Bloom Security Raises $20M Seed to Bring Visibility and Control to the AI-Native Endpoint

Bloom Security raises $20M to secure AI agents, MCP servers, browser extensions and code across the modern enterprise endpoint.
Bloom Security team Bloom Security team

AI is changing more than how employees work. It is also changing what the enterprise endpoint looks like, and creating a security problem that many existing tools were never designed to solve.

Bloom Security has emerged from stealth with a $20 million seed round led by Glilot Capital Partners, with participation from Ten Eleven Ventures (1011vc), Okta Ventures, and Runtime Ventures. Axios first reported about the company’s launch and funding. The Tel Aviv-based startup is focused on securing the growing collection of AI agents, MCP servers, browser extensions and code packages now operating across corporate endpoints.

The funding round also includes prominent angel investors, including founders of Dig Security, Demisto, Snyk and Talon. Bloom said its platform is already deployed at dozens of large enterprises across the United States and Europe.

Advertisement

The New Endpoint Is Harder to Govern

The traditional endpoint security model was built around predictable devices and a relatively controlled software environment. Endpoint detection and response products focused primarily on threats such as malware, malicious processes and suspicious executables.

That environment is becoming more difficult to manage. Employees can now assemble software ecosystems around their work, while browsers, IDEs and AI agents offer marketplaces and app stores that accelerate the spread of new tools. The resulting risks may come not from malware, but from legitimate software with excessive permissions, insecure configurations or unexpected access to sensitive systems.

“In the AI era, the employee device is no longer just a managed endpoint,” said Itay Keren, Co-Founder and CEO of Bloom Security. “Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”

Bloom’s platform is designed to provide visibility into everything running across an organization’s endpoints, including tools, extensions and code. It also analyzes supply-chain risk, configurations and permissions, as well as how software interacts with data and systems.

Risk Depends on Where Software Runs

Bloom’s approach centers on contextual risk assessment. The company argues that a tool cannot always be classified as safe or risky without understanding the environment in which it operates.

“The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”

The platform is designed to give security teams control over the software environment as well. According to Bloom, organizations can block risky installations before they reach employee endpoints, enforce secure configurations and remediate risks without manual approval workflows or disruption to employees.

That combination of visibility and enforcement is aimed at enterprises adopting AI at scale. Rather than relying on rigid, blanket policies, Bloom says its customers can use contextual information to identify and remediate risks across their endpoint environments.

A Familiar Security Team Tackles an Emerging Category

Bloom’s founding team brings experience from some of the enterprise security industry’s established companies. CEO Itay Keren previously held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security and Demisto. Chief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks and previously worked at Dig Security and XM Cyber.

Chief Technology Officer Itay Frishman built AISPM and DSPM solutions at Palo Alto Networks and Dig Security, with prior cybersecurity R&D leadership experience in IDF’s Unit 81. Bloom now has 30 employees, many of whom previously worked together at Dig Security.

“While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Itay Frishman, Co-Founder and CTO. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”

Bloom’s investors see the shift toward AI-powered work as an opportunity to establish a new approach to endpoint security. Kobi Samboursky, Founder and Managing Partner at Glilot Capital, said the company is addressing a gap created by the rapid expansion of software running on employee devices.

“AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee’s machine, entirely outside the reach of traditional controls,” said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. “Bloom identified this gap before the market did, and the business traction we’ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.

With $20 million in new funding, a 30-person team and deployments at dozens of large enterprises, Bloom is now building around a premise that could become increasingly important as AI adoption expands: securing the endpoint may require understanding not just what is malicious, but everything that is running, and the context in which it operates.

 

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Advertisement

Pin It on Pinterest

Share This