Sesame Summit 2026 – application open

Belfast’s Cloudsmith Raises $72M Series C to Secure the AI-Era Software Supply Chain

Cloudsmith, the Belfast-headquartered artifact management platform, has raised $72 million in Series C funding led by TCV, with participation from Insight Partners and other existing investors. The round, announced on 23 April 2026, takes the company’s total funding to well over $100 million and positions it as one of Northern Ireland’s most significant software businesses, with a valuation that public reports place close to the $1 billion mark.

Cloudsmith was founded in 2016 by Alan Carson and Lee Skillen, who met working for the New York Stock Exchange’s Belfast engineering operation, and now employs around 130 people, the bulk of them at its Belfast headquarters. The new capital will fund product development and an expansion of go-to-market capabilities, as the company moves to consolidate its position in an artifact management category that has become a front line in enterprise software supply-chain security.

Inside the round

TCV — the growth investor best known for backing Netflix, Spotify and Airbnb — leads the Series C, with continued participation from Insight Partners, which joined Cloudsmith’s Series B in 2025. The round fits a pattern in 2026 of large growth-stage cheques written into infrastructure companies that sit on the compliance-critical path for enterprise software delivery.

Cloudsmith has the scale and the broad view across the open-source ecosystem to protect enterprises against the new kinds of threats that AI-driven development introduces.

Glenn Weinstein, CEO, Cloudsmith

Morgan Gerlak, partner at TCV, added that “Cloudsmith is uniquely positioned to become a platform enterprises rely on for compliance, control, and security.” Thomas Krane of Insight Partners echoed the framing, citing Cloudsmith’s position to help power enterprise and AI-driven builds and mitigate emerging risks.

Why artifact management is in the spotlight

Cloudsmith sells a universal artifact management platform — the system of record for the software packages, container images and binaries that modern applications depend on. It supports dozens of package formats, integrates with enterprise identity and policy tooling, and increasingly doubles as a control plane for software supply-chain security.

The category has become strategically important for two reasons. First, regulators on both sides of the Atlantic — from the US executive order on improving cybersecurity to the EU’s Cyber Resilience Act — have pushed formal requirements for software bills of materials (SBOMs), provenance attestation and vulnerability response. Second, the explosion of AI-assisted code generation has dramatically increased the volume of third-party dependencies flowing into enterprise codebases, amplifying the risk surface that artifact-management platforms are designed to contain.

Cloudsmith’s pitch is that enterprises can no longer rely on a collection of format-specific repositories — one for npm, another for Docker, another for Python — stitched together with in-house policy scripts. The company is betting that a single cloud-native platform with deep security telemetry will win against both incumbents such as JFrog and Sonatype, and against open-source self-hosted tooling that has become difficult to govern at scale.

New product direction

Alongside the funding, Cloudsmith announced an expansion of its security stack. The company highlighted two core additions: continuous package enrichment, which continuously updates metadata, vulnerability intelligence and provenance for stored artifacts; and OPA-based policy management, which applies Open Policy Agent rules to artifact workflows. Features flagged include cool-down periods for newly published packages, exploitability-based prioritisation, deeper SBOM inspection and detection of malicious packages.

For enterprise security teams, the pitch is operational: less time triaging low-risk CVEs, more automated enforcement of policy, and a clearer audit trail for AI-generated code paths.

The competitive and regulatory picture

Cloudsmith’s main public competitors are JFrog, which went public in 2020, and Sonatype, which has remained private under Vista Equity Partners. Both command substantial enterprise footprints, but both were architected before the current wave of supply-chain legislation and AI coding workflows. Cloudsmith’s bet is that a newer, API-first architecture lets it move faster on the capabilities enterprise buyers now prioritise — particularly around SBOM, attestation and AI-specific risk controls.

For Belfast’s technology scene, Cloudsmith’s Series C is a significant moment. Northern Ireland’s startup ecosystem has produced a number of notable outcomes over the last decade but relatively few growth-stage software companies operating at this scale. The round will bring increased focus on Belfast’s talent base, particularly in cyber and developer tooling, and will put further pressure on local universities and government agencies to keep pace with hiring demand.

What to watch

The questions ahead for Cloudsmith concern durability more than direction. Growth-stage infrastructure rounds raise the bar on net dollar retention, multi-product adoption and enterprise penetration. The company will need to show that its AI-era security story converts into measurable platform stickiness — and that the artifact management layer becomes, as Weinstein argues, the mandatory chokepoint for compliant software delivery.

For Sesamers readers tracking European software infrastructure, Cloudsmith is one of the most interesting growth-stage stories on the continent: a European-built platform now backed by two of the most consequential American growth investors, positioned squarely at the intersection of regulation, AI and enterprise developer tooling.

