UK Cybersecurity Startup Ossprey Raises 2.65 Million Dollars to Stop AI-Driven Software Supply Chain Attacks
Editorial Team

London based cybersecurity startup Ossprey has raised 2.65 million dollars in pre‑seed funding, led by Osney Capital, to expand its AI powered platform for detecting malicious open source code before it reaches production environments.
The company is targeting a threat category that has grown increasingly difficult for traditional security tools to keep pace with, as engineering teams across fintech, crypto and broader technology sectors depend heavily on open source software at scale, while attackers continue finding new ways to slip malicious packages into widely used dependency ecosystems faster than conventional defenses can catch them.
Catching Threats That Signature Based Tools Miss
Most existing supply chain security tools work by checking incoming packages against databases of previously known threats and flagged signatures, an approach that works reasonably well for cataloged vulnerabilities but struggles against novel attacks that have not yet been documented anywhere. Ossprey's approach is different: rather than relying on databases of known threats, its just in time AI scanning pipeline analyzes what packages actually do at runtime, allowing it to catch malicious behavior in real time even when the specific threat has never been seen before.
The platform is built API first, with integrations spanning the command line interface, CI/CD pipelines, AI powered coding assistants, integrated development environments, software composition analysis tools and a dedicated security dashboard. That breadth of integration is intended to give engineering and security teams visibility at the exact point where a dependency gets resolved, rather than only after a compromise has already occurred and the damage has been done.
A Track Record of Catching Real‑World Attacks
According to the company, Ossprey has already detected several confirmed real world supply chain campaigns, including the Shai‑Hulud attack, the Bitwarden CLI breach and the Telnyx PyPI compromise. Those detections give the company concrete evidence to point to when making the case that behavioral, runtime based analysis can catch threats that pure signature matching would miss entirely.
Ossprey describes its mission as helping establish a new standard for open source dependency security across the UK and European technology sector, positioning its tooling as something that should sit quietly in the background of a development workflow rather than disrupting how engineers actually build software.
Built for Speed, Not Just Security
A recurring theme in how Ossprey talks about its own product is the emphasis on not slowing developers down. The company frames its positioning around the idea that security shouldn't come at the cost of innovation speed, arguing that most existing tools check every package against known threats and flagged signatures well enough for common cases, but fall short against attackers who are not submitting their malicious work to be cataloged anywhere in advance.
That focus on frictionless integration reflects a broader shift in enterprise security tooling generally, where platforms are increasingly expected to operate invisibly within existing developer workflows rather than introducing separate approval gates or manual review steps that slow down release cycles.
Part of a UK Government‑Backed Growth Pipeline
Ossprey is an alumnus of Cyber Runway, a UK government backed initiative designed to support the growth of early stage cybersecurity startups and scaleups through mentorship, funding access and other resources. That program participation has provided the company with guidance from industry experts as it built out its platform and worked to establish early customer relationships within the UK and European fintech and technology sectors.
Riding a Broader Wave of Supply Chain Security Investment
Ossprey's raise lands amid sustained investor interest in software supply chain security more broadly, a category that gained significant attention following high profile incidents like the SolarWinds attack and subsequent regulatory pushes such as software bill of materials requirements. Other companies in the space, including Ox Security, have previously raised tens of millions of dollars to address adjacent parts of the same problem, underscoring how supply chain risk has become a persistent and well funded area of enterprise cybersecurity spending.
With fresh capital in place, Ossprey's next challenge will be scaling its customer base beyond its current UK and European fintech and crypto client base while continuing to build the detection track record that differentiates behavioral analysis from the signature based tools most of the market still relies on.





