Summary
- Cytix has raised a $7 million Series A led by Northern Gritstone, with Auriga Cyber Ventures and NPIF II – PXN Equity Finance participating.
- Its platform analyses software changes across tickets, pull requests, code, and releases before deciding what security response is proportionate.
- The company is targeting enterprise and regulated customers as AI-assisted development increases the volume and speed of software changes requiring oversight.
Cytix has raised $7 million to expand a security platform built around an emerging consequence of AI-assisted software development: organisations can generate and release code faster than many of the controls used to assess what each change does to business and cyber risk.
The Manchester-based company’s Series A was led by Northern Gritstone, with existing investors Auriga Cyber Ventures and NPIF II – PXN Equity Finance participating. Cytix put its change-risk platform into general release on 12 August and plans to expand among larger enterprises and regulated organisations, where evidence about how software changes were reviewed can become part of compliance as well as security.
The product sits between the software-development lifecycle and security, risk, and compliance teams. It examines context around development tickets, pull requests, code changes, and releases, assesses the associated risk, and then helps determine whether a change needs security testing, can proceed with a lighter control, or requires further investigation.
The approach addresses a problem that predates generative AI but becomes more acute as developers produce working code more quickly. Security teams have finite time, and treating every change as equally risky can create queues that slow development without necessarily concentrating effort on the changes most likely to cause harm.
More code changes the economics of review
Traditional application-security programmes rely on combinations of developer training, automated scanning, penetration testing, manual review, and controls around releases. Each method addresses a different part of the problem, but most become more expensive operationally as the number and frequency of changes rise.
AI coding assistants alter that arithmetic because they can reduce the effort required to generate, revise, and document software. A developer may therefore make more changes during the same period, while employees with less conventional development experience can also build or modify applications with generative assistance.
That does not mean AI-generated code is inherently insecure, nor does Cytix provide independent evidence that every organisation is experiencing a measurable deterioration in software quality. The company’s own research, conducted by Opinion Matters among 250 UK IT security leaders at organisations with more than 1,000 employees and in-house development teams, found that only 38% strongly agreed that their organisation was prepared for the volume of AI-generated code entering its environment.
The survey is vendor-sponsored and should be treated as evidence of reported concern rather than an independent measure of security outcomes. The operational pressure is nevertheless visible across the market, where suppliers are moving controls closer to the point at which code is created. Checkmarx, for example, has been putting security remediation inside AI coding workflows rather than expecting developers to leave those environments whenever a vulnerability appears.
Cytix is selling prioritisation, not another scanner
Cytix describes the problem through change risk rather than vulnerability detection alone. A scanner can identify a technical weakness, but organisations still need to understand the application involved, the importance of the affected system, what data it handles, whether the change alters exposure, and what evidence is required before release.
The platform is intended to create that decision layer by combining technical and business context around each change. Lower-risk changes can move through with less friction, while more consequential ones can trigger additional validation or testing. The system also retains evidence around the decision, giving regulated customers a record of what was considered and how the resulting risk was handled.
That places Cytix in a crowded application-security market being reshaped by the same automation accelerating development. Security vendors increasingly need to determine not only whether they can detect more issues but whether their products can process enough context to avoid overwhelming developers and analysts with findings that carry little practical consequence.
Cytix says customers can access the platform directly or through managed-service relationships with NCC Group and KPMG, while its technology already underpins continuous-testing work offered through those organisations. Those channels may be particularly useful in regulated sectors where customers already rely on external assurance and security providers.
Governance moves into the development workflow
The product also reflects a broader convergence between software engineering and governance. When release cycles were comparatively slow, organisations could build formal review gates around individual deployments, but continuous delivery and AI-assisted development make heavy manual approval increasingly difficult to sustain without becoming a bottleneck.
Automating part of the risk decision creates another challenge: the system has to identify which changes genuinely deserve closer scrutiny. A platform that labels too many changes as high-risk recreates the queue it is meant to reduce, while one that is too permissive could allow consequential changes through with insufficient review.
Cytix will therefore have to demonstrate that its analysis improves security decisions rather than simply producing another risk score. The company has not disclosed current revenue, customer numbers, valuation, or independently measured reductions in incidents, leaving the Series A as financing for a commercial thesis still to be tested at broader enterprise scale.
Generative AI has spent several years making software creation faster and more accessible, while governance systems are only beginning to adjust to the resulting increase in change. Security cannot inspect every line manually, but organisations still need to know which modifications alter their exposure and why.
Cytix is betting that the control point will shift from asking only whether code contains a known vulnerability towards understanding the risk created by the change as a whole. If AI-assisted development continues increasing the volume of software moving through enterprise environments, accurate prioritisation may become as important as the tools helping developers produce the code.












