Market Guide for Adversarial Exposure Validation

24 March 2026 - ID G00834008 - 22 min read
By Dhivya Poole, Mitchell Schneider,  and 1 more
Validating threat exposure, security controls and defensive readiness against attack scenarios and techniques benefits both offensive and defensive security teams. Cybersecurity leaders must understand the key use cases of adversarial exposure validation to navigate the market effectively.

Overview


Key Findings

  • Adversarial exposure validation (AEV) solutions use a variety of testing techniques that aid in reaching outcomes such as a better defensive posture, prioritized exposure awareness, and greater readiness for attack scenarios.
  • AEV continues to be a maturing technology area, and vendors are taking diverse approaches to solving customer exposure validation challenges. Some vendors specialize in only a few outcomes, whereas others cover a broader range.
  • Many organizations fall short in conducting frequent and consistent offensive security testing, largely because it is complex to orchestrate and demands specialized skill sets. As a result, essential security gaps remain unaddressed. AEV technologies are key to overcoming these challenges, as they reduce skill and complexity barriers, enabling organizations to test their defenses more effectively and proactively.
  • Recent focus on integration capabilities has created robust automated workflows, lowering barriers to entry. This automation fosters collaboration, streamlines operations and increases efficiency, while also enhancing the relevance and effectiveness of testing scenarios.

Recommendations

  • Prioritize validation outcomes, such as improved defensive posture, exposure awareness or attack scenario readiness, to guide your AEV tool selection and required capabilities.
  • Optimize cybersecurity investments by using AEV solutions to validate actual state of readiness (the ability to detect, respond and recover) against current and emerging threat scenarios, thereby supporting evidence-based decisions.
  • Conduct validation testing on a regular cadence to create trending metrics that reflect your ability to find, prioritize and remediate exposure or readiness gaps related to attack scenarios that are rapidly evolving and occurring more frequently.
  • Scale red teaming activities by using solutions that provide workbenches for building attack scenarios and help codify and automate manual validation tasks.
  • Gain greater visibility into the actual priority of exposures or attack scenarios by actively testing attack paths to determine which ones lead to real, organization-specific impact.

Strategic Planning Assumptions


  • By 2029, 60% of organizations will have adopted a structured exposure validation practice as part of CTEM, with AEV technologies and managed service providers serving as primary enablers.
  • By 2029, 30% of organizations will link AEV results to automated remediation or orchestration workflows, enabling faster treatment of validated exposures.

Market Definition


Gartner defines adversarial exposure validation (AEV) as technologies that deliver consistent, continuous and automated evidence of the feasibility of an attack. These technologies confirm how potential attack techniques would successfully exploit an organization and circumvent prevention and detection security controls. They achieve this by performing attack scenarios and modeling or measuring the outcome to prove the existence and exploitability of exposures. AEV is generally delivered as a SaaS solution with or without on-premises agents.
AEV as a market category replaces breach and attack simulation (BAS) and automated penetration testing and red teaming technology from the 2023 Gartner Hype Cycle (Hype Cycle for Security Operations, 2023). AEV technologies provide automated execution of both simplified and/or extensible attack scenarios. Results data from an executed attack scenario is used for various outcomes, such as: validating a theoretical exposure as real, automating frequent controls testing, improving preventive security posture or improving detection and response capabilities.
AEV technologies can achieve some or all of the common exposure validation outcomes by:
  • Supporting an organization’s strategic decision to shift from ad hoc testing to a more continuous exposure validation that enables continuous threat exposure management (CTEM) programs.
  • Providing blue teams with a defender’s advantage by quickly assessing how their defensive posture withstands various attack scenarios and techniques within their actual environment and level of exposure. This data is helpful for:
    • Detection stack tuning
    • Preventive posture changes
    • Exposure prioritization
    • Service provider performance validation
    • Security vendor performance scorecards
    • Other operations or controls improvements
  • Allowing offensive testing teams the ability to create custom attack scenarios and multistaged attacks designed to either validate complex threats or attempt to defeat current defensive systems. They can also leverage automation for various tasks associated with red team testing, which can increase the team’s scale and reach.

