Bloom Security Emerges With $20M Seed to Protect the Expanding AI-Native Endpoint
The traditional corporate endpoint was built around a simple premise: organizations knew which devices employees used and could largely control the software installed on them. That model is becoming harder to maintain as AI agents, browser extensions, MCP servers and code packages become embedded in daily work.
Bloom Security is launching with the goal of addressing that growing complexity. The Tel Aviv-based company has emerged from stealth with a $20 million seed round led by Glilot Capital Partners, with participation from Ten Eleven Ventures (1011vc), Okta Ventures, and Runtime Ventures. Axios first reported about the company’s launch and funding.
The funding also includes prominent angel investors, including the founders of Dig Security, Demisto, Snyk and Talon. Bloom said its platform is already deployed at dozens of large enterprises across the United States and Europe, giving the startup an early foothold as companies look for ways to manage the security implications of rapid AI adoption.
The New Software Perimeter
The challenge Bloom is targeting goes beyond the traditional definition of endpoint security. Employees are increasingly assembling their own software environments through AI tools, extensions and other applications, while browsers, IDEs and AI agents introduce marketplaces that can expand the number of tools operating on a corporate device.
For security teams, the issue is not necessarily that these tools are malicious. Instead, legitimate software can become a source of risk because of how it is configured, what permissions it receives or how it interacts with other systems and data.
“In the AI era, the employee device is no longer just a managed endpoint,” said Itay Keren, Co-Founder and CEO of Bloom Security. “Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”
Bloom points to a range of potential risks, including AI agents with incorrect configurations, plugins that have excessive data permissions, screen recorders operating on executive devices and code libraries that pull from untrusted sources. These scenarios can create attack paths that traditional endpoint detection and response products may not have been designed to identify or manage.
“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren added. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”
Understanding Risk in Context
Bloom Security’s platform is designed to give organizations a broad inventory of what is running across their endpoints, including software, tools, extensions and code. It also examines how those components interact with data and systems and analyzes supply-chain risk, configurations and permissions.
The company is taking a contextual approach to determining exposure. Its premise is that the risk associated with a particular application can vary significantly depending on the employee using it and the environment in which it operates.
“The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”
The platform is also designed to let security teams take action based on those assessments. Bloom says organizations can block risky installations before they reach employee devices, enforce secure configurations and remediate risks without manual approval workflows.
That combination of visibility and enforcement is central to the company’s positioning as it targets large enterprises navigating AI adoption at scale.
Building From Enterprise Security Experience
Bloom’s leadership team has backgrounds at several established cybersecurity companies. CEO Itay Keren previously held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security and Demisto. Chief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks and previously worked at Dig Security and XM Cyber.
Chief Technology Officer Itay Frishman built AISPM and DSPM solutions at Palo Alto Networks and Dig Security, alongside earlier cybersecurity research and development experience. Bloom currently has 30 employees, many of whom previously worked together at Dig Security.
“While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Itay Frishman, Co-Founder and CTO. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”
Bloom’s investors see the changing endpoint as an emerging category in enterprise security. Kobi Samboursky, Founder and Managing Partner at Glilot Capital, said the company’s early traction reflects the urgency of the problem.
“AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee’s machine, entirely outside the reach of traditional controls,” said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. “Bloom identified this gap before the market did, and the business traction we’ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.
With $20 million in seed funding and deployments at dozens of large enterprises, Bloom is now focused on a security perimeter that is changing alongside the workplace itself. Its bet is that protecting the AI-native endpoint will require organizations to understand not only what is running on employee devices, but also the context in which that software operates and the access it has to corporate resources.


