Curious about today's AI digest?ai-tldr.dev

Daily Digest

Pomegra Startups

Cytix Pulls $7M to Police AI Code Risk

Manchester cybersecurity startup Cytix raises $7M Series A led by Northern Gritstone for its platform that continuously monitors and validates security risk in every AI-driven software change, with KPMG and NCC Group among its customers.

CybersecurityNOTABLE4 min read
Cytix Pulls $7M to Police AI Code Risk

Manchester cybersecurity startup Cytix closed a $7M Series A led by Northern Gritstone to expand its platform monitoring security risk across every AI-driven software change.

  • Cytix raised $7M Series A led by Northern Gritstone; Auriga Cyber Ventures and NPIF II - PXN Equity Finance also participated.
  • The Change Risk Platform monitors and validates security risk continuously in AI-generated and AI-modified code, targeting enterprise and regulated sectors.
  • KPMG and NCC Group already embed the platform within their managed security service offerings.

The Deal

Cytix, a Manchester cybersecurity company founded in 2022 by Ben Armstrong, Thomas Ballin, and Matt Milan, closed a $7 million Series A on August 12, 2026. Northern Gritstone, the £382 million northern England deep tech fund, led the round. Existing investors Auriga Cyber Ventures and NPIF II - PXN Equity Finance, managed by PXN Ventures as part of the Northern Powerhouse Investment Fund II, also participated. Cytix has not disclosed a post-money valuation. The prior seed of £1.6 million brings total capital raised to roughly £6.8 million.

The round is modest by US standards but consistent with early commercial-stage enterprise software raises in the UK. At this stage, the money goes toward go-to-market expansion and enterprise customer acquisition, not scaling an established revenue base.

What Does Cytix Actually Do?

The company's Change Risk Platform sits between an organisation's software development lifecycle and its security, risk, and compliance functions. Every time code is written, modified, or deployed, Cytix analyses the change for security exposure, determines what level of testing or remediation is proportionate, and generates compliance evidence. The platform reached general availability on August 12, concurrent with the funding announcement.

KPMG and NCC Group have already integrated the platform into their managed security programmes. Enterprise and regulated-sector clients can access it directly from Cytix or through those partners, which effectively gives the company a distribution channel built on existing relationships rather than a direct sales team it would otherwise need to build from scratch.

Why Is AI-Assisted Coding a Security Problem?

AI coding tools dramatically increase the volume and velocity of software changes. Development teams using AI assistance can produce far more code per day than was previously possible. Traditional security reviews cannot match that pace. Vulnerability density does not shrink because code is generated faster. AI tools carry their own risk categories - insecure patterns inherited from training data, opaque logic, and misconfigured implementations of security-sensitive features like authentication and input validation.

Cytix's argument is that point-in-time penetration testing cannot address a problem that moves continuously. Its platform decides autonomously which changes need deep security engagement and which do not, surfacing risk signals to human teams rather than routing every commit through a manual queue that would immediately become a bottleneck.

Strategic Context

Northern Gritstone's typical portfolio is built around spinouts from the universities of Manchester, Leeds, and Sheffield. Cytix is a venture-backed founding team, not a research spinout. The investment suggests the fund is willing to back commercially-proven companies with northern roots, not only those carrying university IP.

The round arrives during a broader enterprise push to close what security buyers increasingly describe as the AI change gap - the growing distance between how fast software changes and how fast security programmes can evaluate it. Financial services, professional services, and critical infrastructure operators face direct regulatory pressure to demonstrate continuous assurance. An annual audit cycle, once sufficient, now looks defensively inadequate in front of regulators who have been watching AI-generated code enter production environments at scale.

NCC Group's partnership is particularly pointed context. The firm built its reputation on human-led offensive security. Integrating Cytix means it is acknowledging that manual testing cadences cannot cover the full surface area of AI-assisted development pipelines.

Outlook

Cytix's immediate task is converting partnership distribution into accountable revenue - customer depth within the KPMG and NCC Group base, not just logo count. The structural risk for the category is whether enterprise buyers consolidate around specialist change-risk platforms or fold the requirement into broader application security stacks offered by larger vendors. At under £7 million in total capital raised, Cytix has limited runway to absorb an extended enterprise sales cycle. The next funding test, whenever it comes, will hinge on whether customer expansion data can do what partnership announcements cannot: demonstrate that the platform compounds value over time rather than solving a narrow onboarding problem.

More Startup News