Mandatory Features

The mandatory features for this market include:
  • Performing attack scenarios for multiple threat vectors, including but not limited to: malware, email, application infrastructure, and application and identity abuses. Delivered outputs include: security-framework-aligned reporting, attack scoring, and prioritized lists of attack scenario findings with estimated impact and suggested remediation actions.
  • Providing empirical results about an organization’s defensive posture as it relates to various attack techniques and scenarios. The validation results data should greatly improve upon other more theoretical data (such as vulnerability data) and give insights into urgently needed changes.
  • Ability to scale defensive testing with vendor-supplied attack scenarios that require little to no hacking knowledge to execute and obtain results data.
  • Automated scheduling for increased testing frequency without the need for human intervention, helping to reduce errors and improve trending measurability data for exposure management and defensive operations.

Common Features

The common features for this market include:
  • A continuously updated marketplace of prebuilt attack scenarios for validation usage.
  • Customizable dashboards that allow for better workflow through common use cases.
  • Ability, either natively or through third-party integrations with tools like external attack surface management (EASM), to leverage estate information such as asset discovery, attack surface management or vulnerability management data.
  • Providing, through a SaaS model, the ability to use an externally hosted point of attack system (POA) hosted by the provider.
  • A custom attack creation workbench for advanced users that allows for the creation of validation tests, useful for purple and red teams.
  • Ability to assist in the mobilization of findings through integration with workflow, ticketing or actual defensive systems.
  • Access to threat intelligence from various sources, either through native or third-party integrations that is available for use while creating custom attack scenarios.
  • Ability to integrate with security controls via APIs or native interfaces to enhance the alignment of attack data with the defensive posture through contextualized content suggestions.
  • Recommend vendor-specific detection engineering content on systems — such as security information and event management (SIEM), extended detection and response (XDR) and endpoint detection and response (EDR) — based on actual test results that will improve defensive posture.
  • Detailed reports based on roles such as executives, asset owners, blue team owners, content engineers and testing teams. These reports should include necessary context for each role, such as industry peer baselining, vendor scorecards or attack path graphics.
  • Intelligent posture prioritization suggestions based on the use of frameworks such as MITRE’s Threat-Informed Defense.

Market Description


Solutions in the AEV market consist of technology that helps:
  • Optimize defense
  • Improve exposure awareness
  • Scale offensive-testing capabilities
Figure 1 shows the three common use cases that AEV tools support, the key capabilities that enable those use cases and the outcomes most notable for each. Table 1 provides more details on the features that support these use cases.
Figure 1: Adversarial Exposure Validation (AEV) Overview
Adversarial exposure validation enhances defense, exposure awareness, and offensive-testing capabilities. Key features include security integration, threat-informed readiness, continuous testing, and attack scenario creation. Outcomes include blue team enablement, improved validation and increased red team capabilities.

Key Use Cases Mapped to AEV Capabilities

Optimize defense
Prioritize and reduce exposures
Scale offensive-testing capabilities
Mandatory features
  • Simulate attack scenarios across multiple threat vectors (such as malware, email, application, cloud, identity, etc.).
  • Provide organization-specific defensive performance results aligned to various attack scenarios and techniques. Reporting is often expressed in terms of MITRE ATT&CK labeling.
  • Recommend new vendor-specific detection content and control tuning based on validated outcomes.
  • Run frequent, automated attack scenarios across exposed assets to confirm which exposures lead to successful adversarial actions.
  • Leverage continuously updated attack scenarios informed by threat intelligence.
  • Provide organization-specific exposure prioritization by proving attack scenario success across actual attack paths.
  • Automate emulation of newly disclosed techniques (zero-day/emerging) across the entire infrastructure.
  • Extend red team capacity by automating some penetration testing functions and executing multistep attack scenarios across the enterprise.
  • Deeper integration with asset management (CAASM), EASM, cloud inventory, and threat intel sources to enhance scenario realism.
  • Advanced automation to run multistage, chained attack scenarios to enhance scenario reach and operational efficiency.
Common features
  • Support a testing approach that measures how defensive controls stand up to known threats.
  • Leverage a continuously updated marketplace of attack scenarios that require little to no offensive security experience to operate.
  • Integrate into actual defensive systems and their current configuration.
  • Detect and validate configuration drift by baselining and alerting on security performance and changes in posture.
  • Mobilize findings by bidirectionally integrating into workflow, ticketing, patching, configuration or actual defensive systems.
  • Provide insights on exposure prioritization, root cause (attack path) and monthly trends.
  • Leverage estate information, such as asset discovery, attack surface management or vulnerability management data, either natively or through third-party integrations with tools like exposure assessment platforms (EAPs), application security posture management (ASPM).
  • Support highly distributed deployment models that enable large-scale testing across global organizations.
  • Leverage an attack creation workbench that enables advanced users to develop custom attack scenarios for offensive-testing teams.
  • Access threat intelligence from various sources, either through native or third-party integrations, to inform emulation of threat-aligned custom attack scenarios.
  • Adjust attack scenarios dynamically based on changes in the environment, new threat intelligence, or previous test results.
  • Provide detailed visualizations and reports that aid in understanding the entire attack path of a scenario, not just a single security control.
  • Support collaboration between teams via features for sharing findings, tracking remediation/mitigation progress and generating stakeholder-specific reports.
Source: Gartner (March 2026)

