The rapid adoption of artificial intelligence is creating a new problem for enterprise security teams: keeping track of software that was never part of the traditional corporate endpoint. AI agents, browser extensions, MCP servers and code packages are increasingly being used alongside established business applications, creating a software environment that can be difficult to inventory and control.
Bloom Security is launching with a $20 million seed round and a platform designed specifically for that changing environment. The Tel Aviv-based startup announced its emergence from stealth with funding led by Glilot Capital Partners, alongside participation from Ten Eleven Ventures (1011vc), Okta Ventures, and Runtime Ventures. Axios first reported about the company’s launch and funding.
The financing also includes angel investors who founded companies such as Dig Security, Demisto, Snyk and Talon. Bloom said it is already deployed at dozens of large enterprises across the United States and Europe, where it is focused on helping security teams understand and control the expanding software layer on employee endpoints.
The Endpoint Has Become a Moving Target
The security industry has traditionally built endpoint protection around a defined set of threats. Endpoint detection and response tools were primarily designed to identify malware, suspicious processes and malicious executables.
But the rise of AI is expanding the range of software running on corporate devices. The problem is not always an application that is explicitly malicious. A legitimate tool can create risk because of how it is configured, the permissions it has been granted or the systems and data it can access.
“In the AI era, the employee device is no longer just a managed endpoint,” said Itay Keren, Co-Founder and CEO of Bloom Security. “Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”
Bloom identifies several examples of this new risk environment, including misconfigured AI agents, plugins with excessive data permissions, screen recorders and code libraries pulling from untrusted sources. These tools can create potential attack paths while remaining outside the traditional focus of malware-centric endpoint security.
“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren added. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”
A Different Way to Assess Endpoint Risk
Bloom Security’s platform is designed to provide an inventory of software running across enterprise endpoints, including tools, extensions and code. It also examines how those components interact with data and systems and analyzes supply-chain risks, configurations and permissions.
The company argues that the security implications of a particular application cannot always be assessed without understanding the surrounding environment. The same tool can carry different levels of risk depending on the employee’s role, their access to sensitive information and the other software running on the device.
“The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”
The company says its platform also provides active controls, allowing organizations to block risky installations before they reach employee endpoints, enforce secure configurations and remediate risks without manual approval workflows.
Founders With a Track Record in Security
Bloom’s founding team has worked across several established cybersecurity companies. Keren previously held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security and Demisto. Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks and previously worked at Dig Security and XM Cyber.
Chief Technology Officer Itay Frishman previously built AISPM and DSPM solutions at Palo Alto Networks and Dig Security. Bloom currently employs 30 people, many of whom previously worked together at Dig Security.
“While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Itay Frishman, Co-Founder and CTO. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”
The company’s investors are positioning Bloom around what they see as a widening gap between AI adoption and traditional security controls. Kobi Samboursky, Founder and Managing Partner at Glilot Capital, said the shift is already visible across enterprise environments.
“AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee’s machine, entirely outside the reach of traditional controls,” said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. “Bloom identified this gap before the market did, and the business traction we’ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.
With $20 million in seed funding, 30 employees and deployments across dozens of large enterprises, Bloom is entering the market as companies continue to expand their use of AI. Its central premise is that securing the modern endpoint will require more than detecting malware—it will require understanding the full software environment and giving security teams the ability to govern it.

