Bloom Security Raises $20 Million to Protect Organizations from Unknown AI Tools on Endpoints
Bloom Security, an Israeli cybersecurity startup founded in 2025 by former Israeli Navy and elite tech unit veterans Itay Keren (CEO), Ofir Belsiano (CPO), and Itay Frishman (CTO), has secured $20 million in a seed funding round. The round was led by Glilot Capital with participation from Ten Eleven Ventures, Okta Ventures, Runtime Ventures, and private investors including founders of cybersecurity firms Snyk, Demisto, Dig Security, and Talon. The company currently employs 30 staff members, mostly ex-Dig Security and Palo Alto Networks employees.
Bloom Security addresses the growing security challenge posed by the proliferation of AI agents, browser extensions, development environment plugins, automation tools, and code libraries running on employee and developer computers. These endpoint environments have evolved into complex software ecosystems with app stores and package management, often including tools installed without formal organizational approval. Such tools can gain permissions and access sensitive data without security teams' knowledge.
The company’s platform uses autonomous AI agents to analyze and map all software, plugins, and code running on each endpoint, assessing their access to information and interaction with other tools. Risk evaluation is context-aware, considering the user’s role, data access, and the combination of active tools. This enables blocking dangerous installations, enforcing security policies, and mitigating risks without disrupting user workflows or AI adoption.
CEO Itay Keren emphasized that employee computers no longer run only vetted software but also AI agents and code packages that may access sensitive data unnoticed by security teams. Glilot Capital managing partner Kobi Sambursky noted that existing security solutions cannot keep pace with the rapid evolution of endpoint environments, which now include new risk layers from AI agents and code packages.
Bloom Security’s technology aims to give organizations full visibility and control over endpoint risks in the AI era, balancing security with operational agility.
