Bloom Security has emerged from stealth with a $20m seed round to tackle risks that traditional endpoint tools were never built to manage.
The round was led by Glilot Capital Partners and Ten Eleven Ventures, with Okta Ventures and Runtime Ventures also taking part. A group of angel investors joined as well, among them founders of Dig Security, Demisto, Snyk and Talon. The company said its platform is already live at dozens of large enterprises in the United States and Europe.
The startup is responding to a fundamental change in how employees work. AI assistants, browser extensions, MCP servers and code packages have become embedded in daily workflows, and browsers, IDEs and AI agents now come with their own marketplaces where new software can be installed.
As a result, the software running on corporate devices can grow faster than security teams are able to catalogue or evaluate it. The danger, in Bloom’s view, extends well beyond malware: perfectly legitimate tools can become hazardous when granted excessive permissions, configured incorrectly or allowed to touch sensitive data in unforeseen ways.
Examples cited by the company include misconfigured AI agents, plugins with broad data access, screen recorders and code libraries drawing from untrusted sources, exposures that often sit outside the remit of conventional EDR products.
Bloom Security’s platform builds a complete inventory of the tools, extensions and code operating across an organisation’s endpoints, then analyses how each component interacts with data and systems, alongside supply-chain risks, configurations and permissions. Central to its approach is the belief that software cannot be judged in isolation; an application may be safe for one employee yet dangerous for another depending on their role, data access and the surrounding tools on the device.
The platform goes further than monitoring, allowing security teams to block risky installations before they land on devices, enforce secure configurations and remediate issues without manual approval workflows.
The founding team draws on backgrounds at several enterprise cybersecurity firms. CEO Itay Keren previously held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security and Demisto. Chief product officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks after stints at Dig Security and XM Cyber, while CTO Itay Frishman built AISPM and DSPM solutions at Palo Alto Networks and Dig Security. The company employs 30 people, many of whom worked together at Dig Security. Axios first reported the launch and funding.
Bloom Security co-founder and CEO Itay Keren said, “In the AI era, the employee device is no longer just a managed endpoint. Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”
Keren added, “As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality. Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”
Bloom Security co-founder and chief product officer Ofir Balassiano said, “The same tool can be completely acceptable on one endpoint and high-risk on another. Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”
Bloom Security co-founder and CTO Itay Frishman said, “While this is technically our first company as founders, our team has built and integrated category-defining products before. We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”
Stay ahead of the regulatory curve with strategic intelligence and early insight trusted by industry leaders. Subscribe to the RegTech Analyst newsletter today.
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst





