Kusari
Kusari provides a source-built software supply chain security platform (Trust Fabric) unifying SBOMs, attestations, and vulnerability data with AI-powered PR review, natural-language querying, and autonomous remediation. It serves regulated enterprises in healthcare, financial services, and government via subscription SaaS, while offering free tooling to developers and open source projects.
- Company typePrivate
- Founded2022
- HeadquartersRidgefield, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Kusari does
Kusari, Inc. is a venture-backed software supply chain security company founded in 2022 and headquartered in Ridgefield, Connecticut (Delaware-incorporated). The company's core offering is the Kusari Trust Fabric — a source-built knowledge graph that ingests SBOMs, attestations, vulnerability streams, and dependency relationships from existing security tooling (Black Duck, GHAS, Dependabot, Prisma, CycloneDX, SPDX, VEX, deps.dev, OSV) and normalizes them into a continuously updated, queryable single source of truth. Four product surfaces sit atop the Trust Fabric: the Kusari Platform (full transitive dependency graph, provenance, reachability, exploitability, audit history), Kusari Inspector (autonomous AI-powered PR reviewer with a proprietary Kusari Score weighting reachability, exploitability, and blast radius), Kusari Agent (MCP-ready natural-language query interface for zero-day incident response), and Kusari AutoFix (autonomous remediation that submits working fix PRs). The company also maintains GUAC, an open source knowledge graph project co-created with Google and Purdue University, now an OpenSSF Incubating Project with 50+ contributors.
Kusari operates a hybrid go-to-market: a freemium product-led growth motion via free Kusari Inspector access for individual developers, CNCF-hosted projects, and OpenSSF projects, combined with enterprise direct sales targeting CISOs and security leaders in regulated industries through 30-minute working demos, proof-of-value engagements, and ROI calculator-driven business cases. Named customers and partners span healthcare (BCBS Affiliate, Roche), financial services (DTCC, SS&C), insurance (Guidewire), and technology (Google, Yahoo, VMware, ClearAlpha, Red Hat ecosystem). The commercial pricing model is quote-based annual subscription, per seat or per organizational tier; pricing is not publicly disclosed.
The company is led by co-founders Tim Miller (CEO, ex-Citi/MUFG/Bridgewater), Michael Lieberman (CTO, OpenSSF TAC and SLSA Steering Committee member, co-creator of GUAC and FRSCA), and Parth Patel (CPO, GUAC lead maintainer, in-toto and FRSCA maintainer). The founders co-authored the open standards (SLSA, in-toto, OSPS Baseline, GUAC) that underpin modern software supply chain security and serve in OpenSSF leadership roles (Governing Board, TAC, SLSA Steering). As of January 2024, Kusari has raised $8 million in combined Pre-Seed and Seed funding led by J2 Ventures and Glasswing Ventures, with participation from Unusual Ventures. The company has 11–50 employees and operates with global distribution via GitHub App, GitLab, Bitbucket, Azure DevOps, Jenkins, and CircleCI integrations.
Kusari firmographics
Firmographics- Name
- Kusari
- Legal name
- Kusari, Inc.
- Website
- https://kusari.dev
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Kusari provides a source-built software supply chain security platform (Trust Fabric) unifying SBOMs, attestations, and vulnerability data with AI-powered PR review, natural-language querying, and autonomous remediation. It serves regulated enterprises in healthcare, financial services, and government via subscription SaaS, while offering free tooling to developers and open source projects.
- Ownership category
- akta.pro rank
Kusari industry classification
Industry- Product category
- Software Supply Chain Security
- NAICS
- Software Publishers (5132), Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Software Supply Chain & Dependency Security (SBOM, Signing) (HDADACAD)
- akta.pro secondary industries
- AI Supply Chain Security & SBOM/Model Provenance (artifacts, lineage) (HDAAAKAG), Container & Kubernetes Application Security (HDADACAE), Cloud Security for Containers & Kubernetes (KSPM/Kubernetes Security) (HDABAHAO)
Keywords
Where Kusari is headquartered
LocationHeadquarters
- HQ city
- Ridgefield
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Kusari business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Infrastructure, Operations
Revenue model
- Kusari Platform Subscription: Commercial SaaS subscription to the Kusari Trust Fabric platform, providing enterprise-grade dependency intelligence, SBOM management, autonomous remediation, AI-powered querying, and continuous supply chain visibility. Priced per seat or by tier based on organizational scale. Enterprise deals include proof-of-value engagements and annual contracts.
- Kusari Inspector (Freemium / Free Tier): Kusari Inspector is offered free to individual developers, open source maintainers, CNCF-hosted projects, and OpenSSF projects. Free access enables broad developer adoption and bottom-up PLG motion. The free tier converts to paid commercial use at the organizational level.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free tier for developers and OSS maintainers |
| Subscription | Annual | Commercial platform subscription |
Go-to-market motion4 records
Distribution channels4 records
Marketing channels8 records
Kusari product offering
Product offeringCore offering
Kusari provides a software supply chain security platform built on the Kusari Trust Fabric, a living knowledge graph that unifies SBOMs, attestations, vulnerability streams, and dependency relationships into a single source of truth. The platform is exposed through four surfaces: Kusari Inspector (autonomous PR security reviewer), Kusari Agent (natural-language query interface), Kusari AutoFix (autonomous remediation), and the core Platform (command and control center for transitive dependency visibility, provenance, reachability, and exploitability analysis). Kusari also maintains GUAC, an open source knowledge graph project co-created with Google and now an OpenSSF Incubating Project.
