{"slug": "bloom-security-lands-20-million-seed-as-ai-rewrites-what-runs-on-the-enterprise", "title": "Bloom Security lands $20 million seed as AI rewrites what runs on the enterprise endpoint", "summary": "Bloom Security launched from stealth with a $20 million seed round led by Glilot Capital Partners and Ten Eleven Ventures to secure the AI-era enterprise endpoint. The Tel Aviv-based company argues that traditional endpoint detection and response was built for malware, not for the AI agents, MCP servers, browser extensions, and code packages now running on employee devices. Its platform provides contextual visibility across all endpoint software and enforces risk-based policies without blanket lockdowns, and is already deployed at dozens of large US and European enterprises.", "body_md": "#### TL;DR\n\n*Bloom Security has raised $20M in seed funding led by Glilot Capital and Ten Eleven Ventures to secure the AI-era endpoint. The company argues that EDR was built for malware, not for the AI agents, MCP servers, browser extensions, and code packages now running on every employee device. Its platform provides contextual visibility across all endpoint software and enforces risk-based policies without blanket lockdowns. Already deployed at dozens of large US and European enterprises.*\n\nWork does not look like it did three years ago. Employees now assemble their own toolkits daily: AI agents that act on their behalf, [browser extensions](https://thenextweb.com/news/google-chrome-enterprise-ai-coworker-agentic-browser) that reshape how they read and write, code packages pulled from public registries, [MCP servers](https://thenextweb.com/news/rise-of-model-context-protocol-in-the-agentic-era) connecting one tool to another. AI tools are no longer optional. They are how modern work gets done. The device on every desk has quietly become an ecosystem, and almost none of the security stack guarding it was built with that in mind.\n\nInto this gap steps [Bloom Security](https://bloom.security/), which launched from stealth today with a $20 million seed round, first reported by Axios, led by Glilot Capital Partners and Ten Eleven Ventures (1011vc), with participation from Okta Ventures and Runtime Ventures, plus angel backing from founders of Dig Security, Demisto, Snyk, and Talon.\n\n## The Shape of the Shift\n\nThe Tel Aviv-based company describes the enterprise endpoint as fundamentally shifted. What were once managed, predictable devices are now assemblages of agentic software, MCP servers, browser extensions, and code packages. Browsers, IDEs, and AI agents ship with their own app stores and marketplaces, which means the software layer on employee devices grows faster than any security team can track. Existing security infrastructure was never built to see it.\n\n“*In the AI era, the employee device is no longer just a managed endpoint,*” said [Itay Keren](https://www.linkedin.com/in/itay-keren-%F0%9F%8C%B8-544760148/), Co-Founder and CEO of Bloom Security. “*Every endpoint is now running software no one reviewed, connecting to services no one provisioned.*”\n\nThe industry’s incumbent answer, endpoint detection and response, was engineered for a different threat model. EDR hunts malware: binaries, executables, malicious processes. But on the modern endpoint, malware is only part of the problem. The risks that keep security leaders awake are now often legitimate tools in the wrong state. A misconfigured AI agent. A plugin with excessive data permissions. A screen recorder on an executive’s laptop. A code library pulling from an untrusted source. Each is an everyday tool capable of creating a dangerous [attack path](https://thenextweb.com/news/google-ai-zero-day-exploit-cybersecurity-arms-race). Risk starts with what is already running, and most security teams lack a way to control it.\n\n## What Bloom Security Built\n\nThe company’s answer is a full-scope endpoint security architecture that integrates deep contextual visibility, proactive enforcement, granular remediation, and proactive prevention in one platform. The intent is not to lock devices down. It is to bring order to the inherent complexity of the modern endpoint so that productivity tools can be used to their full potential, free from unnecessary risk.