Bloom Security secures $20 million in seed funding as AI transforms operations on the enterprise endpoint.
**Summary**: Bloom Security has secured $20 million in seed funding, led by Glilot Capital and Ten Eleven Ventures, to enhance security for endpoints in the AI era. The firm contends that existing Endpoint Detection and Response (EDR) solutions were designed for malware, not for the diverse software components—such as AI agents, MCP servers, browser extensions, and code packages—that now operate on employee devices. Their platform offers contextual visibility over all software on endpoints while implementing risk-based policies without imposing blanket restrictions. The solution is already in use by numerous major enterprises in the US and Europe.
Work environments have transformed significantly in three years. Employees now curate their own daily toolkits, utilizing AI agents to perform tasks, browser extensions for content creation, code packages sourced from public repositories, and MCP servers for tool integration. AI tools have become essential for modern work processes. Devices have evolved into intricate ecosystems, yet the security tools available often fail to address these changes.
Bloom Security, emerging from stealth mode, has announced a $20 million seed round, which was first reported by Axios, with investors including Glilot Capital Partners, Ten Eleven Ventures, Okta Ventures, and Runtime Ventures, along with angel investments from founders of Dig Security, Demisto, Snyk, and Talon.
**Nature of the Change**: The Tel Aviv-based company indicates that the concept of the enterprise endpoint has undergone a fundamental transformation. Once regarded as manageable, predictable devices, endpoints now encompass various software components, MCP servers, browser extensions, and code packages. With browsers, integrated development environments (IDEs), and AI agents offering their own app stores, the software landscape on employee devices is evolving faster than security teams can manage. Existing security frameworks were never designed for this complexity.
“In the AI era, the employee device is no longer just a managed endpoint,” explained Itay Keren, Co-Founder and CEO of Bloom Security. “Every endpoint is now executing software that hasn’t been reviewed and connecting to services that haven’t been provisioned.”
The traditional response from the security industry, focused on endpoint detection and response (EDR), is insufficient for new threats. EDR was created to tackle malware and related issues, but today’s risks often involve legitimate tools misconfigured, like an AI agent set up incorrectly or a plugin with excessive data permissions. These common tools can easily create significant security vulnerabilities. Current security teams often lack methods to manage these variables effectively.
Bloom Security proposes a comprehensive endpoint security framework that incorporates detailed contextual visibility, proactive enforcement, granular remediation, and prevention—all within a single platform. The aim is not to restrict access but to manage the complexity of modern endpoints, allowing productivity tools to be utilized securely.
The platform provides security teams with a comprehensive overview of all software running on every endpoint, assessing how each component interacts with data and systems. It evaluates risks associated with supply chains, analyzes configurations, and scrutinizes permissions to ascertain real exposure.
The fundamental principle of the product is that risk is context-dependent. “A single tool might be safe on one device but pose a high risk on another,” noted Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk is influenced by context, including the user’s role, their access to sensitive information, other tools present on that endpoint, their configurations, and the interactions among all elements. Bloom Security is designed to assess this context in real time.”
The visibility offered supports proactive actions; teams can prevent risky installations before they are implemented, enforce secure configurations directly, and address risks promptly without disrupting employee workflows.
“As the adoption of AI accelerated, we realized that traditional endpoint controls were not sufficient for this new scenario,” Keren added. “Security teams require a system to understand, govern, and regulate modern tools while allowing employees to work effectively.”
**Experienced Team**: The founders of Bloom Security have extensive credentials in cybersecurity. CEO Itay Keren has held leadership roles in engineering and sales at Palo Alto Networks, Dig Security (acquired by Palo Alto Networks), and Demisto (also acquired by Palo Alto Networks), following his service as a Naval Officer.
Chief Product Officer Ofir Balassiano previously led research on Cortex Cloud Posture Security at Palo Alto Networks, concentrating on AI, identity, and data security. He has also held a senior research role at Dig Security and has experience as a Senior Security Researcher at XM Cyber, starting in the IDF’s Mamram Unit.
Chief Technology Officer Itay Frishman developed core AISPM and DSPM solutions at Palo Alto Networks and Dig Security after leading cybersecurity R&D at the IDF’s Unit 81.
“While this is our first startup as founders, our team has a history of developing and integrating leading products,” Frishman stated. “We understand how enterprise security operates, and we've designed Bloom Security to address the realities of current endpoint usage.”
Currently, Bloom Security has a staff of 30, many of whom collaborated at Dig Security.
**Early Success and
Other articles
Bloom Security secures $20 million in seed funding as AI transforms operations on the enterprise endpoint.
Bloom Security has come out of stealth mode with a $20 million seed funding round led by Glilot Capital and Ten Eleven Ventures. The Tel Aviv-based startup claims that AI agents, MCP servers, and browser extensions have transformed every employee device into an unmonitored environment that Endpoint Detection and Response (EDR) systems were not designed to detect.
