
Ask a security team what is running on their endpoints right now and the honest answer, in most organizations, is that nobody fully knows. Employees install browser extensions between meetings. Developers pull code packages from public sources. AI agents connect to MCP servers that were never provisioned by IT. Bloom Security launched from stealth today with a $20 million seed round, first reported by Axios, to give security teams an answer to that question, and the controls to act on it.
The round was led by Glilot Capital Partners, with participation from Ten Eleven Ventures (1011vc), Okta Ventures, and Runtime Ventures. Angel investors include founders of Dig Security, Demisto, Snyk, and Talon.
The problem Bloom Security targets will be familiar to anyone running a security program through the current wave of AI adoption. Endpoints have stopped being managed, predictable devices. They are now ecosystems of agentic software, MCP servers, browser extensions, and code packages that employees assemble daily. AI tools are no longer optional. They are how modern work gets done. Browsers, IDEs, and AI agents ship with their own app stores and marketplaces, so the software layer grows faster than any team can track. Existing security infrastructure was never built to see it.
"In the AI era, the employee device is no longer just a managed endpoint," said Itay Keren, Co-Founder and CEO of Bloom Security. "Every endpoint is now running software no one reviewed, connecting to services no one provisioned."
For practitioners, the frustration is that the risks slipping through are not malware, which existing EDR tooling was built to catch. They are everyday tools in dangerous states: a misconfigured AI agent, a plugin with excessive data permissions, a screen recorder on an executive's laptop, a code library pulling from an untrusted source. Each creates an attack path. Risk starts with what is already running, and most teams lack a way to control it.
Bloom Security's platform starts with inventory. It provides a holistic view of every piece of software running across every endpoint, covering tools, extensions, and code, along with the context of how each interacts with data and systems. It analyzes supply chain risk and examines configurations and permissions to surface actual exposure, not theoretical exposure.
That last distinction matters operationally. Blanket policies fail because they treat identical tools identically regardless of where they run. "The same tool can be completely acceptable on one endpoint and high-risk on another," said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. "Risk depends on context: the user's role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time."
From there, the platform moves teams from observation to action. Risky installs can be blocked before they reach employee endpoints, cutting off supply chain risks at the point of entry. Secure configurations can be enforced directly. Remediation happens without manual approval workflows and without disrupting how employees work.
That last point addresses a real organizational tension. Security controls that slow employees down get bypassed or fought. "As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality," Keren said. "Security teams need a way to understand, govern, and control modern tools without disrupting how employees work."
For teams evaluating new vendors, deployment history matters more than promises. Bloom Security is already running at dozens of large enterprises across the United States and Europe. Customers are gaining total visibility into their endpoints and swapping rigid, blanket policies for precise, contextual remediation. The company is focused on large enterprises navigating AI adoption at scale, the environments where the tool sprawl problem is most acute.
The founding team's backgrounds map closely to the problem. CEO Itay Keren held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security (acquired by Palo Alto Networks), and Demisto (acquired by Palo Alto Networks). Before cybersecurity, he served as a Naval Officer, leading teams in high-pressure environments.
Chief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks, working on AI, identity, and data security. He previously led the research group at Dig Security and served as a Senior Security Researcher at XM Cyber, having begun his career in the IDF's Mamram Unit.
Chief Technology Officer Itay Frishman built core AISPM and DSPM solutions at Palo Alto Networks and Dig Security, with prior cybersecurity R&D leadership in the IDF's Unit 81.
"While this is technically our first company as founders, our team has built and integrated category-defining products before," Frishman said. "We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today."
The company employs 30 people, many of whom previously worked together at Dig Security.
Kobi Samboursky, Founder and Managing Partner at Glilot Capital, framed the opportunity from the investor's chair. "AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee's machine, entirely outside the reach of traditional controls," he said. "Bloom identified this gap before the market did, and the business traction we've seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one."
For security leaders, the practical takeaway is that a new option now exists for a problem most have been managing with spreadsheets, blanket blocks, or resignation. Whether it fits a given environment is a question for evaluation. That the problem is real is not much in dispute on any security team living with AI-era endpoints today.