
Bloom Security, founded by three ex-Palo Alto Networks engineers, has raised $20 million to address a gap in endpoint security created by the rise of AI agents and third-party tools on employee devices.
Traditional cybersecurity tools were built to detect malware, not to manage the legitimate but unvetted software—including AI agents, browser extensions, and code packages—that now runs on corporate endpoints.
Bloom's platform uses AI to analyze what is actually running on each device, assess context-specific risk based on user role and data access, and enforce granular security controls without slowing productivity.
What happened
Israeli startup Bloom Security raised $20 million in a Seed round led by Glilot Capital Partners and Ten Eleven Ventures, with backing from Okta Ventures, Runtime Ventures, and angels including founders of Snyk, Demisto, Dig Security, and Talon. The company was founded in 2025 by three ex-Palo Alto Networks engineers—CEO Itay Keren, Chief Product Officer Ofir Balassiano, and Chief Technology Officer Itay Frishman—and now employs 30 people in Israel.
Why it matters
Employee devices today run AI agents, browser extensions, and code packages that traditional cybersecurity tools were never designed to manage. These tools often gain access to sensitive data without formal security review. Bloom Security's platform uses autonomous AI to map what is actually running on each endpoint, analyze context-specific risk based on user role and data access, and block risky installations—addressing a gap that legacy tools cannot fill as enterprises adopt AI.
What to watch
Bloom says its platform is already deployed at dozens of large enterprises across the United States and Europe, where customers are using it to replace broad security restrictions with more granular, context-based controls.
Bloom Security, an Israeli cybersecurity startup, closed a $20 million Seed funding round led by Glilot Capital Partners and Ten Eleven Ventures. Okta Ventures and Runtime Ventures also participated, alongside angel investors including the founders of major cybersecurity companies: Snyk, Demisto, Dig Security, and Talon.
The company was founded in 2025 by three veterans of Palo Alto Networks. CEO Itay Keren previously served as a submarine officer in the Israeli Navy before moving into cybersecurity. Chief Product Officer Ofir Balassiano began his career in the IDF's Mamram Unit. Chief Technology Officer Itay Frishman held R&D leadership roles in Unit 81. All three worked together in senior engineering, product, and research roles at Palo Alto Networks following its acquisitions of Dig Security and Demisto. The company currently employs 30 people in Israel, many of whom previously worked together at Dig Security.
Bloom Security's core insight is that traditional endpoint security tools no longer match the reality of modern enterprise devices. Employee laptops and developer workstations now run far more than approved operating systems and enterprise applications. They execute AI agents, MCP (Model Context Protocol) servers, browser and IDE plugins, automation tools, and countless code libraries. Browsers, development environments, and AI agents themselves have become platforms with app stores and package managers, causing the number of programs running on each machine to grow faster than security teams can track. Some tools are installed directly by employees; others are added automatically by AI-powered applications. Many receive extensive permissions and access to sensitive data and enterprise services without undergoing formal security review.
Traditional endpoint detection and response (EDR) products were designed to identify malware, malicious executables, and suspicious processes—but they are poorly suited to managing risks created by legitimate AI agents, browser extensions, code packages, and automation tools that have become part of everyday enterprise workflows. Bloom Security has built an endpoint security platform designed specifically for the AI era. The platform uses autonomous AI agents to analyze and map the applications, AI agents, plugins, extensions, and code running on every endpoint, identifying what data and systems they access and how they interact with one another.
Crucially, Bloom's risk analysis is context-aware. Software that may be appropriate for one employee can present a security risk on another's device, depending on the user's role, access privileges, the data they can access, and the other applications running in the same environment. The platform analyzes permissions, configurations, and software supply chain risks, enabling organizations to block risky installations before they reach employee devices, enforce security policies, and remediate threats without disrupting employee productivity.
CEO Itay Keren said: "In the AI era, the employee device is no longer just a managed endpoint. Every endpoint is now running software no one reviewed, connecting to services no one provisioned." He continued: "Employee computers no longer run only software that organizations have selected, tested, and approved. They now run AI agents, plugins, and code packages that connect to services and gain access to information, often without security teams even knowing about them. We founded Bloom to help organizations understand what is actually running on every computer and control those risks without slowing productivity or limiting the adoption of AI tools." Chief Product Officer Ofir Balassiano added: "The same tool can be completely acceptable on one endpoint and high-risk on another. Risk depends on context: the user's role, access to sensitive data, the other tools operating on that endpoint, and how everything interacts. Bloom Security was designed to evaluate that context in real time."
Bloom Security says its platform is already deployed at dozens of large enterprises across the United States and Europe, where customers are using it to replace broad security restrictions with more granular, context-based controls as they expand their use of AI tools. Koby Samboursky, Founder and Managing Partner at Glilot Capital, commented: "The endpoint is evolving faster than existing security stacks can keep up. Agents, plugins, and code packages running directly on employee devices create a new layer of risk that existing tools weren't built to address."
Bloom Security emerges from a real tension in modern enterprise security: the tools organizations rely on to protect endpoints were designed for an era when devices ran only approved applications and known operating systems. Today, employee laptops and developer workstations have become complex software environments where AI agents, browser extensions, IDE plugins, automation tools, and code libraries run alongside enterprise software—and many of these programs are installed either directly by employees or automatically by AI applications, often with broad permissions and no formal security review.
The founding team's pedigree matters here. Keren, Balassiano, and Frishman all come from senior roles at Palo Alto Networks, where they worked on Dig Security and Demisto (both acquired by Palo Alto). That background gives them deep credibility in endpoint security and relationships across the industry. Their pitch—that context matters more than binary rules—reflects a genuine shift in how enterprises need to think about security in the age of AI. A browser extension or automation tool that is harmless for a junior developer can pose a serious risk for someone with access to sensitive data or critical systems. Traditional endpoint detection and response (EDR) products flag malware and suspicious processes, but they cannot evaluate whether a legitimate tool is appropriate for a given user in a given role.
The funding round's composition—led by Glilot Capital and Ten Eleven Ventures, with participation from Okta Ventures and Runtime Ventures, plus angels from Snyk, Demisto, Dig Security, and Talon—signals broad confidence among security leaders that this problem is both real and urgent. The fact that Bloom claims to be already deployed at dozens of large enterprises across the United States and Europe, just weeks after founding, suggests either rapid early sales or a very mature product before the public announcement. Either way, it indicates that the market is actively seeking this capability.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Google, Microsoft, and Meta continue expanding capital spending on AI infrastructure, signaling confidence tha…

ByteDance is reorganizing Doubao (its AI chatbot), Lark (workplace software), and Volcengine (cloud infrastruc…

Pegatron chairman Tzu-hsien Tung stated he remains optimistic about the long-term outlook for artificial intel…

Powertech Technology chairman DK Tsai said the company's FOPLP (Fan-Out Panel-Level Packaging) project with AM…

Nebius Group (NBIS) has more than doubled this year on strong demand for AI data centers with secured power, a…

Reddit reported Q2 earnings that surpassed estimates, driven by expansion in AI-powered advertising tools that…

The AI news that matters, in one minute each morning.
Sign up free