eCommerceNews US - Technology news for digital commerce decision-makers
United States
Ossprey raises USD $2.65 million for supply chain security

Ossprey raises USD $2.65 million for supply chain security

Fri, 24th Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Ossprey has raised USD $2.65 million in pre-seed funding in a round led by Episode 1 Ventures.

Osney Capital and Octopus Ventures also participated in the oversubscribed round. The UK software supply chain security company will use the funding for product development, hiring across engineering and commercial roles, and international expansion.

The raise ranks among the larger pre-seed rounds for a UK cyber security company. It comes as investors show growing interest in tools that address risks tied to AI-assisted software development and the broader use of open-source components in business software.

Ossprey focuses on detecting malicious code hidden in open-source software packages before it reaches production systems. The company argues this threat is becoming more urgent as developers rely more heavily on AI coding assistants and other automated tools that increase the volume of software being written and deployed.

Modern software development often depends on open-source libraries and packages assembled by many external contributors. Around 90% of enterprise software is now built using open-source components, according to Ossprey, creating more opportunities for attackers to introduce malware through legitimate development workflows rather than more traditional routes.

The business was founded by Nate Dunning and David Read to address that issue. Its platform continuously scans open-source packages for signs of malicious code before developers use them, aiming to reduce risk without slowing engineering teams.

Since securing the funding, Ossprey has expanded its team to seven people, broadened its platform and launched continuous public scanning across major open-source ecosystems. It has also become one of the faster organisations globally to detect newly published malicious packages, according to the company.

Dunning outlined the company's view of the market shift driven by AI tools in software development.

"Software development has fundamentally changed. AI is enabling organisations to build software faster than ever before, but it's also dramatically increasing the amount of code entering production and creating new opportunities for attackers to hide malicious software inside trusted open source packages. We founded Ossprey because existing approaches weren't designed for the pace modern engineering teams now operate at. Organisations shouldn't have to choose between shipping software quickly and building it securely. This investment allows us to continue developing technology that helps organisations build safely at AI speed while expanding our reach internationally," said Nate Dunning, Chief Executive Officer, Ossprey.

Investor interest

Backing from the three venture firms reflects a wider view that software supply chain threats remain under-addressed, particularly when malicious code is designed to resemble legitimate packages or evade tools that rely on known signatures.

Episode 1 Ventures said the rise in open-source attacks had created an opening for more behaviour-based detection methods.

"Open source software supply chain attacks have quietly exploded in scale and sophistication, yet security tools today can't tell malicious code from benign. Ossprey's detection engine catches what signature-based tools miss, stopping malicious code before it hits production. Having experienced this directly, Nate and David's rare technical depth make them uniquely equipped to set a new security gold standard," said Millan Suri, Principal, Episode 1 Ventures.

Osney Capital placed the case in the context of how heavily engineering teams depend on externally produced code.

"Every engineering team now depends on open-source code they didn't write and can't fully vouch for. Most tools check that code against a list of things already known to be bad. Ossprey looks at what the code actually does. Nate and David are the perfect team to build it," said Paul Wilkes, Partner, Osney Capital.

Octopus Ventures also pointed to the broader cyber security significance of the issue.

"Ossprey addresses one of the most pressing challenges in modern cyber security. The team's vision, technical expertise and market opportunity made this an exciting investment for us. We're looking forward to supporting Ossprey as it enters its next phase of growth and brings its technology to organisations around the world," said Kirsten Connell, Investor, First Cheque Fund, Octopus Ventures.

Growth path

Ossprey emerged from Cyber Runway, the UK cyber accelerator programme funded by the Department of Science, Innovation and Technology and hosted by Plexal. Dunning and Read took part in the Launch and Grow programmes as they established the business.

The company is building its presence across the UK, Europe and North America, targeting organisations that develop software at scale. Its pitch rests on the idea that the speed gains from AI-assisted coding must be matched by stronger checks on the third-party components entering the software supply chain.

As businesses face pressure to release software more quickly, Ossprey is positioning itself around a narrower problem than broad cyber defence: stopping harmful code from entering development environments through trusted package ecosystems. That focus has become more prominent as attackers look for ways to exploit the same open-source and automation tools that legitimate developers use every day.