You’re an analyst at a debt advisory firm. Build me a prospecting list of the public SaaS companies most vulnerable to AI that are carrying bank debt, and flag the ones whose loan structures suggest trouble is coming. Make no mistakes.
I spoke that prompt into my LLM last week, which queried a proprietary research base developed by Terrain, and had auditable results back in minutes: a ranked list of 342 US-listed SaaS companies and a detailed assessment of their AI vulnerability and credit profile. A year ago, that would have been a fantasy. Five years ago, pure science fiction.
The results were the product of a collaboration: someone else’s technical mind and creativity in shaping complex datasets, paired with my own domain expertise in credit. Producing them meant working through over 5,000 SEC filings, creating a SaaS company filter and a novel AI vulnerability framework, and reviewing roughly 100 credit agreements and amendments. Keep reading to find out how we did it.
From raw filings to a proprietary and interactive research base. Source: Terrain research base.
Vanished Into Thin Air(table)
Vulnerability is the birthplace of love, belonging, joy, courage, empathy, and creativity.
— Brené Brown
It is also, in this context, the birthplace of enterprise value destruction.
The recent news regarding Airtable has been broadly covered, so I won’t rehash the deal terms. But the transaction, and the repricing of software multiples it reflects, caught my attention. Not as a trend line, but as a real economic event: an actual buyer at an actual price, not a squiggle on a chart. Airtable carried no debt, so the markdown stopped at its equity holders. But the transaction got me thinking. Who else might be exposed? And for the companies that do carry credit, what would a repricing like this do to their ability to borrow more, to refinance what they already owe, or even to raise fresh equity at these multiples against what could be viewed as a large debt overhang?
The credit side I knew I could handle; it was the kind of work I’d been doing week after week for my Loan of the Week posts, sourcing deals out of EDGAR and reading the credit agreements behind them. I could find which public companies carried exposure, and I could read the loan documents themselves. The hard part was the vulnerability question: how do you determine, at the ground level, whether a company is genuinely exposed to AI? And harder still, how do you do it at scale? One name at a time, the way I’d always worked, it would take forever.
Picks and Shovels
Erin Riglin, the founder of Terrain, and I found each other on Substack. I’d been following his publication, The Credit Terrain, admiring what he was building, and reached out. It turned out we were mirror images: I had the credit background he lacked, and he had the technical chops I didn’t, honed over a decade teaching machines to do journalism at the Wall Street Journal and later at Applied XL, the “editorial algorithms” startup he co-founded. It was, to borrow from Casablanca, the beginning of a beautiful collaboration.
Long before the news of Airtable’s acquisition, we were already discussing a specific application focused on identifying and ranking public SaaS companies deemed vulnerable to AI threats. Erin was interested in furthering his vision of Terrain enabling the “automation of expertise,” and we were both eager to use the platform as a veritable “scoop machine” for mining EDGAR, a database that was built to store filings, not to give up trends and insights easily.
What he could do with EDGAR data went beyond anything I thought possible, and honestly, it was mind-blowing.
Get SaaS-y
His first order of business was to develop the SaaS universe, and that alone took real work. Anyone who’s spent much time in EDGAR can relate: the SIC codes aren’t much help when you’re trying to understand what a company actually does. You have to go into the filings themselves and take it from management’s own description of the business. From there, the application runs every candidate through a single scope question: is the customer paying for access to a software or data product, or for labor, hardware, or a financial outcome that software merely helps produce? Consulting shops, hardware makers, and lenders that happen to run on software get screened out, leaving a universe of genuine software and data-product businesses, each assembled from its own SEC filings.
Source: Terrain research base.
Get Vulnerable
Next up, Erin had to decide how to actually parse out this concept of vulnerability. The easy way would have been to ask whether a company uses AI, but that tells you nothing: a payroll processor and a stock-photo library both “use AI” now, and only one of them is in trouble. The question he built the framework around is narrower and more uncomfortable: can an AI agent do this company’s work without ever opening its product?
Underneath every verdict sits a single test: what is left when you remove the interface? A proprietary system of record, a regulated process, settlement rails, or a data asset that took years to build means the company is defended, because an agent still has to read from and write to it. “A workflow anyone could rebuild” means the interface was the only moat, and those are the names that screen high. Erin kept high a deliberate minority verdict; simply selling software doesn’t make you vulnerable.
Source: Terrain research base.
Get Leveraged
The credit layer was the last layer, and as Erin writes about in his post, it was anything but simple. A lot of filings will actually give you a debt maturity schedule broken out by year, so that summary view isn’t where the difficulty is. What takes work is getting insights from the filings themselves, down to the discrete instrument level, and understanding who owes whom and what’s coming due, loan by loan, note by note, bond by bond. Covenants are even more work, and to understand those, he had to read each of the credit agreements to parse out the covenants and their intricate and variable definitions. They’re diverse, and often change from deal to deal and company to company. That’s where the covenant and its definition live: how leverage or EBITDA actually gets calculated at each measurement period.
65 high AI-vulnerability companies, approximately $4.86 billion, maturities from 10-K debt footnotes. Source: Terrain research base.
You Want Answers? I’ll Give You Answers.
Remember that prompt I opened with, the one asking for a prospecting list of vulnerable SaaS companies carrying bank debt? Well, I have that answer in hand now. See below for an anonymized example.
One record, identity withheld. Figures are rounded. Source: Terrain research base.
What Comes Next
I’ll share more in the next installment of this three-part series.
Part 2 will go into more detail on the research base itself, and include additional examples of how I’m using it every day to find new information.
Part 3 is still in development, but conceptually I plan to show the fruits of my labor: results from the stories I’ve published, the engagement they’ve drawn, and the feedback from my debt advisory prospecting.
In the meantime, here are a few other questions I’ve been thinking about:
Across the whole universe, how are these companies describing the AI threat in their own risk disclosures, and whose language has quietly shifted from boilerplate to something that reads like genuine worry?
What legal and documentation structures recur across their credit agreements, and which borrowers agreed to the most unusual or aggressive terms?
How are software companies recognizing revenue, and do the ways they describe and categorize it differ from one sub-sector to the next?
Which companies introduced new AI-risk language into their filings this year that wasn’t there a year ago, and what do the specific words give away?
Where does the optimism in management’s own discussion diverge most sharply from the caution buried in the risk factors?
What are some questions you have? Reply below and let’s explore this data together.









