London-based software supply chain security startup Ossprey has raised $2.65m (£2m) in a pre-seed funding round to support its technology tackling malicious code threats.
Founded by Nate Dunning and David Read, Ossprey develops continuous scanning technology that inspects open-source software dependencies for malicious code before they enter production environments.
The platform addresses security risks linked to the rise of AI coding assistants and “vibe coding,” which significantly increase the volume of code and dependencies introduced into enterprise software pipelines.
A graduate of the UK Department for Science, Innovation and Technology’s (DSIT) Cyber Runway accelerator, Ossprey will use the capital injection to accelerate product development, grow its technical and sales teams, and support expansion across North America and Europe.
“Software development has fundamentally changed. AI is enabling organisations to build software faster than ever before, but it’s also dramatically increasing the amount of code entering production and creating new opportunities for attackers to hide malicious software inside trusted open-source packages,” said Dunning.
“We founded Ossprey because existing approaches weren’t designed for the pace modern engineering teams now operate at. Organisations shouldn’t have to choose between shipping software quickly and building it securely.”
The round was led by Episode 1 Ventures, with participation from Osney Capital and Octopus Ventures.
“Open-source software supply chain attacks have quietly exploded in scale and sophistication, yet security tools today can’t tell malicious code from benign,” said Millan Suri, principal at Episode 1.
“Ossprey’s detection engine catches what signature-based tools miss, stopping malicious code before it hits production. Having experienced this directly, Nate and David’s rare technical depth make them uniquely equipped to set a new security gold standard.”