Cloudsmith Raises $72M to Govern AI-Generated Software Supply Chains

The Series C, led by TCV with Insight Partners, positions Cloudsmith as an infrastructure for enterprises managing code produced by AI coding agents.

The Series C, led by TCV with Insight Partners, positions Cloudsmith as an infrastructure for enterprises managing code produced by AI coding agents.

Cloudsmith, a cloud-native artifact management platform, raised $72 million in a Series C round led by TCV with participation from Insight Partners, the company said in a press release on Wednesday. The funding arrives one year after the company’s Series B and will go toward product development and expanded sales operations. 

The raise is one of the largest venture rounds in Northern Ireland’s history. Cloudsmith’s customers include Fortune 500 and Global 2000 companies, many of which are replacing on-premise artifact management tools with the company’s platform. 

ALSO READ: CrowdStrike Unites Industry Against AI-Driven Security Risks

The investment follows a period in which AI coding agents have accelerated the pace at which software components, packages, libraries, and dependencies enter enterprise environments. That speed has created a wider attack surface. Regulators have increased pressure on businesses to demonstrate that software, including code generated by AI systems, is traceable and secure throughout development. Cloudsmith positions its platform as the governance layer that sits between AI-generated code and production systems.

AI agents generate so much software, so fast, it’s nearly impossible for humans to carefully review it all. Cloudsmith has the scale and the broad view across the open-source ecosystem to protect enterprises against the new kinds of threats that AI-driven development introduces.
CEO Glenn Weinstein.

TCV Partner Morgan Gerlak, whose firm led both the Series B and Series C, said the company is “uniquely positioned to become a platform enterprises rely on for compliance, control, and security at global scale,” per the release. Thomas Krane, Managing Director at Insight Partners, cited the platform’s cloud-native architecture and its ability to “mitigate emerging risks” in AI-driven builds.

Cloudsmith was founded in Belfast in 2016. It raised a $15 million in Series A in 2021 before closing its Series B in early 2025. The company’s platform supports multiple package formats and environments, giving engineering teams visibility over every component across the software lifecycle.

In March 2026, the company expanded its security capabilities, adding continuous package enrichment sourced from OSV.dev, EPSS, and OpenSSF malicious package data, alongside policy management tools that include malicious package detection and software bill of materials inspection. 

The artifact management market has drawn increased enterprise attention as AI-assisted development has moved from experimentation to production use. The company declined to name specific rivals in its announcement.

TCV has backed more than 350 technology companies since 1995 and has over $22 billion invested globally. Insight Partners manages more than $90 billion in regulatory assets under management as of June 30, 2025, and has backed more than 875 companies worldwide. 

Avatar photo
NN Desk

Lasă un răspuns

Adresa ta de email nu va fi publicată. Câmpurile obligatorii sunt marcate cu *

Stay updated with NervNow Weekly

Subscribe now