Skip to content

Cytix

Manchester-based continuous offensive security testing platform that analyzes code changes in real time to predict and test for vulnerabilities as software ships, rather than on a periodic pentest schedule.

Visit Website ↗ + Add to Compare
58/100Incremental Innovator

Overview

Cytix sells continuous offensive security testing (its own term, “COST”) aimed at a specific mismatch: application security teams still largely rely on point-in-time penetration tests scheduled annually or quarterly, while modern software, especially AI-assisted development, ships continuously. Cytix’s platform analyzes code changes as they happen, uses that analysis to predict where new vulnerabilities are likely to have been introduced, and orchestrates automated and human-augmented testing against those changes rather than waiting for a scheduled engagement.

Founded in 2022 in Manchester, UK by Ben Armstrong and Thomas Ballin, Cytix raised a £1.6 million seed round in 2024 co-led by Praetura Ventures’ NPIF II fund and French VC Auriga, followed by a £5.18 million ($7M) Series A in 2026 led by Northern Gritstone, explicitly targeting the security testing gap created by AI-assisted, high-velocity software delivery. Rather than selling only to enterprise security teams directly, Cytix has structured distribution partnerships with established firms KPMG and NCC Group, who run managed security testing programs built on the Cytix platform — a channel strategy that lends the technology some independent credibility beyond Cytix’s own claims. Named platform customers include Cambridge University Press & Assessment, fintech BNVK, and bot-mitigation vendor Netacea.

The company’s proposition depends on continuous testing actually catching vulnerabilities faster than scheduled pentests without generating so much noise that security teams tune it out — a real and unresolved tension in the automated-testing space generally, not unique to Cytix, and one that is not yet settled by independently published, head-to-head efficacy data.

Innovation Matrix Assessment

Innovation Velocity 7/10

Moved from seed to a £5.18M Series A within roughly two years while expanding its platform to explicitly target AI-generated code risk, a fast pace for a young UK security startup.

Operational Value 6/10

Shifting testing from a scheduled annual pentest to continuous, change-triggered analysis addresses a real operational lag in application security programs, though it adds an always-on tool that teams must tune and monitor.

Market Momentum 6/10

British Business Bank-backed seed funding followed by a Northern Gritstone-led Series A, plus distribution partnerships with KPMG and NCC Group, are independently reported and indicate real commercial and investor momentum for an early-stage company.

Category Disruption 6/10

Continuous, code-change-triggered offensive testing is a genuinely different delivery model from calendar-scheduled penetration testing, directly responding to the velocity mismatch created by AI-assisted development.

Real-World Efficacy 4/10

A reported 60% reduction in security incident discovery time for customer BrightHR is a concrete named-customer data point, but it is vendor-published rather than independently audited, and no third-party benchmark or MITRE-style evaluation was found.

Enduring Relevance 6/10

AI-assisted coding is measurably increasing the rate of code change across the industry, making the specific problem Cytix targets more relevant, not less, though the continuous-testing category itself has several other entrants.

Why CISOs Should Care

Gives AppSec leaders a way to keep pentest-grade testing coverage aligned with continuous deployment cadence, instead of leaving code shipped between quarterly pentest windows effectively untested.

What Makes It Different

Distribution through established firms KPMG and NCC Group as a managed-testing backend, rather than selling only direct-to-enterprise, is an unusual go-to-market for a security testing startup and provides a degree of external vetting.

The Matrix Verdict

58/100 — INCREMENTAL INNOVATOR

A fast-moving, well-funded UK startup addressing a real and growing gap in application security testing cadence; the KPMG/NCC Group channel is a credible momentum signal, though independently verified efficacy data remains limited this early.

Editorial Note: Claims vs. Verified Findings

Seed and Series A funding amounts, investors, and the British Business Bank case study are independently reported. The BrightHR 60%-reduction figure and other customer outcome statistics are vendor-published case studies, not third-party audited results.

Sources