Market Direction


Security operations performance relies on evidence and data about how technologies, processes, service contracts and human resources are functioning. AEV solutions provide cybersecurity leaders with that data by performing a range of validation use cases. The market has evolved due to:
  • Initiatives by cybersecurity leaders to be more continuous in their threat exposure management
  • Innovations from security tool vendors in automating validation techniques
  • The growing complexity of hybrid and multicloud environments, with increased speed of delivery demanding scalable, automated validation across diverse infrastructures
  • The decreasing time between vulnerability disclosure and active exploitation, creating pressure for faster and more automated validation of exploitable exposures and attack paths
The value that these solutions bring to an organization depends on which use cases the organization wishes to embrace. For some organizations, the need to reduce threat exposure by implementing continuous threat exposure management (CTEM) is the primary justification for the AEV solution. Other organizations with larger investments in tools, teams and service partnerships seek AEV data to improve the efficiency of staff, processes and security controls. In other words, they are looking to justify, with data, why a change is necessary.
For many organizations that are dealing with the outputs of a traditional vulnerability management (VM) program, the volume of findings is high. Validation techniques allow security operations teams to reduce that volume by confirming and prioritizing findings through offensive-testing techniques. Traditionally, the process of validating a finding through a red team exercise or a penetration test has been not only high-impact but also time- and labor-intensive. AEV technologies aim to replicate and provide consistent, automated and targeted validation of prioritized exposures quickly and accurately, without a persistent need for specialized testing skill sets, enabling closed-loop mobilization.

Market Analysis


AEV solutions appeal to organizations with more mature security operations, more offensive capabilities or those in highly regulated industries. Structured and repeatable offensive capabilities offer high value, as measuring and justifying spend on offensive activities is challenging, and use cases regularly evolve. However, the latter point also helps justify the decision to acquire a technology to govern and productize testing across a diverse set of capabilities.
Organizations have the most success with AEV when justifying spend for the following initiatives:
  • Scaling the testing abilities of internal red or blue teams
  • Improving vendor management by using performance data for infrastructure security controls to better inform product renewals or vendor management strategies
  • Improving security operations performance by either initiating a CTEM program or strengthening their defensive posture via AEV’s tuning, optimization and readiness capabilities
  • Driving resource and process efficiency by validating and prioritizing exposures that pose the greatest real-world risk, ensuring remediation and mitigation efforts are focused on where they are needed the most
Ultimately, validation solutions answer key questions about top strategic initiatives for cybersecurity leaders, such as product performance, team and service-provider-contract performance, and risk relative to exposure or defensive capabilities.
An essential part of a validation solution is having a method of operation that leads to (mostly) nonrefutable results. Vendors widely use frameworks, such as MITRE’s ATT&CK and threat-informed defense (TID), as a common taxonomy to relate their findings in a simplified format across a range of devices.
AEV solutions are different from other testing solutions, such as exposure assessment platforms (EAPs) (see Magic Quadrant for Exposure Assessment Platforms). EAP solutions continuously discover, assess and prioritize exposures with context such as business, asset criticality and threats that pose the greatest risk, commonly covering all assets in an environment. In contrast, AEV solutions tend to focus on proving exploitation of high-value vulnerabilities or threat scenarios that lead to successful attacks related to their validation functions.
EAP solutions provide broader and more up-to-date information about exposures, and some can predict the likelihood and potential impact of exploitation through passive modeling. However, they can’t offer direct evidence on whether the vulnerability or other exposure is actually exploitable within an organization’s security posture/controls. They also can’t provide context on the blast radius of the exposure. By contrast, AEV solutions’ validation takes a “closed loop” approach to getting results.
For example, suppose an EAP solution found a system to be, in fact, exposed and vulnerable. The AEV solution could then:
  • Craft an external attack scenario that uses the vulnerability against your actual environment
  • Validate the vulnerability as it exists in your actual environment
  • Determine whether other factors, such as your security controls or teams, were effective in the defense
  • Automatically raise the exposure priority for affected assets within EAPs and communicate findings to relevant teams
  • Trigger mobilization actions such as remediation and tune detections or controls as needed
  • Retest the environment to verify that remediation/mitigation is effective
  • Continue the cycle until exposure is resolved, closing the loop by confirming that the vulnerability is no longer exploitable and updating the status in EAP
This approach helps better prioritize patching and mobilizes findings to defensive teams more quickly.

