Cloudsmith
Cloudsmith is a cloud-native artifact management platform that adds SBOM inspection, dependency quarantine, and exploitability-based policy controls to secure the software supply chain.
Visit Website ↗ + Add to CompareOverview
Cloudsmith operates a cloud-native, fully managed artifact repository platform (packages, containers, and other build artifacts) that has increasingly layered software-supply-chain security controls on top of its core package-hosting function. Its security capabilities include deep SBOM (software bill of materials) inspection to flag unsafe transitive dependencies or non-compliant licenses, automatic quarantine ("cool-down") periods that hold newly published dependencies until they’ve been vetted by the broader security community, and exploitability-based prioritization that uses EPSS scoring to focus remediation on vulnerabilities that are actually likely to be exploited rather than every CVE regardless of real-world risk.
Founded in 2016 by Lee Skillen and Alan Carson, Cloudsmith is headquartered in Belfast, Northern Ireland. The company has raised substantial venture funding, including a $23 million Series B and, more recently, a $72 million Series C led by TCV with participation from Insight Partners, explicitly positioned around securing the software supply chain, including AI-generated code and dependencies.
Cloudsmith’s core product remains a general-purpose artifact management platform rather than a dedicated, single-purpose security tool, so its supply-chain-security capabilities function as an increasingly prominent layer on top of an infrastructure product rather than the company’s sole focus. That said, software supply-chain attacks (malicious packages, dependency confusion, compromised build pipelines) are a well-documented and growing threat category, and Cloudsmith’s SBOM- and EPSS-based controls are a substantive, purpose-built response to it rather than a superficial add-on.
Innovation Matrix Assessment
Progressed from basic artifact hosting to deep SBOM inspection, dependency cool-down quarantine, and EPSS-based exploitability prioritization in successive product releases, a substantive security-specific roadmap on top of its core platform.
As a fully managed, cloud-native SaaS platform, artifact hosting and its layered security policies require no customer-managed infrastructure, though realizing full supply-chain-security value requires integrating policy enforcement into existing CI/CD pipelines.
A $72M Series C led by TCV with Insight Partners' continued participation, following a $23M Series B, is independently reported and represents strong, escalating investor confidence for a company of its size.
Combining SBOM-level (component, not just image-level) policy enforcement with exploitability-based prioritization is a meaningful advance over simple vulnerability-count scanning, though it extends rather than reinvents the software-composition-analysis approach used across the category.
No independently verified, named-customer breach-prevention outcome data was found; the SBOM inspection and EPSS-prioritization mechanisms are technically sound and industry-standard approaches, but effectiveness claims beyond the mechanism description are largely vendor-sourced.
Software supply-chain attacks via malicious or compromised open-source dependencies are a well-documented, growing threat vector, and the added complexity of AI-generated code dependencies makes artifact-level supply-chain controls increasingly relevant.
Why CISOs Should Care
Gives security and platform engineering teams a single control point to enforce software-supply-chain policy (blocking unsafe dependencies, quarantining unvetted packages) at the artifact-repository layer, where most dependency risk actually enters the build pipeline.
What Makes It Different
Differentiates from generic artifact/package registries by building SBOM-aware, component-level policy enforcement and EPSS-based exploitability prioritization directly into the repository layer, rather than treating security as a bolt-on scanner.
The Matrix Verdict
68/100 — INCREMENTAL INNOVATOR
A well-funded, fast-growing artifact management platform whose deepening software-supply-chain-security features are a genuine and increasingly central part of its value proposition, though it remains fundamentally an infrastructure product with security layered on top rather than a pure-play security vendor.
Editorial Note: Claims vs. Verified Findings
Founding details, headquarters, and Series B/C funding figures are independently reported (Yahoo Finance, Silicon Republic, company press releases); specific claims about SBOM inspection accuracy or quarantine effectiveness are vendor-described mechanisms rather than independently benchmarked outcomes.
Sources
Alternatives to Cloudsmith
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…