Enterprise security teams have long treated the endpoint as a relatively well-defined security boundary: a laptop, a workstation or another managed device that can be monitored for malware and suspicious activity. The rapid adoption of AI is changing that model, turning employee devices into increasingly complex environments filled with software, agents, extensions and external connections.

The company was founded by a team with previous experience building enterprise security products, and it says its platform is already deployed at dozens of large enterprises across the United States and Europe.

The Software Layer Security Teams Can't Easily See

The challenge Bloom Security is targeting is broader than traditional malware detection. Employees now routinely use AI tools, browser extensions and other software that can connect to systems, access data or interact with other applications. At the same time, browsers, IDEs and AI agents increasingly have their own marketplaces and app stores, creating an expanding software ecosystem on corporate endpoints.

"In the AI era, the employee device is no longer just a managed endpoint," said Itay Keren, Co-Founder and CEO of Bloom Security. "Every endpoint is now running software no one reviewed, connecting to services no one provisioned."

Bloom argues that these changes create security risks that conventional endpoint detection and response tools were not designed to address. The concern is not necessarily that a piece of software is malicious, but that it may have excessive permissions, be poorly configured or create an unexpected path to sensitive information.

A misconfigured AI agent, for example, could introduce risk without behaving like traditional malware. The same can apply to a browser extension with broad data access, a screen recorder installed on an executive's computer or a code library that pulls from an untrusted source.

“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren added. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”

From Inventory to Active Enforcement

Bloom Security's platform is designed to give security teams a broader view of what is operating across their endpoint environments. That includes software, tools, extensions and code, as well as the relationships between those components and the organization's data and systems.

The platform also evaluates supply-chain risk, configurations and permissions to assess potential exposure. The company's approach centers on contextual analysis rather than treating every installation or application as carrying the same level of risk.

“The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”

The company says its platform can also be used to block risky software installations before they reach employee devices, enforce secure configurations and remediate identified risks. The goal is to give security teams more precise controls without relying on manual approval workflows or disrupting employee productivity.

That emphasis on context is also reflected in Bloom's broader positioning. Rather than focusing exclusively on detecting malicious activity, the company is attempting to address the security implications of everything that is running on the modern endpoint.

An Experienced Team Takes on a Growing Problem

Bloom's founding team brings experience from several enterprise security companies. Keren previously held engineering and sales engineering leadership positions at Palo Alto Networks, Dig Security and Demisto. Balassiano previously led the Cortex Cloud Posture Security research group at Palo Alto Networks and worked at Dig Security and XM Cyber.

Chief Technology Officer Itay Frishman previously built AISPM and DSPM solutions at Palo Alto Networks and Dig Security, alongside earlier cybersecurity research and development experience.

“While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Itay Frishman, Co-Founder and CTO. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”

Bloom currently employs 30 people, many of whom previously worked together at Dig Security. According to the company, its platform is already being used by dozens of large enterprises in the United States and Europe.

For investors, the company's proposition reflects a broader shift in how enterprise technology is being deployed. As AI tools become embedded in everyday workflows, security teams are being asked to govern an endpoint environment that is increasingly defined not only by the devices employees use, but by the rapidly expanding collection of software and services running through them.

**“AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee's machine, entirely outside the reach of traditional controls," said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. "Bloom identified this gap before the market did, and the business traction we've seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.