Architecture and Deployment

AEV is primarily delivered as a SaaS platform that centralizes the scheduling, execution, and reporting of attack scenarios, offering:
  • Centralized control: The SaaS console acts as a control plane for orchestrating simulations, visualizing attack paths, accessing remediation and mitigation guidance, and integrating with the broader security stack for workflow automation.
  • Point of attack (PoA): Externally hosted PoA systems for “outside-in” attack simulation and internal PoA systems for “inside-out” scenarios, ensuring coverage of both external and internal threats.
  • Attack workbench: Advanced platforms feature an attack creation workbench, enabling customization of scenarios and multistage attack chains through data ingestion, generative AI or manual scripting.
AEV platforms increasingly leverage AI to improve scalability, adaptability, and operational relevance by incorporating LLMs and AI agents within the control plane to assist with scenario selection, prioritization and interpretation of results to support decision making.
AEV platforms support flexible deployment architectures including agent-based, agentless and hybrid models:
  • Agent-based: Installs lightweight agents on endpoints and servers for simulation.
  • Agentless: Uses authenticated access or APIs or self-contained test packages to test assets without additional software installation, enabling rapid and frictionless deployment.
  • Hybrid: Combines agent-based and agentless methods to maximize coverage and flexibility across diverse environments.
AEV platforms support multiple execution environments that determine where validation occurs:
  • Digital twin: A replica of the production environment that mirrors relevant assets, identities, configurations, traffic and security controls. Digital twins enable safe execution against high‑risk or mission‑critical assets without impacting live operations.
  • Live, production environment: Validation activities are executed directly against production systems using controlled, nondisruptive techniques where operational risk is acceptable.

Pricing and Licensing

Comparing pricing from multiple AEV vendors is challenging, as many different pricing models are possible. In Gartner’s observation, the majority of the pricing models in the market are based on either:
  • The number of agents deployed
  • The assets/IP addresses being assessed (when no agent is used)
  • The number of users for use cases like phishing, user-centric or insider threat simulation
Overall pricing will likely include other pricing model factors as well, such as:
  • The size of the organization (e.g., based on the size of the network/environment or the number of endpoints/entities in the cloud)
  • The number of administrative users
  • Advanced features or testing methods (e.g., comprehensive vs. sampling methods)
Gartner recommends comparing competitive pricing by using a common means of assessment such as price per asset or price per user. You can further evaluate pricing differences by layering on a secondary factor such as advanced features.
Gartner observes that most buyers use a “crawl, walk, run” approach to purchase AEV products. That is, they control cost by limiting deployments and setting key value milestones before making further purchases.

