Skip to content

Kusari

Software supply chain security platform that builds a live dependency graph to show which vulnerabilities are actually reachable and exploitable.

Visit Website ↗ + Add to Compare Claim This Company
53/100Incremental Innovator

Overview

Kusari builds a software supply chain security platform centered on a continuously updated graph of the components found across an organization’s repositories, container images, and build pipelines. Rather than replacing existing scanners, the platform sits alongside them and adds Reachability and Blast Radius analysis to show which vulnerabilities in a dependency tree are actually exploitable in context, plus an AutoFix module and an Inspector feature that performs automated security review on pull requests.

The company was co-founded in 2022 by Tim Miller (CEO), Michael Lieberman (CTO), and Parth Patel, who together created GUAC (Graph for Understanding Artifact Composition), an open-source project built in partnership with Google’s open source security team to map relationships between software components across an ecosystem. The founders previously worked on supply chain security and cloud engineering at Citi, MUFG, Bridgewater Associates, and Raytheon. Kusari is based in Ridgefield, Connecticut.

Kusari raised $8 million across combined pre-seed and seed rounds in January 2024, with participation from Glasswing Ventures, J2 Ventures, and Unusual Ventures. The company has continued active involvement with the Open Source Security Foundation (OpenSSF) and the Cloud Native Computing Foundation (CNCF) through 2026, reflecting ongoing technical credibility in the open-source supply chain security community, though this community standing has not yet translated into disclosed commercial scale.

Innovation Matrix Assessment

Innovation Velocity 7/10

Founders built GUAC with Google's open source security team before commercializing it, and the company maintains active OpenSSF and CNCF partnerships through 2026.

Operational Value 6/10

Reachability and blast-radius analysis help vulnerability management teams cut through raw CVE counts to focus on what's actually exploitable in their environment.

Market Momentum 4/10

Only $8M raised as of its last disclosed round in January 2024, with no named commercial customers, though continued open-source ecosystem partnerships are a positive non-commercial signal.

Category Disruption 5/10

Reachability-based triage built on the open-source GUAC graph is a meaningful evolution of vulnerability management, but builds on an existing open-source foundation rather than introducing an entirely new paradigm.

Real-World Efficacy 4/10

No independent efficacy data, named customer outcomes, or third-party benchmarks were found publicly.

Enduring Relevance 6/10

Software supply chain risk and alert fatigue in vulnerability management are durable, growing problems as dependency trees keep expanding.

Why CISOs Should Care

Kusari helps vulnerability management teams stop drowning in CVE counts by showing which vulnerabilities are actually reachable in a running application, so remediation effort goes where it matters.

What Makes It Different

It is built on GUAC, an open-source artifact-composition graph the founders created with Google's open source security team, rather than a proprietary scanning engine built from scratch.

The Matrix Verdict

53/100 — INCREMENTAL INNOVATOR

Kusari is an Incremental Innovator: strong open-source technical credibility and a founding team with real supply-chain security pedigree, but still early commercially with no disclosed customer names or funding since its 2024 seed round.

Editorial Note: Claims vs. Verified Findings

The funding round, founding team, and GUAC origin story are corroborated by multiple independent outlets including Glasswing Ventures and CNCF. Specific product performance and customer-impact claims are vendor-stated and not independently verified.

Sources