Kusari
Software supply chain security platform that builds a live dependency graph to show which vulnerabilities are actually reachable and exploitable.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Kusari builds a software supply chain security platform centered on a continuously updated graph of the components found across an organization’s repositories, container images, and build pipelines. Rather than replacing existing scanners, the platform sits alongside them and adds Reachability and Blast Radius analysis to show which vulnerabilities in a dependency tree are actually exploitable in context, plus an AutoFix module and an Inspector feature that performs automated security review on pull requests.
The company was co-founded in 2022 by Tim Miller (CEO), Michael Lieberman (CTO), and Parth Patel, who together created GUAC (Graph for Understanding Artifact Composition), an open-source project built in partnership with Google’s open source security team to map relationships between software components across an ecosystem. The founders previously worked on supply chain security and cloud engineering at Citi, MUFG, Bridgewater Associates, and Raytheon. Kusari is based in Ridgefield, Connecticut.
Kusari raised $8 million across combined pre-seed and seed rounds in January 2024, with participation from Glasswing Ventures, J2 Ventures, and Unusual Ventures. The company has continued active involvement with the Open Source Security Foundation (OpenSSF) and the Cloud Native Computing Foundation (CNCF) through 2026, reflecting ongoing technical credibility in the open-source supply chain security community, though this community standing has not yet translated into disclosed commercial scale.
Innovation Matrix Assessment
Founders built GUAC with Google's open source security team before commercializing it, and the company maintains active OpenSSF and CNCF partnerships through 2026.
Reachability and blast-radius analysis help vulnerability management teams cut through raw CVE counts to focus on what's actually exploitable in their environment.
Only $8M raised as of its last disclosed round in January 2024, with no named commercial customers, though continued open-source ecosystem partnerships are a positive non-commercial signal.
Reachability-based triage built on the open-source GUAC graph is a meaningful evolution of vulnerability management, but builds on an existing open-source foundation rather than introducing an entirely new paradigm.
No independent efficacy data, named customer outcomes, or third-party benchmarks were found publicly.
Software supply chain risk and alert fatigue in vulnerability management are durable, growing problems as dependency trees keep expanding.
Why CISOs Should Care
Kusari helps vulnerability management teams stop drowning in CVE counts by showing which vulnerabilities are actually reachable in a running application, so remediation effort goes where it matters.
What Makes It Different
It is built on GUAC, an open-source artifact-composition graph the founders created with Google's open source security team, rather than a proprietary scanning engine built from scratch.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
Kusari is an Incremental Innovator: strong open-source technical credibility and a founding team with real supply-chain security pedigree, but still early commercially with no disclosed customer names or funding since its 2024 seed round.
Editorial Note: Claims vs. Verified Findings
The funding round, founding team, and GUAC origin story are corroborated by multiple independent outlets including Glasswing Ventures and CNCF. Specific product performance and customer-impact claims are vendor-stated and not independently verified.
Sources
Alternatives to Kusari
Unknown Cyber Inc.
CISO ReviewedMalware genomics platform using automated deep static analysis and code-lineage comparison to identify unseen malware, variants, and supply-chain…
Synack Inc
A penetration-testing-as-a-service platform pairing a vetted researcher community with AI-driven attack surface discovery for continuous security validation.
Horizon3.ai
Autonomous penetration testing company whose NodeZero platform self-attacks networks without persistent agents, aiming to replace annual manual pentests…
Airlock Digital
Application allowlisting (deny-by-default) platform that blocks unapproved executables, scripts, and processes to prevent ransomware and malware execution.
Cogent Security
Agentic AI platform that autonomously triages, investigates, and remediates vulnerabilities as a force multiplier for security teams.
ReversingLabs
Software supply chain security and binary analysis vendor that inspects compiled software and packages for malware and unauthorized…