Source: Tech.eu — Cloudsmith raises $72M Series C to secure the AI-era software supply chain (23 April 2026)

you might also like

Fundraising 2 hours ago

London-based AI laboratory Ineffable Intelligence has emerged from stealth with a $1.1 billion seed round at a $5.1 billion post-money valuation, the company confirmed on 27 April 2026. The financing is the largest seed round ever raised by a European company and one of the largest first-money-in rounds in the global history of artificial intelligence. The round was co-led by Sequoia Capital and Lightspeed Venture Partners. Participating investors included Nvidia, DST Global, Index Ventures, Google, and the UK Sovereign AI Fund, the British government’s recently established vehicle for backing strategic AI capacity on home soil. A bet on a different path to general intelligence Ineffable Intelligence was founded in 2025 by David Silver, the former Vice President of Reinforcement Learning at Google DeepMind and the principal architect of AlphaGo, AlphaZero and AlphaStar. He is joined by three further DeepMind alumni: Wojciech Czarnecki, Lasse Espeholt and Junhyuk Oh. All four have spent the past decade at the frontier of reinforcement learning research, the discipline behind some of the most consequential demonstrations of machine learning over the past ten years. The company describes its objective as building a “superlearner” — an AI system capable of acquiring knowledge directly from its own experience rather than from human-generated text or imagery. “Our mission is to make first contact with superintelligence,” Silver said in a statement accompanying the launch. “We are creating a superlearner that discovers all knowledge from its own experience, from elementary motor skills through to profound intellectual breakthroughs.” The framing is a deliberate departure from the dominant industry trajectory. Most leading AI laboratories, including OpenAI, Anthropic and Google DeepMind itself, have built large language models trained primarily on the corpus of the internet, then refined that training with human feedback. Ineffable’s wager is that the marginal returns on scaling text-based pretraining are diminishing and that the next leap in capability will come from agents that learn endlessly from the consequences of their own actions, in much the same way AlphaZero learnt the game of Go without studying any human matches. Why $1.1 billion at seed The size of the round is unusual even by the inflated standards of the 2026 AI capital cycle. Two factors appear to explain it. First, frontier reinforcement learning at the scale Ineffable describes is computationally extraordinarily expensive: the company will need to operate vast simulation environments and train very large models against them, an undertaking that consumes capital at a rate closer to physical R&D than to traditional software. Second, the round signals a strategic move by Europe’s investor and policy ecosystems to retain the most ambitious AI researchers on the continent. The presence of the UK Sovereign AI Fund alongside Sequoia, Lightspeed and Nvidia is the clearest expression of that intent. The British government has publicly framed the investment as a bet on breakthrough AI that “can discover new knowledge”, positioning the country as a willing co-investor in domestic frontier laboratories. For Ineffable, the implication is access not only to capital but to compute, regulatory engagement and the still-resilient academic talent base around UCL, Oxford, Cambridge and Imperial. Founder pledge of historic scale Alongside the funding announcement, Silver disclosed that he is committing 100 per cent of any personal proceeds from his Ineffable equity to charity via the Founders Pledge network — described by the organisation as the largest pledge in its history. At the round’s $5.1 billion valuation, that commitment could ultimately exceed several billion dollars if the company succeeds. It is a meaningful gesture in a sector where the reputational stakes around concentrated AI wealth are escalating, and one likely to be referenced in subsequent founder-led commitments. Implications for the European AI landscape Ineffable’s emergence reshapes the European AI map in three concrete ways. It establishes London as the home of the continent’s largest-ever seed-stage company, complicating Paris’s recent narrative of frontier-AI primacy after Mistral’s earlier rounds. It validates a thesis — that reinforcement learning, not transformer scaling, is the next frontier — that has lately been losing capital share to language-model incumbents. And it confirms that the UK government is now willing to act as a balance-sheet co-investor in domestic AI laboratories, a posture much closer to the French model than to the predominantly grant-based regimes elsewhere in Europe. The execution risk is non-trivial. Reinforcement learning at frontier scale has historically required years of careful environment design before producing competitive systems, and Ineffable’s “first contact” framing sets a high bar against which it will be judged. But for now, with a billion dollars on the balance sheet, four of the discipline’s most accomplished researchers in the founding team and a sovereign co-investor at its back, Ineffable Intelligence is the most heavily resourced new entrant in the European AI cycle. Sesamers covers European fundraising rounds across deeptech, fintech and AI. Source: tech.eu.

Fundraising 5 days ago

Belfast's Cloudsmith has raised $72M Series C led by TCV, with Insight Partners participating, to expand its artifact management platform and secure the AI-era software supply chain.

Fundraising 5 days ago

Berlin’s VREY has raised €3.3M seed led by Rubio Impact Ventures to roll out rooftop solar software for Germany’s multi-family buildings.

Subscribe to
our Newsletter!

Stay at the forefront with our curated guide to the best upcoming Tech events.