New York, USA, July 30th, 2026, FinanceWire
For much of the modern cybersecurity era, the endpoint has been a relatively straightforward concept. Security teams managed laptops and workstations, monitored processes and applications, and relied on endpoint detection and response tools to identify malicious activity. The rapid adoption of AI is changing that equation, introducing a new layer of software and services that traditional endpoint controls were not designed to govern.
Bloom Security is emerging from stealth with a $20 million seed round aimed at addressing that challenge. The Tel Aviv-based company said the round was led by Glilot Capital Partners and Ten Eleven Ventures (1011vc), with participation from Okta Ventures and Runtime Ventures. Axios first reported about the company's launch and funding.
The round also includes angel investors who founded companies including Dig Security, Demisto, Snyk and Talon. Bloom said its platform is already deployed at dozens of large enterprises across the United States and Europe.
The Endpoint Is No Longer Just a Device
The shift Bloom is targeting is driven by how employees now work. AI tools, browser extensions, MCP servers and code packages are increasingly becoming part of everyday workflows, while browsers, IDEs and AI agents themselves offer marketplaces and app stores where new software can be added.
That creates an environment in which the software layer on corporate devices can expand faster than security teams can inventory and assess it. For Bloom, the problem is not limited to malware. Software that is legitimate and widely used can still create risk when it has excessive permissions, is incorrectly configured or interacts with sensitive data in unexpected ways.
"In the AI era, the employee device is no longer just a managed endpoint," said Itay Keren, Co-Founder and CEO of Bloom Security. "Every endpoint is now running software no one reviewed, connecting to services no one provisioned."
The company points to examples that include misconfigured AI agents, plugins with excessive data permissions, screen recorders and code libraries that pull from untrusted sources. These scenarios represent a broader category of endpoint exposure that may fall outside the traditional focus of EDR products.
“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren added. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”
Security Based on Context
Bloom Security's platform is designed to provide a full inventory of software operating across an organization's endpoints, including tools, extensions and code. It also analyzes how those components interact with data and systems, while examining supply-chain risks, configurations and permissions.
The company's approach is based on the idea that risk cannot always be assessed by looking at a piece of software in isolation. The same application may be appropriate for one employee and potentially dangerous for another depending on the user's role, access to sensitive data and the other tools operating on the endpoint.
“The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”
The platform is also designed to move beyond passive monitoring. Bloom says security teams can block risky installations before they reach employee devices, enforce secure configurations and remediate identified risks without manual approval workflows.
A Familiar Team Tackling a New Problem
Bloom's founders bring experience from several enterprise cybersecurity companies. Keren previously held engineering and sales engineering leadership positions at Palo Alto Networks, Dig Security and Demisto. Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks and previously worked at Dig Security and XM Cyber.
Chief Technology Officer Itay Frishman built AISPM and DSPM solutions at Palo Alto Networks and Dig Security, following earlier cybersecurity research and development experience. Bloom currently has 30 employees, many of whom previously worked together at Dig Security.
“While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Itay Frishman, Co-Founder and CTO. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”
With its new funding and early enterprise deployments, Bloom is positioning itself around a security problem emerging alongside the AI adoption curve: how organizations can give employees access to rapidly evolving tools while maintaining visibility and control over what those tools can access and how they operate.