
Work Here?
Cloudsmith provides a cloud-native artifact management platform with a universal repository for all enterprise software packages and containers. It supports 28+ formats (including Docker, Maven, PyPI, and npm) so teams store, manage, and distribute dependencies and internal assets in one place. An OPA Rego-based policy engine blocks malicious or non-compliant artifacts before they reach the build, and the platform adds auditing, vulnerability scanning, and automated promotion across 600 global edge points for fast, compliant DevOps. Its Embodied Security and AI-driven protection offer governance and visibility to accelerate software delivery while safeguarding the software supply chain.
Industries
Data & Analytics
Enterprise Software
Cybersecurity
AI & Machine Learning
Company Size
51-200
Company Stage
Series C
Total Funding
$123.4M
Headquarters
Belfast, United Kingdom
Founded
2016
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$123.4M
Meets
Industry Average
Funded Over
5 Rounds
Industry standards
Cloudsmith announces new features for enforcing software supply chain governance in artifact repositories. August 17, 2026 Cloudsmith announced an expansion to its policy management and continuous risk detection capabilities, adding policy templates, cooldown policies, and expanded evaluation triggers. The new features continue to strengthen the artifact repository as the most critical point of control for securing the software supply chain and providing proactive protection for developers. Select customers have been testing the new features and reporting significant benefits, especially from new cooldown and malicious package policies. Attacks increasingly target pipelines and open source packages, so one misconfigured pipeline can result in an incident. Since Cloudsmith policies apply company-wide at the repository level, the risk of a misconfigured pipeline is greatly reduced. Cloudsmith reduces time to policy enforcement, minimizes friction for developers, and ensures policy changes take effect immediately across repositories. New features being announced today include: - Policy templates: pre-configured policies as code, written in the Rego language, to jump-start a set of recommended baseline controls to begin enforcement immediately. - Cooldown policies: Highly configurable cooldown policies that apply across repositories, teams, and formats. Cloudsmith cooldown policies work by creating a filtered view of upstream public registry package indexes, so that each developer or CI/CD pipeline's package managers see only versions that meet policy and thus default to the latest compliant version automatically. This prevents build failures and eliminates the need to revise dependency files. - Expanded evaluation triggers: In addition to evaluating on package upload and when threat intelligence updates, Cloudsmith policies now also evaluate when a policy is created or updated, without the need for a manual backfill step. Together, these capabilities strengthen Cloudsmith's role as a comprehensive, centrally-managed control plane for the software supply chain. Alison Sickelka, Cloudsmith's VP of Product, said "We created our policy management feature set because we believe the artifact registry is the right place to enforce control of the software supply chain. It's one of our most quickly adopted feature sets ever, especially for cooldown and malicious package policies. Security teams need better ways to react, and they need to stop unsafe software at the boundary of their environment, before unwanted packages can reach developers or pipelines. Today's updates give organizations an even stronger enforcement point across every team, every pipeline, and every package format." Industry news. August 17, 2026 The Cloud Native Computing Foundation(R)(CNCF(R), which builds sustainable ecosystems for cloud native software, announced the graduation of Kubeflow, a cloud native ecosystem forged by an open community dedicated to standardizing Data & AI workloads on Kubernetes. August 17, 2026 Google's Agent2Agent Protocol (A2A) is joining the Agentic AI Foundation (AAIF). August 17, 2026 Cloudsmith announced an expansion to its policy management and continuous risk detection capabilities, adding policy templates, cooldown policies, and expanded evaluation triggers. August 13, 2026 The Linux Foundation, the nonprofit organization enabling mass innovation through open source, announced the schedule for Open Source Summit + Embedded Linux Conference Europe 2026, taking place in Prague, Czechia from October 7-9. August 12, 2026 The Cloud Native Computing Foundation(R)(CNCF(R), which builds sustainable ecosystems for cloud native software, announced the graduation of Cloud Native Buildpacks, an open source project that builds OCI-compliant container images directly from application source code. August 12, 2026 Quali announced the general availability of Stack Automation, a deployment automation platform developed in collaboration with Cisco and available exclusively through Cisco, built to bring enterprise-grade speed, governance, and agentic AI capability to every layer of the infrastructure stack. August 12, 2026 CodeRabbit introduced Agentic Change Management - the control layer that enables teams to govern, understand, and ship software created by people and agents. August 11, 2026 Citrix announced new services for Citrix(R) Platform Flex, including Citrix SecurSpaces(TM) Flex, a hosted, cloud-based platform for code development and agentic workloads that allows enterprises to provide secure environments without building and operating the platform themselves. August 11, 2026 Semgrep announced a deepened partnership with Replit to bring automated, real-time security analysis directly into the AI-native development workflow. August 10, 2026 The CNCF announced the full schedule for KubeCon + CloudNativeCon North America 2026, taking place November 9-12 in Salt Lake City, Utah. August 06, 2026 Apiiro has joined Athena, the Chainguard-led coalition to protect open source software from AI attacks. August 05, 2026 The CNCF Technical Oversight Committee (TOC) has voted to accept Kubernetes Global Balancer (K8gb) as a CNCF incubating project. August 05, 2026 Red Hat announced the formation of asago, an open source community project intended to automate how AI governance policies become product-ready, safely-deployed AI systems. August 05, 2026 Checksum launched the Continuous Quality Loop, connecting test generation, execution, and maintenance directly into GitHub, CI pipelines, and MCP so tests run the moment a pull request opens.
