The corporate endpoint is changing faster than the security systems built to protect it. AI agents, MCP servers, browser extensions and code packages are becoming part of everyday work, creating an expanding software layer that can be difficult for security teams to see, assess and control.
Bloom Security is entering the market with a $20 million seed round led by Glilot Capital Partners, with participation from Ten Eleven Ventures (1011vc), Okta Ventures, and Runtime Ventures. Axios first reported about the company’s launch and funding. The Tel Aviv-based startup has emerged from stealth with a platform designed to bring visibility, contextual risk assessment and active enforcement to the AI-native endpoint.
The Endpoint Has Become a Software Ecosystem
Traditional endpoint detection and response tools were built largely around malware, executables and malicious processes. But today’s endpoint can contain legitimate tools that create risk through excessive permissions, insecure configurations or unexpected access to company data and systems. Bloom points to misconfigured AI agents, plugins with broad data permissions, screen recorders and code libraries pulling from untrusted sources as examples of the new attack paths organizations must consider.
“In the AI era, the employee device is no longer just a managed endpoint,” said Itay Keren, Co-Founder and CEO of Bloom Security. “Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”
Bloom’s platform is designed to provide a holistic view of software running across enterprise endpoints, including tools, extensions and code, while analyzing supply-chain risk, configurations and permissions. It also examines how those components interact with data and systems, with the company arguing that security risk must be evaluated in context rather than through blanket policies.
Context Becomes the New Control Layer
For Bloom, the same application can present very different levels of risk depending on where and how it is being used. The platform evaluates factors including a user’s role, access to sensitive data, configurations and the other tools operating on an endpoint.
“The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”
The company says its platform goes beyond visibility by giving security teams the ability to block risky installations before they reach employee devices, enforce secure configurations and remediate risks without manual approval workflows. Bloom is already deployed at dozens of large enterprises across the United States and Europe and is focused on organizations navigating AI adoption at scale.
An Experienced Team Takes Aim at the Gap
Bloom was founded by a team with experience building enterprise security products at Palo Alto Networks, Dig Security and Demisto. CEO Itay Keren previously held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security and Demisto, while Chief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks and previously worked at Dig Security and XM Cyber.
Chief Technology Officer Itay Frishman previously built AISPM and DSPM solutions at Palo Alto Networks and Dig Security. Bloom currently employs 30 people, many of whom previously worked together at Dig Security.
“While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Itay Frishman, Co-Founder and CTO. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”
With $20 million in seed funding and early deployments across dozens of large enterprises, Bloom is betting that the next generation of endpoint security will need to account for an environment where AI and software are increasingly assembled directly on employee devices. The company’s premise is straightforward: as the endpoint becomes more complex, security teams need visibility into everything running across it, and the ability to act on that context.

