The cloud-native registry where software packages get stored, secured, and shipped - now built for the age of AI-written code.
Cloudsmith - the artifact registry, reimagined cloud-native.
Belfast → New York · 2016
The Story
Every modern application is assembled, not just written. It pulls in open source packages, container images, internal libraries and build artifacts - thousands of them, from dozens of ecosystems. For years the place all of that lived, the artifact registry, was treated like plumbing: necessary, invisible, and rarely questioned. Cloudsmith's bet, from a standing start in Belfast in 2016, was that the registry is actually the single best place to see and govern everything a company ships.
Cloudsmith is a fully managed, cloud-native artifact management platform. In plain terms, it is a private registry that stores software packages and containers across more than 30 formats - npm, Docker, Maven, PyPI, Debian, Conan, CocoaPods, Vagrant, raw files and more - in one place. But storage is only the entry ticket. As packages move through, Cloudsmith scans them for known vulnerabilities and malware, enforces policy, can quarantine anything that fails a rule, signs and promotes trusted artifacts, and distributes them globally so builds pull dependencies quickly wherever they run.
The company was founded by Alan Carson and Lee Skillen, who ran into artifact-management pain while working at the New York Stock Exchange's Belfast operations. The existing tools were heavy, self-hosted and slow to move. They built the alternative they wanted, then turned it into a business. Since August 2023 the company has been led by CEO Glenn Weinstein, who previously spent nearly four years as a customer-facing executive at Twilio; Carson moved into a Chief Strategy Officer role.
By The Numbers
Figures compiled from public sources; some are approximate.
The Problem
The problem Cloudsmith addresses has been growing for a decade and is accelerating. Open source now makes up the bulk of most codebases, and a large share carries real risk - by one widely cited figure, 81% of codebases contain high- or critical-risk open source vulnerabilities. Every dependency is also a potential entry point for a supply chain attack, where a compromised package slips into thousands of downstream builds.
AI coding agents sharpen the point. They generate and pull in dependencies faster than any team can manually review, which is exactly why Cloudsmith has reframed its pitch around governing AI-produced software. The registry becomes the last practical place to say "no" before an untrusted artifact reaches a build.
"Cloudsmith is the only platform built for the way software is being developed today - by AI agents." Glenn Weinstein, CEO
"Cloudsmith serves as a private registry for these binary artifacts, so they're always available for future builds." Glenn Weinstein, CEO
Products & Services
A universal registry for 30+ formats plus raw files, with multi-format repositories, upstream proxying and caching, and package promotion and signing.
Docker-compatible, OCI-compliant storage and distribution for container images, living alongside every other artifact format.
Vulnerability and malware scanning, policy-as-code via OPA Rego, automatic quarantine and approval flows - a firewall between open source and your builds.
Global delivery across ~600 points of presence with edge caching, fault tolerance, end-to-end encryption and read-only distribution tokens.
Usage analytics, full audit trails, license and dependency metadata, SBOM support, plus SAML/SSO, SCIM and OIDC authentication.
An API-first architecture with a CLI and Terraform provider so teams can automate repositories and policies as code.
Funding
The trajectory tracks the market. A 2021 round - landmark funding for Northern Ireland's tech scene - was followed by a Series A extension in 2023, a $23M Series B in 2025, and a $72M Series C in April 2026. That most recent round, again led by growth investor TCV with Insight Partners, brought total funding to roughly $126M and, per reports, positioned Cloudsmith close to the $1 billion valuation mark.
Roughly three-quarters of revenue comes from US customers, and the company has used its capital to expand sales, marketing and customer success while investing in AI features that help developers choose safer open source packages.
Where It Fits
The artifact-management category was defined by JFrog's Artifactory and Sonatype's Nexus, tools many enterprises still run themselves. Cloudsmith competes by being fully managed and cloud-native from the ground up: no servers to operate, a global distribution network built in, an API-first design, and security and policy woven through the platform rather than bolted on. It also contends with GitHub Packages and cloud-provider registries such as AWS CodeArtifact and Google Artifact Registry.
Its business model is straightforward B2B SaaS - subscription tiers from self-serve up to enterprise contracts, also available through AWS Marketplace. The buyers are engineering and platform teams that ship a lot of software and need one governed place to manage it.
The registry stopped being plumbing. Cloudsmith made it the place to see, secure and prove everything a company ships. Cloudsmith's core thesis
Customers & Milestones
Cloudsmith's customers are enterprise and high-growth engineering teams. Named names include Shopify, HP, PagerDuty, Font Awesome and EnterpriseDB, alongside a growing set of Fortune 500 and Global 2000 companies migrating off legacy tools. Its user base spans Europe, the Middle East, Australia and North America.
Timeline
Alan Carson and Lee Skillen launch Cloudsmith to fix the artifact pain they hit at NYSE's Belfast operations.
Landmark funding for Northern Ireland, with plans to create dozens of new jobs.
An $11M extension, and ex-Twilio executive Glenn Weinstein appointed CEO.
Capital fuels supply chain security features and US market expansion.
Its largest round, led by TCV with Insight Partners, to secure the AI-powered software supply chain.
FAQ
Cloudsmith is a cloud-native artifact management platform - a fully managed, private registry where engineering teams store, secure, and distribute software packages and containers across 30+ formats, with built-in vulnerability scanning, policy enforcement, and global delivery.
It was founded in 2016 in Belfast, Northern Ireland by Alan Carson and Lee Skillen. It's now led by CEO Glenn Weinstein, with a growing US presence.
Roughly $126M total, including a $26M Series A, a $23M Series B in 2025, and a $72M Series C in April 2026 led by TCV with Insight Partners. It's reported to be approaching a $1 billion valuation.
Its main competitors are JFrog (Artifactory) and Sonatype (Nexus), along with GitHub Packages and cloud-provider registries like AWS CodeArtifact and Google Artifact Registry.
Enterprise and high-growth engineering teams, including named customers like Shopify, HP, PagerDuty, Font Awesome and EnterpriseDB, plus a growing set of Fortune 500 and Global 2000 companies.
Watch
Links