thenextweb.com web signal

Bloom Security exits stealth with $20M for AI-era endpoints

TL;DR

  • Bloom Security raised $20M in seed funding led by Glilot Capital Partners and Ten Eleven Ventures, with Okta Ventures and Runtime Ventures participating.
  • The Tel Aviv platform inventories AI agents, MCP servers, browser extensions and code packages on employee endpoints, scoring risk by context not blanket blocks.
  • Bloom says it is already deployed at dozens of large enterprises across the US and Europe, with a 30-person team drawn from Dig Security alumni.

There is a specific gap that endpoint security has quietly opened up over the last eighteen months, and Bloom Security's coming-out-of-stealth pitch is that it exists to fill it. The Tel Aviv startup announced a $20 million seed round led by Glilot Capital Partners and Ten Eleven Ventures, with Okta Ventures and Runtime Ventures participating, according to The Next Web. Angel backing came from the founders of Dig Security, Demisto, Snyk and Talon, which is a very specific rolodex saying this is a real problem.

The problem, as Bloom frames it, is that a modern employee laptop is no longer a stable list of installed apps plus a browser. It now runs AI agents, MCP servers, browser extensions and code packages that arrive through channels the classic endpoint agents were never designed to inventory. Bloom's platform maps what is actually running on each device and then, in the words of Chief Product Officer Ofir Balassiano, treats risk as contextual: 'The same tool can be completely acceptable on one endpoint and high-risk on another.' Instead of blanket blocks it enforces policy against the specific combination of user role, data access and other tools present.

The credentials read the way you would expect a Palo Alto Networks alumni startup to read. CEO Itay Keren previously held leadership roles at Palo Alto Networks, Dig Security and Demisto. Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks. CTO Itay Frishman built core AISPM and DSPM solutions at Palo Alto and Dig. The 30-person team is heavily drawn from Dig Security. Bloom says it is already deployed at dozens of large enterprises across the United States and Europe.

The honest caveat is that 'contextual, risk-based' is exactly the pitch every next-generation security tool makes, and dozens-of-enterprises with no named logos is a claim to check rather than accept. It is also a category the endpoint incumbents will extend into if it turns out to be a durable line item rather than a temporary gap. What the reporting does not give you is the technical shape of the sensor, the pricing model, or whether Bloom watches agent behaviour or only inventories the software present.

The forward-looking piece is that whoever owns the visibility layer for AI-on-endpoint becomes the natural policy chokepoint for enterprise AI governance, which is a question every CISO with a Copilot or Claude rollout is going to have to answer to their board. Okta Ventures on the cap table hints at where the eventual hand-off to identity policy might land.