Cytix
Manchester-based continuous offensive security testing platform that analyzes code changes in real time to predict and test for vulnerabilities as software ships, rather than on a periodic pentest schedule.
Visit Website ↗ + Add to CompareOverview
Cytix sells continuous offensive security testing (its own term, “COST”) aimed at a specific mismatch: application security teams still largely rely on point-in-time penetration tests scheduled annually or quarterly, while modern software, especially AI-assisted development, ships continuously. Cytix’s platform analyzes code changes as they happen, uses that analysis to predict where new vulnerabilities are likely to have been introduced, and orchestrates automated and human-augmented testing against those changes rather than waiting for a scheduled engagement.
Founded in 2022 in Manchester, UK by Ben Armstrong and Thomas Ballin, Cytix raised a £1.6 million seed round in 2024 co-led by Praetura Ventures’ NPIF II fund and French VC Auriga, followed by a £5.18 million ($7M) Series A in 2026 led by Northern Gritstone, explicitly targeting the security testing gap created by AI-assisted, high-velocity software delivery. Rather than selling only to enterprise security teams directly, Cytix has structured distribution partnerships with established firms KPMG and NCC Group, who run managed security testing programs built on the Cytix platform — a channel strategy that lends the technology some independent credibility beyond Cytix’s own claims. Named platform customers include Cambridge University Press & Assessment, fintech BNVK, and bot-mitigation vendor Netacea.
The company’s proposition depends on continuous testing actually catching vulnerabilities faster than scheduled pentests without generating so much noise that security teams tune it out — a real and unresolved tension in the automated-testing space generally, not unique to Cytix, and one that is not yet settled by independently published, head-to-head efficacy data.
Innovation Matrix Assessment
Moved from seed to a £5.18M Series A within roughly two years while expanding its platform to explicitly target AI-generated code risk, a fast pace for a young UK security startup.
Shifting testing from a scheduled annual pentest to continuous, change-triggered analysis addresses a real operational lag in application security programs, though it adds an always-on tool that teams must tune and monitor.
British Business Bank-backed seed funding followed by a Northern Gritstone-led Series A, plus distribution partnerships with KPMG and NCC Group, are independently reported and indicate real commercial and investor momentum for an early-stage company.
Continuous, code-change-triggered offensive testing is a genuinely different delivery model from calendar-scheduled penetration testing, directly responding to the velocity mismatch created by AI-assisted development.
A reported 60% reduction in security incident discovery time for customer BrightHR is a concrete named-customer data point, but it is vendor-published rather than independently audited, and no third-party benchmark or MITRE-style evaluation was found.
AI-assisted coding is measurably increasing the rate of code change across the industry, making the specific problem Cytix targets more relevant, not less, though the continuous-testing category itself has several other entrants.
Why CISOs Should Care
Gives AppSec leaders a way to keep pentest-grade testing coverage aligned with continuous deployment cadence, instead of leaving code shipped between quarterly pentest windows effectively untested.
What Makes It Different
Distribution through established firms KPMG and NCC Group as a managed-testing backend, rather than selling only direct-to-enterprise, is an unusual go-to-market for a security testing startup and provides a degree of external vetting.
The Matrix Verdict
58/100 — INCREMENTAL INNOVATOR
A fast-moving, well-funded UK startup addressing a real and growing gap in application security testing cadence; the KPMG/NCC Group channel is a credible momentum signal, though independently verified efficacy data remains limited this early.
Editorial Note: Claims vs. Verified Findings
Seed and Series A funding amounts, investors, and the British Business Bank case study are independently reported. The BrightHR 60%-reduction figure and other customer outcome statistics are vendor-published case studies, not third-party audited results.
Sources
Alternatives to Cytix
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…