[ Funding
](https://www.unite.ai/series/funding/)
[Add Unite.AI to your preferred sources on Google](https://www.google.com/preferences/source?q=unite.ai)
Bloom Security has emerged from stealth with $20 million in seed funding to address a growing blind spot in enterprise cybersecurity: the expanding collection of AI agents, browser extensions, plugins, code packages, and local automation operating on employee devices.
The round was led by Glilot Capital Partners, with participation from Ten Eleven Ventures, Okta Ventures, and Runtime Ventures. Angel investors include founders of cybersecurity companies Dig Security, Demisto, Snyk, and Talon. Bloom is launching with a 30-person team and says its platform is already deployed at dozens of large enterprises in the United States and Europe.
The Enterprise Endpoint Is Becoming Harder to Define #
Traditional endpoint security was built for managed devices running approved software, with endpoint detection and response tools focused primarily on malware and suspicious processes.
Generative AI has disrupted that model. Employees can now add coding assistants, AI agents, browser extensions, open-source packages, and local automation outside traditional procurement channels. Browsers and development environments have become software marketplaces, while agents can install dependencies independently.
As a result, endpoints are evolving into constantly changing software ecosystems. Security teams must now assess not only whether a tool is malicious, but whether a legitimate tool is appropriate for a particular user, device, and data environment.
A browser extension may be low risk on one laptop but dangerous on an executive’s device. Similarly, an approved AI agent may become overprivileged if it can access production credentials, customer data, or financial records.
Building an Inventory of What Is Actually Running #
Bloom’s platform maintains a continuously updated inventory of software across an organization’s endpoint fleet, including applications, browser extensions, development environment plugins, AI tools, Model Context Protocol servers, and local code libraries.
Model Context Protocol, or MCP, allows AI agents to connect with external tools, data sources, and business systems. While these connections expand what agents can do, they may also expose sensitive information or enable actions on a user’s behalf.
Bloom analyzes each component’s developer, origin, permissions, configuration, and access to corporate resources. It also tracks changes over time, helping security teams identify software introduced through marketplaces, package managers, background updates, or automated agent activity.
This is particularly relevant in software development, where a coding agent may select frameworks and install multiple dependencies before a developer reviews the resulting application.
Evaluating Risk in Context #
Beyond identifying software, Bloom evaluates the context in which each component operates. The platform combines marketplace intelligence, static analysis, and behavioral sandboxing to assess configurations, permissions, data access, vulnerable packages, policy bypasses, and interactions between tools.
Risk is measured according to factors such as the employee’s role, the sensitivity of accessible data, and the systems connected to the device. An extension that is acceptable for one user may pose greater exposure on an executive’s laptop, while an AI agent operating in a test environment presents less risk than one with access to production credentials.
This approach allows Bloom to move beyond simple approved-or-blocked policies. It is particularly relevant for browser extensions, which may have broad permissions to read website data, interact with tabs, and communicate with external services, creating potential paths into corporate systems that malware-focused tools may overlook.
Moving from Visibility to Enforcement #
Bloom is also designed to move beyond risk detection into direct endpoint enforcement. The platform can block vulnerable components before installation, remove risky tools, revoke permissions, correct insecure configurations, and show administrators which employees will be affected by a policy change.
Policies can be applied to specific tools, teams, or users across channels including npm, the Chrome Web Store, and Open VSX. Bloom’s AI guardrails can also restrict what agents are permitted to access, execute, or transmit while correcting overly permissive Model Context Protocol configurations.
The goal is to replace blanket restrictions with more targeted controls that reduce risk without unnecessarily disrupting legitimate workflows. Bloom’s effectiveness will ultimately depend on whether it can maintain that precision across complex enterprise environments.
A Founding Team with Enterprise Security Experience #
Bloom was founded by CEO Itay Keren, Chief Product Officer Ofir Balassiano, and Chief Technology Officer Itay Frishman.
Keren previously held engineering and sales engineering leadership positions at Palo Alto Networks (PANW ), Dig Security, and Demisto. Both Dig Security and Demisto were acquired by Palo Alto Networks.
Balassiano led research for Cortex Cloud Posture Security at Palo Alto Networks, focusing on AI, identity, and data security. He previously worked at Dig Security and XM Cyber.
Frishman helped build AI security posture management and data security posture management products at Palo Alto Networks and Dig Security. Many of Bloom’s current employees also previously worked together at Dig Security.
That shared background gives the company experience building security products for large organizations, although Bloom is entering a competitive market where endpoint security, browser security, AI governance, software supply-chain security, and data protection increasingly overlap.
Funding a New Layer of Endpoint Security #
The broader significance of Bloom Security’s launch is that endpoint security may need to expand beyond malware detection as AI agents, browser extensions, and autonomous tools become more common in the workplace.
Security teams will increasingly need to understand not only what software is running, but also what data it can access, what actions it can perform, and how its risk changes based on the user and device. This could push endpoint security closer to identity management, software supply-chain monitoring, browser security, and AI governance.
It remains unclear whether AI-native endpoint protection will develop into a separate cybersecurity category or become part of existing security platforms. Either way, vendors will face pressure to provide more contextual controls without relying on blanket restrictions that reduce productivity or encourage employees to bypass approved systems.