Kusari provides a software supply chain security platform that continuously maps every component to identify and prioritize actionable risks. The platform traces dependency provenance, enforces automated security policies within the CI/CD pipeline, and generates audit-ready artifacts like signed SBOMs and VEX reports. This enables development and security teams to fix critical threats faster and ensure only compliant code reaches production.
Funding
$8.1M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.

JVFounders
Product
Problem
Organizations face increasing risks from vulnerabilities and compromises within their software supply chains, leading to potential disruptions and security incidents. Identifying and remediating these vulnerabilities can be a time-consuming and complex process, often requiring months to address.
Solution
Kusari offers a software supply chain security platform that provides transparency and enables secure development practices. The platform integrates with existing IDE and CI/CD tools to automate vulnerability management and ensure software build integrity. By leveraging GUAC, an open-source knowledge graph, Kusari allows organizations to quickly understand the impact of supply chain compromises and respond effectively. The platform facilitates proactive security measures, allowing for the evaluation of artifacts before ingestion and the creation of policies to prevent risky dependencies from entering the supply chain.
Target Audience
Kusari targets DevSecOps teams and security professionals seeking to enhance their software supply chain security and streamline vulnerability management.
Features
- Integration with existing IDE and CI/CD tools for seamless vulnerability management
- Automated generation of metadata to ensure the integrity of each build
- Open-source knowledge graph (GUAC) for evaluating artifacts and creating security policies
- Ability to quickly understand the blast radius of supply chain compromises
- Proactive security measures to prevent risky dependencies from entering the supply chain