Cytix Raises $7M as AI Coding Turns Every Software Change Into a Security Decision
Image credit : Tech.eu
Years before AI coding agents began accelerating software development, security already had a timing problem. Cytix co-founder Thomas Ballin once worked inside a large bank where a software change could move through developers, project managers, and security reviews before reaching a penetration-testing team. The process was thorough, but it belonged to a world where code still moved largely at human speed.
That world is disappearing. Manchester-based Cytix has raised $7 million in Series A funding, led by Northern Gritstone, with existing investors Auriga Cyber Ventures and NPIF II – PXN Equity Finance also participating. The capital will accelerate the rollout of Cytix’s newly launched software change risk platform into enterprise and regulated organizations.
The funding arrives alongside a more interesting transformation inside Cytix itself. Co-founders Ben Armstrong and Thomas Ballin spent years around security testing, but Armstrong says the company eventually stopped defining the problem through labels such as penetration testing, continuous testing or AI pentesting. Customers kept returning to a harder question: which software changes actually create business risk?
Cytix is effectively putting a decision layer in front of the security scanner.
The platform reads the context around tickets, pull requests, code differences, releases and policies, while maintaining a persistent knowledge graph of the software environment. It can identify which changes deserve attention, determine whether the response should involve additional context, review, threat modelling or testing, and preserve the resulting decision as evidence. High-risk changes can move into agentic validation, while lower-risk changes can follow proportionate approval paths.
The urgency is being amplified by AI-assisted development. In Cytix-commissioned research involving 250 UK security leaders at organizations with more than 1,000 employees, 62% said security risk was shifting from a latent problem toward an immediate one. Only 38% strongly agreed that their organization was prepared for the volume of AI-generated code entering its environment.
Cytix says its technology already supports continuous testing programs involving KPMG and NCC Group. NCC Group separately describes the partnership as combining its offensive-security expertise with Cytix’s AI-powered change intelligence to provide more continuous assurance as software evolves. Cytix’s platform became generally available on August 12.
The strategic bet goes beyond finding more vulnerabilities. As AI makes software change cheaper and faster, security attention becomes the scarce resource. Cytix wants to help enterprises decide where that attention belongs, then leave behind enough evidence to explain why the decision was made.