Cloudsmith credentials are now detectable by GitHub Secret Scanning. Jun 18 2026 Leaked API keys are one of the most common and well-understood security failures in software development. A credential committed to a repo, copied into a script, or exposed in a CI log can sit undetected until abuse makes it visible. By then, the damage is done. Cloudsmith is now a member of the GitHub Secret Scanning Partner Program. That means Cloudsmith-issued API keys are uniquely identifiable, and GitHub can detect them automatically when they appear in a repository. How it works. Cloudsmith issues API keys with a unique prefix. That prefix is registered with GitHub's secret scanning infrastructure, so when a Cloudsmith credential appears in a repo - in source code, a config file, a committed .env, or anywhere else GitHub indexes - GitHub detects and flags those credentials automatically. When a leak happens, Cloudsmith notifies the affected customer directly. Teams can revoke or rotate the compromised key before it gets misused. The workflow is straightforward: detection happens automatically, notification is immediate, and your team decides how to respond. Why this matters for your team. The window between a credential leak and credential abuse is short and it closes fast. Automated scanners can pick up a key exposed in a pull request or pushed to a public repo within minutes. Discovering issues through billing anomalies or abuse reports put teams in a challenging position, and one they want to avoid. Automatic detection of leaked API keys changes that dynamic. When exposure triggers an immediate notification, the response begins before most incidents have a chance to develop. This works inside the workflows your team already uses. There is no new tooling to adopt, or new configuration required on your end. GitHub-based teams get detection in place from the moment they issue their next Cloudsmith API key. Read more by
Cloudsmith expands leadership with CFO and General Counsel appointments. Jun 7 2026 Belfast, Northern Ireland, 2 June, 2026 - Cloudsmith, the universal artifact management platform trusted by the world's leading enterprises, today announced the appointment of Mark O'Connor as Chief Financial Officer and Dan Lascell as General Counsel, strengthening the executive leadership team as the firm wins an increasingly large share of its market. More enterprises now depend on Cloudsmith to secure and govern their software supply chains. The appointments reflect the company's scale as Fortune 500 and Global 2000 customers are selecting Cloudsmith as their trusted partner. O'Connor had served as an advisor to Cloudsmith's finance organisation through its last three venture financings, including last month's $72m Series C. Lascell had also served in an advisory role, helping build the company's legal and governance infrastructure. O'Connor brings deep experience leading high-growth SaaS businesses through venture stage, acquisition, and public markets. He has served as CFO or in senior finance roles at Bugcrowd, Tenfold, Appirio, Nuance Communications, and BeVocal. O'Connor's deep institutional knowledge will help Cloudsmith establish financial and procurement controls suitable for an IPO-scale company. "Our focus is on building Cloudsmith's infrastructure for longevity," said Mark O'Connor, Chief Financial Officer, Cloudsmith. "That means ensuring our financial controls and commercial rigor are up to audit-ready standards, while enabling our customer-facing teams to move fast and lead the market. That combination means customers can trust Cloudsmith as a mission-critical infrastructure partner." Lascell brings extensive experience across technology and security companies, with legal leadership roles at Appirio, Bugcrowd, Tercera, AmberPoint, and webMethods. His background in corporate development and international expansion, combined with knowledge of Cloudsmith's commercial and compliance posture, provide Lascell with deep institutional context. He will lead legal, compliance, and commercial contracting, focusing on enterprise procurement and internal governance. "Cloudsmith's platform is built on trust, providing secure artifacts, provable provenance, and policy-driven governance. Our internal legal and compliance posture reflect that same commitment," said Dan Lascell, General Counsel, Cloudsmith. "Our job is to scale the legal and risk frameworks to ensure Cloudsmith is a dependable long-term partner for large enterprise customers with complex regulatory and legal