Bloom Security Launches With $20M Seed to Close the Security Gap Around AI-Native Endpoints

Related

Share

Enterprise employees are adopting AI tools at a pace that is reshaping the corporate endpoint. Laptops and workstations are no longer defined solely by a controlled set of applications deployed by IT departments. They increasingly host AI agents, browser extensions, MCP servers and code packages that can interact with company systems and data.

Bloom Security is building its business around the security implications of that shift. The Tel Aviv-based startup has emerged from stealth with a $20 million seed round led by Glilot Capital Partners, with participation from Ten Eleven Ventures (1011vc), Okta Ventures, and Runtime Ventures. Axios first reported about the company’s launch and funding.

The financing also includes angel investors who founded Dig Security, Demisto, Snyk and Talon. Bloom said its platform is already deployed at dozens of large enterprises across the United States and Europe, where it is focused on giving security teams greater visibility and control over the software running across employee devices.

AI Is Expanding the Definition of an Endpoint

Traditional endpoint security was built around a relatively narrow set of threats. Endpoint detection and response products were designed primarily to identify malware, malicious processes and suspicious executables.

The arrival of AI is introducing a different set of concerns. Employees can now use software that is not necessarily malicious but may still create risk because of its permissions, configuration or access to sensitive information. Bloom points to misconfigured AI agents, plugins with excessive data permissions, screen recorders and code libraries pulling from untrusted sources as examples of potential attack paths.

“In the AI era, the employee device is no longer just a managed endpoint,” said Itay Keren, Co-Founder and CEO of Bloom Security. “Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”

The company argues that security teams need to account for the entire software environment rather than focusing exclusively on known malicious activity. As AI tools become integrated into everyday workflows, that environment can change quickly and include software sourced through the marketplaces and app stores associated with browsers, IDEs and AI agents.

“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren added. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”

A Contextual Approach to Endpoint Risk

Bloom Security’s platform is designed to inventory software operating across endpoints, including tools, extensions and code. It also analyzes how those components interact with data and systems and examines supply-chain risks, configurations and permissions.

A central part of the company’s approach is assessing risk in context. Rather than treating an application as inherently safe or dangerous, Bloom evaluates factors such as the user’s role, access to sensitive data and the other tools running on the same endpoint.

“The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”

The platform is designed to give organizations active controls as well. According to Bloom, security teams can block risky installations before they reach employee endpoints, enforce secure configurations and remediate risks without manual approval workflows or disrupting how employees work.

Founders With Enterprise Security Experience

Bloom’s leadership team has experience developing enterprise security products at Palo Alto Networks, Dig Security and Demisto. Keren previously held engineering and sales engineering leadership positions at Palo Alto Networks, Dig Security and Demisto. Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks and previously worked at Dig Security and XM Cyber.

Chief Technology Officer Itay Frishman previously built AISPM and DSPM solutions at Palo Alto Networks and Dig Security. Bloom currently employs 30 people, many of whom previously worked together at Dig Security.

“While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Itay Frishman, Co-Founder and CTO. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”

The company is now targeting large enterprises navigating AI adoption at scale. Its $20 million seed round provides Bloom with capital as it attempts to establish a security category around a changing endpoint  where the challenge is no longer simply identifying what is malicious, but understanding what is running, what it can access and whether it creates risk in a particular context.

IMG 0514 2
+ posts

John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.