In partnership with

Endpoint platform that enforces what AI agents, extensions, and packages can safely run and access

Bloom Security was founded in 2025 in Tel Aviv by Itay Keren, Ofir Balassiano, and Itay Frishman, who held senior roles at Palo Alto Networks following its acquisitions of Dig Security and Demisto.

The founders’ observation is that corporate endpoints have become a development ecosystem.

Employees now run AI agents, connect MCP servers, install packages, and automate their own work directly on the device—citizen developers building faster than any review process can keep up with.

The agents and tools they assemble act under the employee's identity and have standing access to data, systems, and credentials, and traditional endpoint tooling has no visibility into what any of them are doing.

Bloom lets security teams enable this safely, covering the surface end to end. A supply chain firewall blocks unwanted software at install time; the software that is approved to run has its posture managed and its behavior held to runtime guardrails. Policy is customer-defined and enforced preventively on the device, governing which agents and tools may run, the identity each runs under, and the access each is granted.

Detections are intent based: an agent's action is evaluated by what it is attempting—reading a secret, moving data across a boundary, invoking a connected service—and resolved inline before it completes, with a permission revoked or a component removed at runtime, employee notified, without reimaging.

Those decisions rest on a live map of everything running across the fleet, with risk scored from marketplace intelligence, static and behavioral analysis.

Bloom raised a $20M seed led by Glilot Capital Partners and Ten Eleven Ventures, with Okta Ventures and Runtime Ventures participating, and says it is deployed at dozens of large US and European enterprises.

Market Segments:

Endpoint SecurityAI Security

Categories:

Endpoint SecuritySupply Chain SecurityAgent SecurityAI Guardrails