Ossprey, a software supply chain security startup, has raised £2 million in pre-seed funding led by Episode 1 Ventures, with participation from Osney Capital and Octopus Ventures. The oversubscribed round will fund product development, expand the engineering and commercial teams and support international growth. At the time of the investment, the raise represented one of the largest pre-seed rounds by a UK cyber security company.
Around 90% of enterprise software is built using open source components, and attackers are increasingly hiding malware inside trusted software packages, allowing malicious code to enter organisations through legitimate development workflows rather than traditional attack methods. Ossprey continuously scans open source packages for malicious code before they reach developers, helping organisations secure their software without slowing engineering teams. As AI coding assistants accelerate software development and vibe coding becomes increasingly common, the volume of code being produced is growing rapidly, making software supply chain security more critical than ever.
Since raising the round, the team has grown to seven, the platform has expanded, and continuous public scanning has launched across major open source ecosystems. Ossprey has established itself as one of the fastest organisations globally to detect newly published malicious packages, frequently identifying threats far faster than the wider industry.
Ossprey is a graduate of Cyber Runway, the United Kingdom's largest cyber accelerator programme, which is funded by the Department of Science, Innovation and Technology (DSIT). Founders Nate Dunning and David Read participated in the Launch and Grow programmes, hosted by Plexal, which supported them as they founded Ossprey.
Looking ahead, expansion will continue across the United Kingdom, Europe and North America, with a particular focus on organisations building software at enterprise scale, alongside plans to raise a larger round to continue fuelling growth.
Software development has fundamentally changed. AI is enabling organisations to build software faster than ever before, but it's also dramatically increasing the amount of code entering production and creating new opportunities for attackers to hide malicious software inside trusted open source packages. We founded Ossprey because existing approaches weren't designed for the pace modern engineering teams now operate at. Organisations shouldn't have to choose between shipping software quickly and building it securely. This investment allows us to continue developing technology that helps organisations build safely at AI speed while expanding our reach internationally.
Open source software supply chain attacks have quietly exploded in scale and sophistication, yet security tools today can't tell malicious code from benign. Ossprey's detection engine catches what signature-based tools miss, stopping malicious code before it hits production. Having experienced this directly, Nate and David's rare technical depth make them uniquely equipped to set a new security gold standard.
Every engineering team now depends on open-source code they didn't write and can't fully vouch for. Most tools check that code against a list of things already known to be bad. Ossprey looks at what the code actually does. Nate and David are the perfect team to build it.
Ossprey addresses one of the most pressing challenges in modern cyber security. The team's vision, technical expertise and market opportunity made this an exciting investment for us. We're looking forward to supporting Ossprey as it enters its next phase of growth and brings its technology to organisations around the world.








