Kusari Raises $8 Million in Pre-Seed and Seed Funding
January 18, 2024

Kusari raised $8 million through combined investments in Pre-Seed and Seed Round funding.

The Seed Round was led by J2 Ventures and co-led by Glasswing Ventures with participation from Unusual Ventures, which previously invested $2 million in Pre-Seed funding.

Kusari was established in June 2022 to address the lack of transparency within the software supply chain and development lifecycle, which can lead to costly security vulnerabilities. Cybersecurity Ventures recently reported that the global annual cost of software supply chain attacks to businesses will reach $60 billion in 2025, and is expected to increase to $138 billion by 2031. Transparency into the software supply chain will allow organizations to identify potential weak points and resolve issues faster, helping them maintain trust with partners and minimize risk.

Kusari’s founders, Tim Miller, Michael Lieberman, and Parth Patel, are seasoned navigators of software supply chains with experience leading supply chain security and cloud engineering at Citi, Mitsubishi UFJ Financial Group (MUFG), Bridgewater Associates, and Raytheon. They have personally dealt with the complicated problem of securing software delivery while enabling developer productivity within highly regulated, security-conscious environments. The founding team provides technical leadership and guidance in the Open Source Security Foundation (OpenSSF), which brings together the industry's most important open source security initiatives and the individuals and companies that support them. The Kusari founders also have created many open source projects, including Graph for Understanding Artifact Composition (GUAC), which is supported by industry-leading financial services and technology companies, including Yahoo!, Guidewire, Google, Microsoft, Red Hat, and ClearAlpha Technologies.

Open source libraries comprise the majority of most software written today. Each relies on other libraries, creating a complicated tree of dependencies. Securing a software supply chain starts with understanding how each piece is put together. It can be deceivingly difficult for an organization to understand what this looks like, as modern software development practices work to hide this complexity in favor of easy development.

Kusari introduced and achieved market validation for GUAC in 2023 to address this specific problem. GUAC is an open source tool that addresses the lack of transparency by organizing software supply chain information, like software bills of materials (SBOMs), into a knowledge graph. The project has a diverse community of 50 contributors and has garnered 1.1k GitHub stars.

Kusari will use the funding to accelerate and build on its continued momentum in developing software supply chain security solutions that enable organizations to achieve actionable insights, reduce incident response costs, and relieve the burden on security and developer teams.

“Kusari’s blend of team, technology, and significant adoption, even at this early stage, position them to be a market leader. Our initial indication from government agencies for what they’re building revealed a massive commercial market. GUAC’s potential cannot be overstated,” said Jonathan Bronson, Ph.D., co-founder and Managing Partner of J2 Ventures.

"Code breaches are increasingly becoming a top priority for Chief Information Security Officers,” said Kleida Martiro, Partner, Glasswing Ventures. “In an era where software supply chain attacks are on the rise, the demand for stringent security measures has never been more critical. At the helm of Kusari, a team of seasoned industry veterans, including Tim, Michael, and Parth, are steering the company toward new heights. We are immensely proud of our investment in Kusari. Their unparalleled knowledge and innovative approach position them at the cutting edge, as they lead the charge in defining and delivering groundbreaking security solutions in this vital and evolving space.”

“Identifying where vulnerabilities lie in your software supply chain is complex and time-consuming. With the ever-increasing number of vulnerable packages discovered each year, organizations need a single source of truth about their code,” said Tim Miller, co-founder and CEO of Kusari. “Kusari will be that source of end-to-end transparency and will bring about insights for users to drive more secure outcomes for their organizations. Our focus is on helping users solve their very real security problems.”

Share this

Industry News

January 23, 2025

Progress announced the launch of Progress Data Cloud, a managed Data Platform as a Service designed to simplify enterprise data and artificial intelligence (AI) operations in the cloud.

January 23, 2025

Sonar announced the release of its latest Long-Term Active (LTA) version, SonarQube Server 2025 Release 1 (2025.1).

January 23, 2025

Idera announced the launch of Sembi, a multi-brand entity created to unify its premier software quality and security solutions under a single umbrella.

January 22, 2025

Postman announced the Postman AI Agent Builder, a suite empowering developers to quickly design, test, and deploy intelligent agents by combining LLMs, APIs, and workflows into a unified solution.

January 22, 2025

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the graduation of CubeFS.

January 21, 2025

BrowserStack and Bitrise announced a strategic partnership to revolutionize mobile app quality assurance.

January 21, 2025

Render raised $80M in Series C funding.

January 16, 2025

Mendix, a Siemens business, announced the general availability of Mendix 10.18.

January 16, 2025

Red Hat announced the general availability of Red Hat OpenShift Virtualization Engine, a new edition of Red Hat OpenShift that provides a dedicated way for organizations to access the proven virtualization functionality already available within Red Hat OpenShift.

January 16, 2025

Contrast Security announced the release of Application Vulnerability Monitoring (AVM), a new capability of Application Detection and Response (ADR).

January 15, 2025

Red Hat announced the general availability of Red Hat Connectivity Link, a hybrid multicloud application connectivity solution that provides a modern approach to connecting disparate applications and infrastructure.

January 15, 2025

Appfire announced 7pace Timetracker for Jira is live in the Atlassian Marketplace.

January 14, 2025

SmartBear announced the availability of SmartBear API Hub featuring HaloAI, an advanced AI-driven capability being introduced across SmartBear's product portfolio, and SmartBear Insight Hub.

January 14, 2025

Azul announced that the integrated risk management practices for its OpenJDK solutions fully support the stability, resilience and integrity requirements in meeting the European Union’s Digital Operational Resilience Act (DORA) provisions.

January 14, 2025

OpsVerse announced a significantly enhanced DevOps copilot, Aiden 2.0.