UK AI security firm Ossprey raises £2m to fight bad code
TL;DR:
- London-based Ossprey has raised £2m in an oversubscribed pre-seed round to secure software supply chains against malicious code.
- The company says it is among the top three pre-seed raises for a UK cyber firm, led by Episode 1 Ventures with Osney Capital and Octopus Ventures.
- Its pitch targets a risk amplified by AI: far more code entering production, and more places for attackers to hide.
Ossprey, a UK software supply chain security company, has secured £2m in pre-seed funding to scale a platform that scans open-source packages for malicious code before it reaches developers. The raise, one of the larger UK cyber pre-seeds on record, will fund product development, hiring and international expansion.
Securing code at AI speed
The company’s thesis is that AI has changed the shape of the problem. “AI is enabling organisations to build software faster than ever before, but it’s also dramatically increasing the amount of code entering production,” said chief executive Nate Dunning, adding that attackers are increasingly hiding malware inside trusted open-source packages. With around 90% of enterprise software built on open-source components, a single poisoned package can slip through legitimate workflows rather than obvious attack routes.
That risk grows as AI coding assistants and “vibe coding” push more code through faster. Ossprey continuously scans major open-source ecosystems and claims to be among the fastest globally at detecting newly published malicious packages. Since raising the round it has grown to a team of seven and launched public scanning across major ecosystems.
Part of a UK cyber pipeline
The raise fits a domestic pattern worth tracking. Ossprey is a graduate of Cyber Runway, the UK’s largest cyber accelerator, funded by the Department for Science, Innovation and Technology — a reminder that public support sits behind much of the country’s cyber start-up base. The problem it targets is not theoretical: UK banks are already shipping code faster than their testing can keep up, exactly the quality-and-security gap that AI-accelerated development opens. It joins a run of recent UK AI raises, from Cambridge’s CuspAI upward.
Looking forward
Pre-seed validation is early, and the market for supply-chain security is crowded. Ossprey’s edge rests on detection speed. The test is whether continuous scanning can stay ahead of attackers who are themselves using AI to generate and disguise malicious packages at scale.