New York, USA, July 30th, 2026, FinanceWire
The endpoint is becoming a very different security problem. As employees adopt AI agents, browser extensions, MCP servers and code packages, corporate devices are evolving from tightly managed machines into increasingly complex software environments that security teams may struggle to fully understand.
Bloom Security is launching with a $20 million seed round to address that gap. The Tel Aviv-based company emerged from stealth with funding led by Glilot Capital Partners and Ten Eleven Ventures (1011vc), with participation from Okta Ventures and Runtime Ventures. Axios first reported about the company’s launch and funding.
The round also includes angel investors who founded companies including Dig Security, Demisto, Snyk and Talon. Bloom said it is already deployed at dozens of large enterprises across the United States and Europe.
A New Endpoint Security Challenge
Traditional endpoint detection and response products were largely designed around identifying malware, malicious processes and suspicious executables. Bloom Security argues that the modern endpoint presents a broader challenge, where the software itself may not be malicious but can still create significant risk through permissions, configurations or connections to sensitive systems.
“In the AI era, the employee device is no longer just a managed endpoint,” said Itay Keren, Co-Founder and CEO of Bloom Security. “Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”
The company points to a growing collection of potential attack paths, including misconfigured AI agents, plugins with excessive data permissions, screen recorders and code libraries that pull from untrusted sources. These tools can become part of an organization’s environment without fitting neatly into the traditional security models built around malware detection.
“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren added. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”
Context as a Security Control
Bloom’s platform is designed to provide visibility into software running across an organization’s endpoints, including tools, extensions and code. It also examines how those components interact with data and systems, while assessing supply-chain risks, configurations and permissions.
The company says its approach is based on contextual risk rather than applying the same security policy to every endpoint. An application that is acceptable for one employee may pose greater risk for another depending on their role, access and the other software operating on their device.
“The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”
Beyond visibility, Bloom says its platform enables organizations to block risky installations, enforce secure configurations and remediate risks without relying on manual approval workflows.
Experienced Founders, Early Enterprise Traction
Bloom’s founding team has previously held leadership and engineering roles at Palo Alto Networks, Dig Security and Demisto. Keren worked in engineering and sales engineering leadership at Palo Alto Networks, Dig Security and Demisto, while Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks.
Chief Technology Officer Itay Frishman previously built AISPM and DSPM solutions at Palo Alto Networks and Dig Security. The company now has 30 employees, many of whom previously worked together at Dig Security.
“While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Itay Frishman, Co-Founder and CTO. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”
For Bloom’s investors, the company’s emergence comes as enterprises grapple with how to govern AI adoption without slowing down employees. Kobi Samboursky, Founder and Managing Partner at Glilot Capital, said the shift has created a gap that traditional endpoint controls have not addressed.
“AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee’s machine, entirely outside the reach of traditional controls,” said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. “Bloom identified this gap before the market did, and the business traction we’ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.