obligations." "Mark and Dan are important additions to our leadership team," said Glenn Weinstein, Chief Executive Officer, Cloudsmith. "Enterprise customers rely on Cloudsmith as a dependable partner they can trust at every level, including the platform, their commercial relationship with Cloudsmith, and our internal governance. Mark and Dan will help ensure we meet the highest standards for financial rigor and legal credibility." The appointments follow Cloudsmith's $72M Series C financing from TCV and Insight Partners. Cloudsmith is scaling to meet the needs of the world's largest and most complex software development organizations, offering customers a secure software supply chain with artifact management that is simple by design, secure by default, and cloud-native. The company's universal artifact management platform serves over 30 formats, delivering secure low-latency distribution from a global package delivery network. Cloudsmith's customers include many Fortune 500 and Global 2000 organizations. About Cloudsmith. Cloudsmith is the leading cloud-native, fully managed universal artifact management platform that helps platform engineering, DevOps, and cybersecurity teams control, secure, and distribute software artifacts globally. Supporting over 30 artifact formats - including containers, language packages, OS packages, and AI/ML models - Cloudsmith delivers enterprise-grade features including continuous vulnerability and malware scanning, SBOM generation, cryptographic signing, a policy-as-code engine, and a global package delivery network with intelligent edge caching. Cloudsmith is built for scale, compliance, and automation, enabling customers in banking, fintech, telecom, software, and AI-native industries to modernize their software supply chains with confidence. Cloudsmith is ISO 27001 and SOC 2 certified and trusted by customers worldwide. Learn more at https://www.cloudsmith.com. Media contact. Other press articles Belfast, UK, 23 April, 2026 - Cloudsmith, the universal artifact management platform trusted by some of the world's leading enterprises, today announced a $72M Series C financing led by TCV and with participation from Insight Partners, along with investments from other existing investors. The additional funding positions Cloudsmith for massive growth to power the era of AI-driven software development. Apr 23 2026 Cloudsmith announced an expansion of its advanced security capabilities, framing the platform as a unified control plane that bridges the gap between threat intelligence and active enforcement. The release highlights two core capabilities - continuous package enrichment (pulling from OSV.dev, EPSS, and OpenSSF malicious package data) and OPA-based policy management with features like cool-down periods, exploitability prioritization, deep SBOM inspection, and malicious package detection. The underlying argument: security tools surface risk just fine, but enforcement is disconnected from where software actually moves - and Cloudsmith fixes that. Mar 23 2026 Cloudsmith announced the early access launch of its Model Context Protocol (MCP) Server. This new integration layer brings Cloudsmith's capabilities directly into the developer's AI-powered workflows Nov 10 2025
Cloudsmith has appointed Mark O'Connor as Chief Financial Officer and Dan Lascell as General Counsel following its $72 million Series C funding round. Both executives previously advised the company for several years before transitioning to full-time roles. The Belfast-based software supply chain security company is expanding its executive team as it pursues deeper relationships with Fortune 500 and Global 2000 customers. O'Connor will oversee financial infrastructure and public market readiness, drawing on experience from Bugcrowd, Tenfold and Nuance Communications. Lascell will lead legal, compliance and commercial contracting, having previously held senior legal roles at Appirio and Bugcrowd. The appointments follow Cloudsmith's recent funding from TCV and Insight Partners. The company's platform supports over 30 artifact formats and serves customers across banking, fintech, telecoms and AI sectors.
The fundraising comes as AI accelerates the pace and scale of software development
Find jobs on Simplify and start your career today
Industries
Data & Analytics
Enterprise Software
Cybersecurity
AI & Machine Learning
Company Size
51-200
Company Stage
Series C
Total Funding
$123.4M
Headquarters
Belfast, United Kingdom
Founded
2016
Find jobs on Simplify and start your career today