Led by Glilot Capital Partners with participation from Ten Eleven Ventures (1011vc), Bloom Security introduces endpoint security purpose-built for the AI-native endpoint.
TEL AVIV, Israel, July 30, 2026 — Bloom Security today announced its launch from stealth with a $20 million seed round led by Glilot Capital Partners, with participation from Ten Eleven Ventures (1011vc), Okta Ventures and Runtime Ventures. The round also includes prominent angel investors, including founders of Dig Security, Demisto, Snyk, and Talon.
Bloom Security was founded by a team with a proven record of building enterprise security companies from zero to acquisition. The company is already delivering clarity, governance, and active enforcement to the AI-native endpoint - one of the most complex and underprotected layers in modern enterprise security.
A New Reality: The Endpoint Has Fundamentally Shifted
Endpoints have fundamentally shifted. What were once managed, predictable devices are now ecosystems of agentic software, MCP servers, browser extensions, and code packages that employees assemble daily. AI tools are no longer optional. They are how modern work gets done. Browsers, IDEs, and AI agents now ship with their own app stores and marketplaces, creating a software layer that grows faster than any security team can track, and that existing security infrastructure was never built to see.
"In the AI era, the employee device is no longer just a managed endpoint," said Itay Keren, Co-Founder and CEO of Bloom Security. "Every endpoint is now running software no one reviewed, connecting to services no one provisioned."
Traditional endpoint detection and response (EDR) solutions were designed for malware: binaries, executables, and malicious processes. But on the modern endpoint, malware is only part of the problem. A misconfigured AI agent, a plugin with excessive data permissions, a screen recorder running on an executive's laptop, a code library pulling from an untrusted source: these are everyday tools creating dangerous attack paths. Risk starts with what's already running, and most security teams lack a way to control it.
“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren added. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”
Context, Enforcement, and Prevention for the AI-Native Endpoint
Bloom Security shields the modern enterprise through a full-scope endpoint security architecture. By integrating deep, contextual visibility, proactive enforcement, granular remediation, and proactive prevention into a single platform, Bloom brings order to the inherent complexity of the modern endpoint. The platform creates a secure environment where productivity tools can be utilized to their full potential, free from unnecessary risk.
The platform provides a holistic view of every software running across every endpoint - tools, extensions, and code - and the context of how they interact with data and systems. It analyzes supply-chain risk and examines configurations and permissions to understand actual exposure.
“The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”
Beyond visibility, the platform gives teams active control at every stage. Users can block risky installs before they reach employee endpoints to prevent supply-chain risks, enforce secure configurations directly, and remediate risks without manual approval workflows or disruption to how employees work.
Bloom Security is already deployed at dozens of large enterprises across the United States and Europe. Customers are already gaining total visibility into their endpoints, allowing them to swap rigid, blanket policies for precise, contextual remediation. The company is focused on large enterprises navigating AI adoption at scale, giving them the visibility and granular control to govern the modern endpoint.
Founded by Proven Operators
Bloom Security’s founding team brings extensive experience building and scaling security platforms inside some of the industry’s most recognized companies.
CEO Itay Keren previously held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security (acquired by Palo Alto Networks), and Demisto (acquired by Palo Alto Networks). Before entering cybersecurity, Keren served as a Naval Officer, leading teams in high-pressure environments.
Chief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks, focusing on AI, identity, and data security. He previously led the research group at Dig Security and served as a Senior Security Researcher at XM Cyber, beginning his career in the IDF’s Mamram Unit.
Chief Technology Officer Itay Frishman is an engineering leader who built core AISPM and DSPM solutions at Palo Alto Networks and Dig Security, with prior cybersecurity R&D leadership experience in IDF’s Unit 81.
“While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Itay Frishman, Co-Founder and CTO. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”
Bloom Security currently employs 30 team members, many of whom previously worked together at Dig Security.
“AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee's machine, entirely outside the reach of traditional controls," said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. "Bloom identified this gap before the market did, and the business traction we've seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.
About Bloom Security
Bloom Security is endpoint security built for the AI era. As AI agents, MCP servers, browser extensions, and local automation become fixtures on every employee device, traditional endpoint security tools no longer provide the visibility or control organizations need. Designed for this new reality, Bloom Security delivers a full inventory of everything running across the fleet, contextual risk assessment that goes beyond malware, and precise remediation that enables security teams to govern modern tools without slowing teams down.