Skip to content

Cloudsmith

Cloudsmith is a cloud-native artifact management platform that adds SBOM inspection, dependency quarantine, and exploitability-based policy controls to secure the software supply chain.

Visit Website ↗ + Add to Compare
68/100Incremental Innovator

Overview

Cloudsmith operates a cloud-native, fully managed artifact repository platform (packages, containers, and other build artifacts) that has increasingly layered software-supply-chain security controls on top of its core package-hosting function. Its security capabilities include deep SBOM (software bill of materials) inspection to flag unsafe transitive dependencies or non-compliant licenses, automatic quarantine ("cool-down") periods that hold newly published dependencies until they’ve been vetted by the broader security community, and exploitability-based prioritization that uses EPSS scoring to focus remediation on vulnerabilities that are actually likely to be exploited rather than every CVE regardless of real-world risk.

Founded in 2016 by Lee Skillen and Alan Carson, Cloudsmith is headquartered in Belfast, Northern Ireland. The company has raised substantial venture funding, including a $23 million Series B and, more recently, a $72 million Series C led by TCV with participation from Insight Partners, explicitly positioned around securing the software supply chain, including AI-generated code and dependencies.

Cloudsmith’s core product remains a general-purpose artifact management platform rather than a dedicated, single-purpose security tool, so its supply-chain-security capabilities function as an increasingly prominent layer on top of an infrastructure product rather than the company’s sole focus. That said, software supply-chain attacks (malicious packages, dependency confusion, compromised build pipelines) are a well-documented and growing threat category, and Cloudsmith’s SBOM- and EPSS-based controls are a substantive, purpose-built response to it rather than a superficial add-on.

Innovation Matrix Assessment

Innovation Velocity 7/10

Progressed from basic artifact hosting to deep SBOM inspection, dependency cool-down quarantine, and EPSS-based exploitability prioritization in successive product releases, a substantive security-specific roadmap on top of its core platform.

Operational Value 6/10

As a fully managed, cloud-native SaaS platform, artifact hosting and its layered security policies require no customer-managed infrastructure, though realizing full supply-chain-security value requires integrating policy enforcement into existing CI/CD pipelines.

Market Momentum 8/10

A $72M Series C led by TCV with Insight Partners' continued participation, following a $23M Series B, is independently reported and represents strong, escalating investor confidence for a company of its size.

Category Disruption 6/10

Combining SBOM-level (component, not just image-level) policy enforcement with exploitability-based prioritization is a meaningful advance over simple vulnerability-count scanning, though it extends rather than reinvents the software-composition-analysis approach used across the category.

Real-World Efficacy 6/10

No independently verified, named-customer breach-prevention outcome data was found; the SBOM inspection and EPSS-prioritization mechanisms are technically sound and industry-standard approaches, but effectiveness claims beyond the mechanism description are largely vendor-sourced.

Enduring Relevance 8/10

Software supply-chain attacks via malicious or compromised open-source dependencies are a well-documented, growing threat vector, and the added complexity of AI-generated code dependencies makes artifact-level supply-chain controls increasingly relevant.

Why CISOs Should Care

Gives security and platform engineering teams a single control point to enforce software-supply-chain policy (blocking unsafe dependencies, quarantining unvetted packages) at the artifact-repository layer, where most dependency risk actually enters the build pipeline.

What Makes It Different

Differentiates from generic artifact/package registries by building SBOM-aware, component-level policy enforcement and EPSS-based exploitability prioritization directly into the repository layer, rather than treating security as a bolt-on scanner.

The Matrix Verdict

68/100 — INCREMENTAL INNOVATOR

A well-funded, fast-growing artifact management platform whose deepening software-supply-chain-security features are a genuine and increasingly central part of its value proposition, though it remains fundamentally an infrastructure product with security layered on top rather than a pure-play security vendor.

Editorial Note: Claims vs. Verified Findings

Founding details, headquarters, and Series B/C funding figures are independently reported (Yahoo Finance, Silicon Republic, company press releases); specific claims about SBOM inspection accuracy or quarantine effectiveness are vendor-described mechanisms rather than independently benchmarked outcomes.

Sources