AEV Market Drivers

Movement to CTEM

Organizations growing from traditional VM programs to CTEM should use AEV solutions to validate discovered and prioritized exposure issues (see How to Grow Vulnerability Management Into Exposure Management). Validation is a stage unique to CTEM that:
  • Provides a “filtering” component for discovered issues
  • Ratifies the authenticity of the issues and gauges their accessibility, reachability, and feasibility to the threat actors that might exploit them
  • Identifies exposure issues, such as vulnerabilities and misconfigurations, that do not directly need remediation
  • Closes the mobilization feedback loop by retesting after remediation or mitigation to ensure exposures are resolved
The continuous nature of a CTEM program necessitates frequent and consistent testing. The capability to repeat testing on a scheduled basis — running orchestrated testing playbooks and reporting findings regularly — aids in the early identification of exposures, misconfigurations, new shadow IT and even updated threat techniques.
AEV delivers validation through two levels of approaches:
Adversarial simulation: Simulation mimics a broad range of adversary tactics, techniques, and procedures (TTPs) using automated, repeatable attack scenarios to assess how security controls perform across the environment. This approach prioritizes breadth and coverage, enabling organizations to efficiently test many attack paths and identify systemic detection and prevention gaps.
Adversarial emulation: Emulation focuses on depth and realism by replicating the behaviors, sequencing, and decision‑making patterns of specific real‑world threat actors based on threat intelligence. Emulation tests how an attacker would adapt to deployed defenses and whether identified exposures can be chained and operationalized into a successful campaign.
A combination of both approaches is recommended for scalable coverage and targeted emulation of high-risk scenarios.
Not all vulnerabilities are patchable. AEV solutions provide organizations with options to mobilize remedies for validated issues. By consuming data from monitoring systems, AEV solutions can identify exploit scenarios that are successful and also invisible to SOC teams. They can increase the priority of such issues and provide treatment suggestions beyond just patching software.

Demand for Scaling Internal Red Teams

Creating in-house red teams for more intensive internalized testing continues to be a popular topic. Although interest is high, many cybersecurity leaders struggle to justify the cost of building an internal team of dedicated, highly skilled testers. Therefore, they outsource many penetration testing and red teaming functions to a third-party provider/consultant.
AEV solutions present an opportunity for cybersecurity leaders to better scale red teaming functions via technology platform features that support threat validation. Generative AI (GenAI), cybersecurity AI assistants and emerging agentic AI solutions can make red teaming operations more economical and can possibly reduce the entry-level skill set required as well.
A lot of the work performed by red teams could be characterized as developing a relationship between very large, yet different, datasets in order to find an avenue of attack. Tools like GenAI have proven to be effective at summarizing, comparing and determining meaningful connections, and predicting high-priority attack scenarios by synthesizing information from sources such as threat intelligence, exposure data, and attack scenario results. AEV tools often use frameworks, such as Lockheed Martin’s Cyber Kill Chain, to help guide content development.
Instead of relying on human effort to create testing cases, other solutions feed raw threat intelligence reports into GenAI and agentic AI orchestration engines to build attack scenarios. Solutions powered by GenAI tools can extract relevant indicators from the reports and generate content to create a testing scenario. However, solutions using GenAI tools will not be able to build business-aligned attack scenarios if they have only limited knowledge of the function and importance of different business applications.
Any such application of scaling technologies that reduces the operational overhead or skills required to build an offensive security team would evolve the AEV market.

Representative Vendors


The vendors listed in this Market Guide do not imply an exhaustive list. This section is intended to provide more understanding of the market and its offerings.

Vendor Selection

Gartner has included a range of providers in this research to ensure coverage from a geographical, vertical and capability perspective. Those included in this Market Guide:
  • Reflect Gartner observations from end-user engagements and feedback
  • Align with key use cases and capabilities
  • Vary in size and distribution to reflect the buying population
  • Offer clear, end-user and outcome-focused solutions, distinct from pure technology-driven offerings
Table 2 provides a list of representative AEV vendors. It is neither an exhaustive list nor a competitive analysis of the providers.

Representative Vendors in Adversarial Exposure Validation

Vendor
Product
AttackIQ
AttackIQ Adversarial Exposure Validation Platform
Breachlock
Breachlock Unified Platform
Cycognito
Cycognito Platform
CYBRAL
CYBRAL STORM
Cymulate
Cymulate Exposure Validation Platform
Erium
BlackNoise attack simulator
FireCompass
FireCompass Agentic AI Platform
Filigran
OpenAEV
Google Cloud
Mandiant Security Validation
Hadrian
Hadrian Platform
Horizon3.ai
NodeZero Platform
Infopercept
Invinsense Platform
Keysight
Threat Simulator
Method Security
Method Platform
NDAY Security
AttackN Platform
NetSPI
NetSPI Platform
NST Cyber
NST Assure
Pentera
Pentera Platform
Pikered
ZAIUX Evo
Picus Security
Picus Security Validation Platform
Prancer
Prancer Platform
Reveald
Epiphany Validation Engine
Ridge Security
RidgeBot
SafeBreach
SafeBreach Exposure Validation Platform
SCYTHE
SCYTHE BAS+ Platform
Skyhawk
Continuous Proactive Protection Platform
Tuskira
Tuskira Platform
watchTowr
watchTowr Platform
WATI
Cybermindr
Source: Gartner (March 2026)

Market Recommendations


AEV is a disruptive trend in the security operations markets. The following are pragmatic guidelines that cybersecurity leaders should consider before acquiring this technology.

