Manchester cybersecurity startup Cytix secured a $7M Series A led by Northern Gritstone to address the security gaps opening up as AI-assisted development floods codebases with unreviewed changes.
- Cytix's $7M Series A was led by Northern Gritstone, with Auriga Cyber Ventures and NPIF II - PXN Equity Finance participating.
- The company's change risk platform is already embedded in managed service programmes run by KPMG and NCC Group.
- Cytix was founded in 2022 and targets a market where AI coding tools have outpaced traditional security review cycles.
Lead
Manchester-based Cytix announced a $7M Series A on August 12, 2026, led by Northern Gritstone, the venture capital firm backing science and technology companies in the north of England. Existing investors Auriga Cyber Ventures and NPIF II - PXN Equity Finance - the latter managed by PXN Ventures as part of the Northern Powerhouse Investment Fund II - also participated. The round will fund the rollout of Cytix's newly launched change risk platform and expand its headcount. No valuation was disclosed.
What Does Cytix Actually Do?
Cytix sits between a software team's ticketing and source control systems and its security function, reading the context behind every ticket, pull request, and release to determine which changes carry genuine risk. The platform is designed to answer three questions automatically: whether a change warrants security attention, what level of risk it introduces, and what action is proportionate. It produces an evidence trail that risk and compliance teams can use when required.
The product targets a specific operational gap. Application security testing has historically operated on a periodic basis - scans before releases, penetration tests on a quarterly cycle. AI-assisted development, agentic workflows, and continuous delivery pipelines now push code far faster than those schedules accommodate. Cytix's pitch is continuous oversight rather than periodic snapshots.
Why Did Northern Gritstone Back This Round?
Northern Gritstone's investment signals confidence that the AI-driven development problem is real enough, and sticky enough, to support a dedicated platform category. The firm focuses on northern England's deep-tech ecosystem and this marks a continuation of a pattern - backing companies that address infrastructure problems created by broader technology shifts rather than consumer-facing applications. Whether the market is large enough to sustain an independent vendor, or whether the eventual acquirers are the security majors or platform players already in the application security space, is an open question.
The co-investors' continued participation matters. Auriga Cyber Ventures is a specialist fund in the cybersecurity sector, suggesting Cytix's technology has passed scrutiny from investors with narrow domain focus, not just generalists chasing a trend.
How Embedded Is the Business Already?
Cytix counts KPMG and NCC Group not as named reference customers but as distribution partners. Both firms run managed security service programmes built on Cytix's platform, handling continuous change-risk assessment for their respective enterprise clients. That structure means Cytix's revenue is partly gated on the volume and growth of its partners' own client bases - a channel dependency that carries both reach and risk. If those partners develop competing capabilities internally, the relationship dynamic shifts.
Founded in 2022 by Ben Armstrong, Thomas Ballin, and Matt Milan, Cytix is still early-stage by conventional measures. The Series A comes roughly four years after founding, which in the current environment suggests the team took time to validate the product with paying partners before seeking institutional capital at scale.
What Comes Next for AI Code Security?
The category Cytix occupies is genuinely contested. Several established application security vendors have extended their products toward continuous monitoring of software changes, and a wave of AI-native security startups is targeting similar buyer pain. The differentiating claim for Cytix is context-awareness - the ability to interpret change meaning rather than just scan for known vulnerability patterns.
Enterprise buyers in regulated industries are under pressure from auditors and regulators to demonstrate that AI-generated code is subject to the same controls as human-written code. That regulatory tailwind is not guaranteed to remain, but for now it creates a purchasing motive that pure efficiency arguments rarely do.
Outlook
Cytix's $7M round positions a well-partnered, early-stage vendor inside a market that is forming rapidly. The Northern Gritstone backing adds institutional credibility in a geography that has historically struggled to produce venture-scale security companies. The channel model with KPMG and NCC Group gives the company market access without building a full enterprise sales function immediately, but it also means growth is not fully in Cytix's own hands. The next measure of progress will be whether the company can convert partner-sourced deployments into direct enterprise relationships as the platform matures.



