us to do are the same ones that make it hard for others to copy. We're just getting started here, and our job now is to convert that into dollars at the end of the day. So thank you for your time, and we will talk to you soon. Bye-bye.

This call discussed

For developers and AI pipelines

Programmatic access to Plurilock Security Inc. earnings transcripts and 253,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.