Define Measurable Outcomes Before Starting Vendor Selection

Because AEV capabilities vary widely, AEV vendors may support some outcomes better than others. Gartner recommends that you start with one of the predefined use cases listed in Figure 1. Next, focus on the desired outcomes you wish to obtain as part of your project success criteria. Trying to reach all three outcomes at once will likely require a much greater project scope and a much longer time to succeed.

Consume AEV as Part of a PTaaS Subscription If You’re Understaffed

Penetration testing as a service (PTaaS) is an adjacent market to AEV (see Innovation Insight: Penetration Testing as a Service). Similar to AEV, PTaaS providers offer a range of testing and validation services on a more periodic basis. Some of these services include not only penetration testing but also control validation and exposure management. PTaaS is attractive to organizations that require frequent adversarial exposure validation but lack the in-house expertise to operate the toolsets.
This model provides scalability and flexibility, allowing businesses to adjust the scope and frequency of testing based on their specific needs and resources. PTaaS providers are, by definition, service providers. As such, they primarily offer their services on top of their own technology platforms and don’t require the organization to purchase an AEV tool. This business model makes PTaaS an ideal choice for organizations with limited security resources, enabling them to maintain a robust security posture without significant infrastructure investment.

Build AEV Acquisition Based on Provable Justifications

Organizations have very different reasons for allotting budget to AEV solutions.
The following are common for AEV purchase justifications:
  • Some very large organizations with sizable investments in security infrastructure protection tools base their justification solely on vendor spending validation. Their supporting data demonstrates that the selected vendor is not only needful but also performing as expected.
  • Other organizations are more concerned about the performance of their security infrastructure tools. They want a solution to provide trending data that proves their investments in defense are working as expected.
  • Some organizations are concerned about exposure due to infrequent testing or inconsistent patching. AEV solutions help drive improvement in that regard.
  • Some organizations are concerned about security gaps emerging during application development and deployment. AEV solutions can be integrated throughout the software development life cycle (SDLC) to continuously validate controls and identify vulnerabilities early, ensuring ongoing protection of applications as they evolve.
  • Organizations may have an initiative to start, or increase the performance of, an internal red team. Although AEV is not the only tool required to operate a red team, it often presents a rightsized solution for starting or moderately improving a practice.
  • Organizations may use the performance of internal or external (service provider) security operations center (SOC) members to justify AEV tools. AEV tools not only provide the technical detail of how an attack scenario worked but also highlight how internal or external SOC members responded to the simulated attack. This information is useful for:
  • Service provider evaluation and renewal
  • Training or policy modification for internal resources

Start With Defense Optimization If You’re Unsure Where to Begin

If you are unsure about which outcome is best for your organization, Gartner suggests starting with defensive optimization or the fundamentals of a blue team practice. Although having a red team sounds more appealing, it’s not for everyone, and the results are often more elusive to prove.
The premise of defensive optimization is twofold:
  • You wish to make your current investments in infrastructure security perform as best as possible.
  • You want trending data to show that your program works as expected day by day.
Having consistent testing data not only shows how well your investments are working, but also shows when they aren’t. This information can:
  • Help explain security gaps
  • Serve as the basis for expanding your budget for infrastructure security controls
  • Help tune security controls to ensure readiness to the latest attacks
  • Detail why you aren’t ready to defend against a particular attack
AEV tools don’t require advanced skill sets to operate for defensive optimization, adding to the outcome success of defensive optimization over other use cases.

Consider Open Source to Gain Visibility Into the Value of Commercial AEV Solutions

A number of open-source, AEV-like solutions are available, such as Atomic Red Team (see atomicredteam.io) and MITRE Caldera (see Caldera). If you are not sure whether an AEV solution will provide value to your organization, you can sometimes gain visibility into use cases and reporting data by testing with open source. Open-source outcomes can also help justify a business case to expand AEV through a commercial solution.
However, open-source solutions take a fair amount of time and skill to function and often produce limited results. Consider this option a last resort, if your effort to fund a commercial AEV solution lacks the evidence it needs to get started.