Ossprey raises $2.65M pre-seed for open-source malware detection
Episode 1 Ventures led the UK startup’s pre-seed round, with Osney Capital and Octopus Ventures also investing.
By Marcus Adeyemi · Startups Editor
· 3 min read
Ossprey has raised $2.65 million in pre-seed funding to build software supply chain security tools for enterprises using open-source code. Episode 1 Ventures led the round, with participation from Osney Capital and Octopus Ventures, giving the UK startup capital for product development, hiring and international expansion.
The company said the round was oversubscribed. It did not disclose a valuation, revenue, customer count or current headcount.
Founded by Nate Dunning and David Read, Ossprey is building technology that scans open-source software packages for malware before those packages reach production systems. The company is targeting a problem that has become more visible as development teams rely on large dependency chains and automated code generation tools.
Ossprey says its platform continuously checks open-source packages for malicious code, with the goal of letting developers keep their existing software delivery pace while reducing supply chain risk. That claim puts the company in a crowded but active segment of security tooling, where vendors are competing to catch compromised dependencies, malicious packages and other attacks that enter companies through normal engineering workflows.
AI speed meets dependency risk
The company frames the timing around AI-assisted software development. Ossprey argues that coding assistants are increasing the amount of code entering production, which raises pressure on security teams to inspect dependencies without slowing releases. The startup also points to the broad use of open source in enterprise environments, saying around 90% of enterprise software depends on open-source components.
That dependency base is attractive to attackers because a compromised package can travel through legitimate development processes. Ossprey’s pitch is that malware detection has to happen earlier in the software build process, before suspect packages become part of deployed applications.
Dunning, Ossprey’s CEO, said the company was founded because current approaches were not built for the speed of modern engineering teams. He said the investment would support technology development and help the company reach more customers internationally.
Where the money goes
Ossprey said it will use the funding to accelerate product work, add to its engineering and commercial teams, and expand outside its home market. The company plans to focus on enterprise organizations that build software at scale across the UK, Europe and North America.
The startup also said it is preparing for a larger funding round to finance its next stage of growth. No timing, target size or investor names for that future raise were disclosed.
For Episode 1 Ventures, Osney Capital and Octopus Ventures, the deal is a bet that software supply chain security remains a budget priority as AI coding tools spread through engineering teams. For Ossprey, the pre-seed round gives it room to prove whether its malware detection approach can stand out in a field where buyers already face a long list of developer security products.
This story draws on original reporting from Tech.eu.