\n\nIn practice, the platform gives security teams a holistic view of every piece of software running across every endpoint, from tools to extensions to code, along with how each interacts with data and systems. It analyzes [supply chain risk](https://thenextweb.com/news/lastpass-klue-supply-chain-breach-customer-data-stolen). It examines configurations and permissions to determine actual exposure.\n\nThe product’s defining idea is that risk is situational. “*The same tool can be completely acceptable on one endpoint and high-risk on another,*” said [Ofir Balassiano](https://www.linkedin.com/in/ofir-balassiano/), Co-Founder and Chief Product Officer at Bloom Security. “*Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.*”\n\nVisibility feeds action. Teams can block risky installs before they reach employee endpoints, enforce secure configurations directly, and remediate risks without manual approval workflows or disruption to how employees work.\n\n“*As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,*” Keren added. “*Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.*”\n\n## A Team That Has Done This Before\n\nBloom Security’s founders arrive with acquisition credentials. CEO Itay Keren held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security (acquired by Palo Alto Networks), and Demisto (also acquired by Palo Alto Networks). He served as a Naval Officer before entering cybersecurity, leading teams in high-pressure environments.\n\nChief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks, working on AI, identity, and data security. Earlier, he led the research group at Dig Security and served as a Senior Security Researcher at XM Cyber. His career began in the IDF’s Mamram Unit.\n\nChief Technology Officer [Itay Frishman](https://www.linkedin.com/in/itay-frishman/) built core AISPM and DSPM solutions at Palo Alto Networks and Dig Security, after cybersecurity R&D leadership in the IDF’s Unit 81.\n\n“*While this is technically our first company as founders, our team has built and integrated category-defining products before,*” Frishman said. “*We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.*”\n\nThe company employs 30 people today, many of whom worked together at Dig Security.\n\n## Early Traction, Bigger Ambitions\n\nDespite only now leaving stealth, Bloom Security is already deployed at dozens of large enterprises across the United States and Europe. Those customers are gaining total visibility into their endpoints and swapping rigid, blanket policies for precise, contextual remediation. The company’s focus is large enterprises navigating [AI adoption](https://thenextweb.com/news/why-2026-will-be-the-year-of-governed-cybersecurity-ai) at scale.\n\nThat early footprint drew notice from its lead investor. “*AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee’s machine, entirely outside the reach of traditional controls,*” said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. “*Bloom identified this gap before the market did, and the business traction we’ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.*”\n\nThe broader story here is about a lag. Workplaces adopted AI tools at consumer speed while security controls moved at enterprise speed. That gap between how people work and how their devices are protected is exactly where Bloom Security has planted its flag. The next few years will show whether the AI-native endpoint becomes a recognized security category. Today’s launch makes clear that serious money believes it will.", "url": "https://wpnews.pro/news/bloom-security-lands-20-million-seed-as-ai-rewrites-what-runs-on-the-enterprise", "canonical_source": "https://thenextweb.com/news/bloom-security-20m-seed-ai-enterprise-endpoint", "published_at": "2026-07-30 13:10:53+00:00", "updated_at": "2026-07-30 14:32:09.711757+00:00", "lang": "en", "topics": ["ai-agents", "ai-startups", "ai-products"], "entities": ["Bloom Security", "Glilot Capital Partners", "Ten Eleven Ventures", "Okta Ventures", "Runtime Ventures", "Itay Keren", "Dig Security", "Demisto"], "alternates": {"html": "https://wpnews.pro/news/bloom-security-lands-20-million-seed-as-ai-rewrites-what-runs-on-the-enterprise", "markdown": "https://wpnews.pro/news/bloom-security-lands-20-million-seed-as-ai-rewrites-what-runs-on-the-enterprise.md", "text": "https://wpnews.pro/news/bloom-security-lands-20-million-seed-as-ai-rewrites-what-runs-on-the-enterprise.txt", "jsonld": "https://wpnews.pro/news/bloom-security-lands-20-million-seed-as-ai-rewrites-what-runs-on-the-enterprise.jsonld"}}