Decoding the business of technology.
examnity.

Bloom Security Secures $20 Million to Protect Enterprise Endpoints from AI-Driven Risks

Bloom Security emerged from stealth this week with a $20 million seed round — and as Pulse 2.0 reports, the real story isn't the check size.

Grace Linwood, Silicon Valley Culture & Venture Chronicler · updated July 30, 2026

Bloom Security Secures $20 Million to Protect Enterprise Endpoints from AI-Driven Risks

It's the moment when an enterprise laptop became something the security industry barely recognizes anymore.

The round, led by Glilot Capital Partners, drew in Ten Eleven Ventures, Okta Ventures, and Runtime Ventures, plus a roster of angel checks from founders of Dig Security, Demisto, Snyk, and Talon. The company is already deployed across dozens of large enterprises in the US and Europe — striking traction for a 30-person team still in stealth mode.

The endpoint stopped being a laptop

Here's the friction that pulled the round together. The modern employee device isn't a managed box running a known OS image anymore — it's an ecosystem of agentic software, MCP servers, browser extensions, and code packages that employees assemble, often daily. Traditional endpoint detection and response tooling was built for malware, and it shows. Nobody designed it for the quieter risk of a junior PM installing an AI agent that quietly exfiltrates a Salesforce export.

Bloom's pitch is contextual visibility: see every tool, extension, and piece of code running across an endpoint, understand how it touches data and systems, score the supply-chain risk, and give security teams the kill switch to block risky installs or enforce configuration without forcing an approval ticket into a Slack channel nobody reads.

Why the money showed up early

The founding team cut its teeth at Palo Alto Networks, Dig Security, and Demisto — pedigree that explains why a firm like Glilot would lead a seed on a 30-person company already logging real enterprise deployments. Co-founder and CPO Ofir Balassiano frames the gap plainly: traditional endpoint controls weren't built for a world where every employee machine runs software nobody reviewed, connecting to services nobody provisioned.

For security buyers, the practical question is whether contextual, real-time risk scoring actually holds up when an AI agent spins up a new MCP server at 2 p.m. on a Tuesday. The bet here is that the next breach won't come from malware at all — it'll come from the extension your marketing intern installed last week.

The parallel outside the enterprise is hard to miss. The creator economy has been stitching together its own unvetted stack for years — the world of influencers, streamers and YouTube and TikTok creators builds daily toolkits from the same kind of browser extensions, plugins, and automation scripts, most of which nobody has reviewed either. Bloom is betting the same audit gap, sitting inside the corporate perimeter, is about to get very expensive.