AI & TechArtificial IntelligenceCybersecurityMENA Tech SceneNewswireTechnology

Bloom Security raises $20M seed as AI transforms enterprise endpoints

▼ Summary

– Bloom Security raised $20 million in seed funding led by Glilot Capital and Ten Eleven Ventures to address security gaps in the AI-era endpoint.
– The company argues that traditional EDR was designed for malware, not for modern risks like AI agents, MCP servers, browser extensions, and code packages on employee devices.
– Its platform provides contextual visibility across all endpoint software and enforces risk-based policies based on user role, data access, and tool interactions, without blanket lockdowns.
– The platform is already deployed at dozens of large US and European enterprises, offering features like blocking risky installs, enforcing secure configurations, and remediating risks without disrupting work.
– The founders have prior experience building cybersecurity products at companies like Palo Alto Networks, Dig Security, and Demisto, with a team of 30 employees.

Bloom Security has emerged from stealth with a $20 million seed round aimed at redefining how enterprises secure the AI-era endpoint. The funding was led by Glilot Capital Partners and Ten Eleven Ventures, with participation from Okta Ventures, Runtime Ventures, and angel investors including founders of Dig Security, Demisto, Snyk, and Talon. The Tel Aviv-based startup argues that legacy endpoint detection and response (EDR) was built to stop malware, not to manage the complex ecosystem of AI agents, MCP servers, browser extensions, and code packages now running on every employee device. Its platform offers contextual visibility across all endpoint software and enforces risk-based policies without resorting to blanket lockdowns. Bloom Security is already deployed at dozens of large enterprises across the United States and Europe.

The modern workplace has transformed. Employees now assemble personalized toolkits daily: AI agents acting on their behalf, browser extensions altering how they read and write, code packages pulled from public registries, and MCP servers linking disparate tools. AI is no longer optional,it is the engine of productivity. Yet the security infrastructure guarding these devices was designed for a different era. The device on every desk has quietly evolved into a living ecosystem, and almost none of the existing security stack was built to see it.

“In the AI era, the employee device is no longer just a managed endpoint,” said Itay Keren, Co-Founder and CEO of Bloom Security. “Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”

The industry’s incumbent answer, EDR, was engineered for a simpler threat model: hunting malware, binaries, and malicious processes. But on the modern endpoint, malware is only part of the problem. The risks that keep security leaders awake are often legitimate tools in the wrong state. A misconfigured AI agent. A plugin with excessive data permissions. A screen recorder on an executive’s laptop. A code library pulling from an untrusted source. Each is an everyday tool capable of creating a dangerous attack path. Risk starts with what is already running, and most security teams lack a way to control it.

Bloom Security’s platform offers a full-scope endpoint security architecture that integrates deep contextual visibility, proactive enforcement, granular remediation, and prevention in one system. The goal is not to lock devices down but to bring order to inherent complexity, allowing productivity tools to function fully without unnecessary risk.

In practice, the platform provides security teams with a holistic view of every piece of software across every endpoint,from tools to extensions to code,along with how each interacts with data and systems. It analyzes supply chain risk and examines configurations and permissions to determine actual exposure.

The product’s core insight is that risk is situational. “The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”

Visibility feeds action. Teams can block risky installs before they reach endpoints, enforce secure configurations directly, and remediate risks without manual approval workflows or disruption to how employees work.

“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren added. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”

The founding team brings deep experience. CEO Itay Keren held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security (acquired by Palo Alto Networks), and Demisto (also acquired by Palo Alto Networks). He served as a Naval Officer before entering cybersecurity. Chief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks, focusing on AI, identity, and data security, and previously led research at Dig Security and XM Cyber. Chief Technology Officer Itay Frishman built core AISPM and DSPM solutions at Palo Alto Networks and Dig Security, following cybersecurity R&D leadership in the IDF’s Unit 81.

“While this is technically our first company as founders, our team has built and integrated category-defining products before,” Frishman said. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”

The company currently employs 30 people, many of whom worked together at Dig Security.

Despite only now leaving stealth, Bloom Security is already deployed at dozens of large enterprises across the United States and Europe. Those customers are gaining total visibility into their endpoints and swapping rigid, blanket policies for precise, contextual remediation. The company’s focus is large enterprises navigating AI adoption at scale.

That early traction drew notice from lead investor Glilot Capital. “AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee’s machine, entirely outside the reach of traditional controls,” said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. “Bloom identified this gap before the market did, and the business traction we’ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.”

The broader story here is about a lag. Workplaces adopted AI tools at consumer speed while security controls moved at enterprise speed. That gap between how people work and how their devices are protected is exactly where Bloom Security has planted its flag. The next few years will show whether the AI-native endpoint becomes a recognized security category. Today’s launch makes clear that serious money believes it will.

(Source: The Next Web)

Topics

ai endpoint security 95% seed funding 92% edr limitations 88% contextual visibility 85% risk-based policies 82% ai agent risks 80% enterprise adoption 78% founder experience 75% mcp servers 73% browser extensions 70%