Cloudsmith Secures $23 Million to Enhance Software Supply Chain Security

Cloudsmith secures significant funding to bolster software supply chain security. The Belfast-based startup aims to transform artifact management and enhance protection against vulnerabilities in open-source technology.

Image courtesy of Tech Crunch
Share:

In the ever-evolving landscape of software development, where the lure of open-source technology often clashes with the stark realities of security vulnerabilities, a beacon of hope has emerged from the verdant hills of Northern Ireland.

Cloudsmith, a Belfast-based startup, is making waves by tackling the thorny issue of software supply chain security with innovative zeal and a fresh injection of $23 million from a Series B funding round.

The software supply chain is a notoriously leaky vessel.

A staggering 81% of codebases reportedly harbor high- or critical-risk open source vulnerabilities.

These vulnerabilities can act as ticking time bombs, ready to trigger widespread calamity, as evidenced by the infamous Log4Shell exploit.

This particular flaw left millions of applications vulnerable to remote code execution hacks, exploiting weaknesses in the ubiquitous Log4j logging library.

Enter Cloudsmith, with its promise to serve as a bulwark against such threats.

Cloudsmith’s solution?

A cloud-native “artifact management platform” that aims to modernize how software packages are handled, stored, and secured.

The term “artifact” might sound like something Indiana Jones would chase, but in the tech world it refers to software packages and components that are crucial to the development process.

These artifacts are often drawn from public open-source registries, where they might change or vanish without notice, potentially leaving developers high and dry.

Cloudsmith steps in by providing mirrors of these packages, ensuring that they remain available and consistent for future builds.

But the startup isn’t just about acting as a digital warehouse.

It’s a vigilant sentinel, scanning these dependencies for security weaknesses, licensing issues, and malware before they infiltrate the developers’ sanctuaries.

In doing so, Cloudsmith transforms itself into a security checkpoint, blocking problematic artifacts from reaching production environments.

The latest capital infusion, led by TCV with participation from Insight Partners, underscores a significant vote of confidence in Cloudsmith’s mission.

With these funds, Cloudsmith aims to expand its team, enhance marketing efforts, and dive into research and development, particularly in AI applications.

The ultimate ambition? To convert vast data banks into actionable insights, guiding developers toward safer, smarter open-source package choices.

Glenn Weinstein, Cloudsmith’s CEO, envisions a future where developers can rely on curated internal registries that prioritize secure and up-to-date packages over potentially risky public options.

This curated approach is akin to transforming the informal grapevine of package recommendations into a formalized, reliable advisory system within the Cloudsmith platform.

Despite its roots in Belfast, Cloudsmith’s impact is decidedly global.

With the majority of its revenue emanating from U.S. clients, the company is strategically poised to cement its status as a leader in artifact management and security.

Co-founder Alan Carson notes that this pivot towards large enterprises is not just a business strategy but a necessary evolution to address the pressing challenges of securing software supply chains and meeting stringent compliance standards.

In a world where digital threats loom large, Cloudsmith stands out as a trailblazer, not only by fortifying the software supply chain but also by redefining how the tech industry approaches security.

As the digital age hurtles forward, the importance of such innovations cannot be overstated.

Cloudsmith’s journey is one to watch, as it charts a course toward a more secure and resilient software ecosystem.

Tags:
artifact management, cloudsmith, news, open source, software security, supply chain
Join Our Newsletter
Stay up to date on latest stories
Join Our Newsletter
Stay up to date on latest stories
Copyright © 2026 Success Quarterly. All Rights Reserved.
Copyright © 2024 Success Quarterly. All Rights Reserved.
Join our newsletter
Stay up to date on latest stories
Close