Deals · Cybersecurity
Cytix raises €6M Series A to manage security risk where AI-driven development moves fastest
A Manchester-based cybersecurity platform that reads the full context of software changes — tickets, pull requests, deployments — and identifies where AI-accelerated development introduces security risk before it reaches production.
“Software change is becoming a key risk for organisations and those that build software need a solution that scales with the current pace of development.”
Cytix (Manchester) has raised €6 million / $7 million in a Series A led by Northern Gritstone, with Auriga Cyber Ventures and NPIF II – PXN Equity Finance (managed by PXN Ventures as part of the Northern Powerhouse Investment Fund II) increasing their existing commitments alongside. The company was founded in 2020 by Ben Armstrong (CEO) and builds a platform for managing the security risk that software changes introduce — at the point of the change itself, not after deployment.
The problem Cytix is solving
The pace of AI-assisted software development has outrun traditional security review. Teams that previously shipped ten changes a week now ship a hundred; the code volume that AI tools generate exceeds what human reviewers can inspect line-by-line at the rate it arrives. The standard response — automated code scanning — identifies vulnerabilities in the code itself but cannot assess the significance of the change in its operational context. A one-line patch to an authentication library carries more risk than a thousand-line refactor of a batch reporting job; code scanners see neither the ticket that prompted the patch nor the system it touches.
Cytix's platform reads the full context a change carries: the Jira or Linear ticket it resolves, the pull request description, the branch name, the deployment configuration, the system component it affects. It then applies its risk model to that context — who changed what, why, and where it goes — and produces a risk score the moment the change is initiated, not after it ships. Partners NCC Group and KPMG deliver the output through managed services to customers in enterprise and regulated sectors, where change risk is already a governance obligation under frameworks like SOC 2 and ISO 27001.
Northern Gritstone and the northern England thesis
Northern Gritstone — the fund that backs deep-tech companies anchored in northern England — led Cytix's Series A having already backed Sheffield's Pixel-Flo in a Seed round earlier this year. Two investments in 2026, two northern English companies solving specific, bounded technical problems: the pattern is consistent with a fund explicitly constructed around the thesis that world-class technology companies can build from Manchester, Leeds, and Sheffield without relocating to London. Cytix's managed-service route to market via NCC Group and KPMG — both with national and international reach — reduces the geographic constraint that often limits northern English B2B startups.
Duncan Johnson, CEO of Northern Gritstone, framed the investment as a direct response to the pace of AI adoption in software engineering: "The explosion of AI-assisted software development has led to a race to ensure software implementation remains secure. Cytix's platform aims to help enterprises take a realistic approach, recognising where change carries the most risk whilst allowing businesses to innovate."
What the capital is for and what comes next
The Series A funds two things: the accelerated rollout of Cytix's newly launched change risk management platform, and expansion into enterprise and regulated-industry customers where change governance is a compliance requirement rather than a best practice. The company's initial commercial base includes enterprise technology teams and software-intensive regulated businesses in the UK.
The 18-month test is whether Cytix can define "change risk" precisely enough to produce a decision, not merely a flag. A risk score is only useful if someone knows what to do with it — and the platform currently sits at the intersection of the engineering team (who own the change) and the compliance team (who own the audit). Enterprise buyers will ask which budget line it belongs to. The answer to that question shapes the sales cycle more than the product does.
Sources
Threaded to this story
Cybersecurity ·
Mindgard raises €26M Series A to turn AI red-teaming expertise into enterprise security infrastructure
€26M · Series A
Cybersecurity ·
Ossprey raises $2.65M to scan open-source packages for malicious code before it reaches production
€2.4M · Pre-Seed
Cybersecurity ·
Xentra raises £2.7M to scale managed cybersecurity for UK SMEs
€3.2M
Every European round, in your inbox by 8am.
The day's seed and Series A rounds across France and Europe — threaded, sourced, and read in two minutes. Free.