
Palo Alto Networks veterans launch Bloom Security with $20 million bet on the AI endpoint
The Israeli startup argues that traditional cybersecurity tools were built for malware, not for a world where employees and AI systems install software that can access sensitive company data.
Cybersecurity startup Bloom Security has raised $20 million in a Seed funding round led by Glilot Capital Partners and Ten Eleven Ventures, with participation from Okta Ventures and Runtime Ventures. The round also included angel investors, including the founders of cybersecurity companies Snyk, Demisto, Dig Security, and Talon.
Bloom Security was founded in 2025 by Itay Keren, the company's CEO, Ofir Balassiano, Chief Product Officer, and Itay Frishman, Chief Technology Officer. The three founders previously held senior engineering, product, and research roles at Palo Alto Networks following its acquisitions of Dig Security and Demisto. Before entering cybersecurity, Keren served as a submarine officer in the Israeli Navy, Balassiano began his career in the IDF's Mamram Unit, and Frishman previously held R&D leadership roles in Unit 81. Bloom currently employs 30 people in Israel, many of whom previously worked together at Dig Security.
Employee laptops and developer workstations have evolved into increasingly complex software environments. Alongside operating systems and enterprise-approved applications, they now run AI agents, MCP servers, browser and integrated development environment (IDE) plugins, automation tools, and countless code libraries. Browsers, development environments, and AI agents have themselves become platforms with app stores and package managers, causing the number of programs running on each machine to grow faster than security teams can track.
Some of these tools are installed directly by employees, while others are added automatically by AI-powered applications. They often receive extensive permissions and gain access to sensitive data and enterprise services without undergoing a formal security review. According to Bloom, traditional endpoint detection and response (EDR) products were built to detect malware, malicious executables, and suspicious processes, but are poorly suited to managing risks created by legitimate AI agents, browser extensions, code packages, and automation tools that have become part of everyday enterprise workflows.
Bloom Security has developed an endpoint security platform designed specifically for the AI era. The platform uses autonomous AI agents to analyze and map the applications, AI agents, plugins, extensions, and code running on every endpoint, identifying what data and systems they access and how they interact with one another.
Its risk analysis is context-aware: software that may be appropriate for one employee can present a security risk on another employee's device, depending on the user's role, access privileges, the data they can access, and the other applications running in the same environment. The platform analyzes permissions, configurations, and software supply chain risks, enabling organizations to block risky installations before they reach employee devices, enforce security policies, and remediate threats without disrupting employee productivity.
Bloom says its platform is already deployed at dozens of large enterprises across the United States and Europe, where customers are using it to replace broad security restrictions with more granular, context-based controls as they expand their use of AI tools.
Itay Keren, CEO of Bloom Security, said: "In the AI era, the employee device is no longer just a managed endpoint. Every endpoint is now running software no one reviewed, connecting to services no one provisioned."
He added: "Employee computers no longer run only software that organizations have selected, tested, and approved. They now run AI agents, plugins, and code packages that connect to services and gain access to information, often without security teams even knowing about them. We founded Bloom to help organizations understand what is actually running on every computer and control those risks without slowing productivity or limiting the adoption of AI tools."
Ofir Balassiano, Bloom's co-founder and Chief Product Officer, said: "The same tool can be completely acceptable on one endpoint and high-risk on another. Risk depends on context: the user's role, access to sensitive data, the other tools operating on that endpoint, and how everything interacts. Bloom Security was designed to evaluate that context in real time."
Koby Samboursky, Founder and Managing Partner at Glilot Capital, said: "The endpoint is evolving faster than existing security stacks can keep up. Agents, plugins, and code packages running directly on employee devices create a new layer of risk that existing tools weren't built to address."