Product overview
Kusari offers a platform-plus-modules architecture built on the Trust Fabric intelligence layer. The core Kusari Platform serves as the command and control center for software supply chain security, unifying existing tools and normalizing data into a single source of truth. Four integrated surface products work together: Kusari Inspector (shift-left autonomous PR reviewer), Kusari Agent (natural language query interface), Kusari AutoFix (autonomous remediation), and the Foundation Platform (full transitive graph, provenance, reachability analysis). The company also maintains GUAC, an open source knowledge graph tool developed with Google and now an OpenSSF Incubating project.
Differentiator
Problem solved
Functional benefit
Brands
- Kusari Platform: The software supply chain command and control center that provides full transitive graph, provenance, reachability, exploitability, dependency search, and audit history capabilities.
- Kusari Inspector
- Kusari Agent
- Kusari AutoFix
- Kusari Trust Fabric
- GUAC (Graph for Understanding Artifact Composition)
Products and services
- Kusari Platform Software supply chain command and control center providing continuous, source-built, enriched security intelligence with agentic risk analysis and exploitability context across full transitive dependency graphs. Targets enterprise security teams in regulated industries.
- Kusari Inspector Autonomous security reviewer embedded in every pull request, providing thumbs up or down on code changes with transitive dependency visibility, Kusari Score analysis, and fix-in-context remediation guidance before anything reaches main. Available via GitHub App, CLI, IDE, and coding-agent surfaces.
- Kusari Agent Natural-language query interface against the entire software estate with zero lag, enabling instant answers about vulnerability presence, blast radius mapping, and ownership routing. MCP-ready for LLM stack integration.
- Kusari AutoFix Autonomous remediation capability that traces vulnerabilities to root cause, models full dependency trees, accounts for environment constraints, and submits working fix PRs with approval workflows.
- GUAC (Graph for Understanding Artifact Composition) Open source tool created in partnership with Google that aggregates software security metadata into a high-fidelity graph database to locate, store, analyze, and correlate software artifact data. Now an OpenSSF Incubating Project.
Quantifiable outcome
- 30–50% reduction in CVE triage and remediation engineering time (estimated $630K–$1.05M reclaimable capacity for a 1,000-dev technology company)
- +5 more outcomes
Companies that use Kusari
Customer profileNamed customers10 records
Segments3 records
Ideal customer profiles3 records
Kusari technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration19 records
AI capability10 records
Feature6 records
Kusari partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered flagship, core and minor.
- Cloud Native Computing Foundation (CNCF)flagshipCNCF and Kusari announced a partnership to provide free access to Kusari Inspector (AI-powered security tool) for all CNCF-hosted projects. The tool combines AI-assisted code review with dependency analysis to identify risks across direct and transitive dependencies, shifting security 'left' into developer workflows.
- Open Source Security Foundation (OpenSSF)flagshipKusari partnered with OpenSSF to offer Kusari Inspector at no cost to all OpenSSF projects. Kusari's co-founders serve on the OpenSSF Governing Board and Technical Advisory Council. OpenSSF also announced $12.5 million in grant funding from leading AI providers to support sustainable AI security initiatives including Alpha-Omega.
- GooglecoreGoogle partnered with Kusari to co-create GUAC (Graph for Understanding Artifact Composition), which is now an OpenSSF Incubating Project. Google is listed as a standards-trusted company alongside Microsoft, Intel, Citi, and Red Hat that use the open standards Kusari founders co-created.
- Purdue UniversitycorePurdue University collaborated with Kusari (alongside Google) to architect and initially develop GUAC. Purdue is listed as a commercial and academic partner of Kusari.
- YahoocoreYahoo is a commercial and open source partner supporting GUAC development. Yahoo is among the industry-leading companies backing GUAC alongside Google, Microsoft, Red Hat, Guidewire, and ClearAlpha.
- Guidewire SoftwarecoreGuidewire is a commercial partner and open source contributor supporting GUAC. Guidewire uses Kusari tools for its own software supply chain security and is cited as a case study for GUAC adoption in the insurance sector.
- ClearAlpha TechnologiescoreClearAlpha Technologies is a commercial and open source partner supporting GUAC development. ClearAlpha specializes in financial services technology and supply chain security.
- Red HatcoreRed Hat is listed as a company that trusts and uses the open standards (GUAC, SLSA, in-toto) co-created by Kusari's founders. Red Hat is part of the ecosystem of standards adopters alongside Google, Microsoft, Intel, Citi, and Ford.
- VMwareminorVMware is listed as a commercial partner of Kusari alongside Yahoo, DTCC, Guidewire, Roche, and ClearAlpha, indicating use of Kusari's supply chain security solutions.
- DTCCminorDTCC (Depository Trust & Clearing Corporation) is listed as a commercial partner of Kusari. As a major financial market infrastructure company, DTCC represents a reference customer in the financial services sector.
- RocheminorRoche is listed as a commercial partner of Kusari. As a major pharmaceutical and diagnostics company, Roche represents a reference customer in the healthcare sector.
Scale indicators6 records
Recent moves6 records
Expansion highlights8 records
Kusari competitors and assessment
Company assessmentDirect peers
- Anchore: Anchore is an SBOM-centric software supply chain security and container compliance platform. It competes with Kusari on SBOM generation, vulnerability management, and FedRAMP/DOD-grade compliance use cases.
- Snyk: Snyk is the leading developer-first software composition analysis (SCA) and application security platform, offering dependency vulnerability scanning, SBOM, and fix advice. It directly competes with Kusari's Trust Fabric and Inspector in the same AppSec buyer and developer persona.
- Mend (formerly WhiteSource): Mend is an enterprise AppSec platform offering SCA, SBOM, and container security. It overlaps directly with Kusari on dependency scanning, SBOM management, and supply-chain visibility for regulated industries.
- Chainguard: Chainguard secures the software supply chain from build through runtime with hardened base images, signed artifacts, and supply-chain security tooling. It targets the same regulated-enterprise and platform-engineering buyers as Kusari and overlaps on SBOM, provenance, and supply-chain integrity.
- Endor Labs: Endor Labs focuses on software dependency management, reachability analysis, and supply-chain security for enterprise development teams. It competes with Kusari on transitive dependency visibility and reachability-based prioritization rather than raw CVSS noise.
- Sonatype: Sonatype operates Nexus Lifecycle and Nexus IQ, the de facto enterprise SCA platform for open-source dependency management, SBOM, and policy enforcement. It is the legacy incumbent Kusari competes against in regulated enterprise AppSec.
Emerging players
- Ox Security: Ox Security is an ASPM platform that aggregates findings across scanners, with overlap to Kusari Trust Fabric's "single source of truth" thesis. It competes more on the security-operations consolidation layer than on PR-time review.
- Socket: Socket provides developer-first detection of malicious and risky open-source packages, overlapping with Kusari Inspector's pull-request shift-left motion. It is a more focused emerging alternative rather than a full AppSec suite.
Broad incumbents
- GitHub Advanced Security: GitHub Advanced Security bundles Dependabot, CodeQL, and secret scanning natively into the GitHub workflow used by most enterprises. It is a broad incumbent that competes with Kusari Inspector on dependency and code scanning inside the same PR surface.
- JFrog Xray: JFrog Xray is the security and compliance module of the JFrog Artifactory platform, providing SCA, container scanning, and SBOM. It is a broad incumbent that overlaps with Kusari in regulated enterprise artifact and dependency security.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights6 records
Customer concentration
Kusari social profiles
Digital presenceKusari compliance and trust
Trust signalCompliance10 records
Kusari financial estimates
Financial estimateRevenue estimate
Valuation estimate
Kusari leadership team
Management profileNumber of profiles
Profiles4 records
Kusari funding detail
Funding detailFunding overview
Funding rounds2 records
Investors4 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Kusari M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Kusari
What does Kusari do?
Kusari provides a software supply chain security platform built on the Kusari Trust Fabric, a living knowledge graph that unifies SBOMs, attestations, vulnerability streams, and dependency relationships into a single source of truth. The platform is exposed through four surfaces: Kusari Inspector (autonomous PR security reviewer), Kusari Agent (natural-language query interface), Kusari AutoFix (autonomous remediation), and the core Platform (command and control center for transitive dependency visibility, provenance, reachability, and exploitability analysis). Kusari also maintains GUAC, an open source knowledge graph project co-created with Google and now an OpenSSF Incubating Project.
Is Kusari a public or private company?
Kusari is a private company. It is classified as venture growth investor backed and is currently operating.
When was Kusari founded?
Kusari was founded in 2022. It employs 11 to 50 people.
Where is Kusari based?
Kusari is headquartered in Ridgefield, United States, in the North America region.
How does Kusari make money?
Two revenue lines are on record. Kusari Platform Subscription is the primary driver. The others are kusari Inspector (Freemium / Free Tier).
Who are Kusari's main competitors?
Direct peers on record are Anchore, Snyk, Mend (formerly WhiteSource), Chainguard, Endor Labs and Sonatype. Emerging players are Ox Security and Socket. Broad incumbents are GitHub Advanced Security and JFrog Xray.
Does Kusari have an API?
No public API is recorded for Kusari.
What industry is Kusari in?
Kusari's product category is Software Supply Chain Security. Its primary akta.pro industry code is HDADACAD, Software Supply Chain & Dependency Security (SBOM, Signing), with a secondary code of HDAAAKAG, AI Supply Chain Security & SBOM/Model Provenance (artifacts, lineage). Its NAICS code is 5132 and its SIC code is 7373.