Every once in a while, you meet a team where conviction comes quickly. That was the case for us with Bloom Security.
Many of the founding team were early employees at Dig Security, a company I previously backed before its acquisition by Palo Alto Networks. I’d seen firsthand how this group built products, operated inside enterprise environments, and navigated major platform shifts in cybersecurity. So when I heard they were coming back together to start something new, there was already a strong foundation of trust.
What makes this team particularly compelling is that they’ve experienced the full arc of company-building: creating category-defining products from the ground up, scaling them within high-growth startups, and then operating them within one of the world's largest cybersecurity platforms. That’s a rare hat trick.
And now, the team has decided to tackle a completely new and game-changing opportunity in the cybersecurity space: securing AI-native endpoints. An exceptional team facing a new, huge opportunity, enabled by one of the most impactful technology waves we’ve ever seen, is not something you see every day as an investor. That’s why we’re thrilled to be investing in the team and backing their vision.
Building Security for the AI-Native Endpoint
We all know that the modern employee device looks nothing like it did even a few years ago - maybe even six months ago! Today’s endpoints increasingly consist of AI agents, browser extensions, MCP servers, local automation tools, containers, and open-source packages that employees install and configure themselves. And this shift is no longer limited to developers. Teams across marketing, finance, sales, and operations are rapidly adopting AI-native tooling to increase productivity. In fact, with trends like “token-maxxing,” where employees increasingly deploy AI agents and consume ever-larger volumes of tokens to accelerate output, and organizations beginning to measure, incentivize, and even mandate AI adoption, we know that these fundamental changes will only accelerate. As workers build increasingly sophisticated ecosystems of AI-powered tools around their daily workflows, the definition of an enterprise endpoint is rapidly expanding beyond the traditional device itself.
As the endpoint is evolving into a highly dynamic and programmable environment, the challenge is that traditional endpoint security platforms were never designed for this. Legacy EDR solutions were built around detecting malware, binaries, and malicious executables. But many of today’s emerging risks don’t resemble traditional malware at all.
So Bloom is building AI-native, modern workstation protection, a platform purpose-built for how endpoints actually operate in the AI era.
Bloom gives enterprises visibility into the tools, agents, extensions, and software running across employee devices, while layering in contextual understanding around permissions, data access, configurations, and software interactions. That contextual approach is critical because endpoint risk is no longer binary. The same tool may be perfectly acceptable on one employee’s device and highly sensitive on another, depending on the user’s role, access privileges, or surrounding environment. And where Bloom finds risk, it acts - remediating misconfigurations automatically, blocking unapproved software before it reaches the endpoint, and enforcing policy continuously across the fleet.
Capturing the Next Big Opportunity
CEO Itay Keren and the broader Bloom team have consistently operated at the center of major transitions in enterprise security architecture. They understand how quickly AI adoption is changing the endpoint landscape, and they recognize that security teams need visibility and control without slowing employees down.
As AI changes how software is built, distributed, and consumed, the endpoint is becoming one of the most important and underprotected layers in enterprise security.
We’re excited to partner with Itay K. and Itay F., Ofir as well as the entire Bloom team as they bring clarity, governance, and control to that complexity without disrupting how people work.