Thursday

30-07-2026 Vol 19

Bloom Security’s $20 Million Seed Raises the Question: Is EDR Enough for the AI Era?

Endpoint security has been considered a solved category for years. EDR vendors consolidated, capabilities matured, and the market settled into a familiar shape. Bloom Security, which launched from stealth today with a $20 million seed round first reported by Axios, is built on the argument that the category quietly stopped matching the problem.

The round was led by Glilot Capital Partners, with participation from Ten Eleven Ventures (1011vc), Okta Ventures, and Runtime Ventures, alongside angel investors including founders of Dig Security, Demisto, Snyk, and Talon.

The Case Against the Status Quo

EDR was designed for malware. Binaries, executables, malicious processes: the threat model assumed something identifiably hostile would land on a device and needed to be caught. That assumption held for a long time.

Bloom Security’s contention is that the composition of the endpoint has changed in ways that break it. Employee devices are now ecosystems of agentic software, MCP servers, browser extensions, and code packages assembled daily. AI tools are no longer optional. They are how modern work gets done. Browsers, IDEs, and AI agents ship with their own app stores and marketplaces, generating a software layer that grows faster than any security team can track and that existing security infrastructure was never built to see.

“In the AI era, the employee device is no longer just a managed endpoint,” said Itay Keren, Co-Founder and CEO of Bloom Security. “Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”

The examples the company cites are notable for how mundane they are. A misconfigured AI agent. A plugin with excessive data permissions. A screen recorder running on an executive’s laptop. A code library pulling from an untrusted source. None of these would trigger a malware signature. Each can create a dangerous attack path. The company’s core claim: risk starts with what is already running, and most security teams lack a way to control it.

The Category Bloom Is Claiming

Rather than positioning as a better EDR, Bloom Security is defining a different job: clarity, governance, and active enforcement for the AI-native endpoint. The platform integrates deep contextual visibility, proactive enforcement, granular remediation, and proactive prevention into one architecture.

Visibility means a holistic view of every piece of software across every endpoint, covering tools, extensions, and code, plus the context of how they interact with data and systems. The platform analyzes supply chain risk and inspects configurations and permissions to determine actual exposure rather than nominal risk.

The governance layer is where the philosophical break from EDR is sharpest. In the EDR worldview, a file is either malicious or it is not. In Bloom Security’s worldview, that binary does not exist. “The same tool can be completely acceptable on one endpoint and high-risk on another,” said Ofir Balassiano, Co-Founder and Chief Product Officer. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”

Enforcement completes the loop. Teams can block risky installs before they reach employee endpoints to prevent supply chain risks, enforce secure configurations directly, and remediate without manual approval workflows or disruption to how employees work.

“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren said. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”

Credentials and Continuity

Category creation claims deserve scrutiny, and the strongest counterweight to skepticism here is the founding team’s track record. All three founders passed through Palo Alto Networks and Dig Security, which Palo Alto Networks acquired.

Keren held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security, and Demisto, another Palo Alto Networks acquisition, and served as a Naval Officer before his security career, leading teams in high-pressure environments. Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks with a focus on AI, identity, and data security, after leading research at Dig Security and serving as a Senior Security Researcher at XM Cyber. He began in the IDF’s Mamram Unit. CTO Itay Frishman built core AISPM and DSPM solutions at Palo Alto Networks and Dig Security, with earlier cybersecurity R&D leadership in the IDF’s Unit 81.

“While this is technically our first company as founders, our team has built and integrated category-defining products before,” Frishman said. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”

The company employs 30 people, many of them Dig Security alumni.

The Evidence So Far

The most persuasive data point in today’s announcement is deployment. Bloom Security is already running at dozens of large enterprises across the United States and Europe. Customers report gaining total visibility into their endpoints and moving from rigid, blanket policies to precise, contextual remediation. The go-to-market focus is large enterprises navigating AI adoption at scale.

Kobi Samboursky, Founder and Managing Partner at Glilot Capital, which led the round, put the firm’s position bluntly. “AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee’s machine, entirely outside the reach of traditional controls,” he said. “Bloom identified this gap before the market did, and the business traction we’ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.”

The Open Question

Whether the AI-native endpoint becomes a recognized category or gets absorbed into existing platforms is the question this launch puts on the table. What is not in question is the underlying shift. Software no one reviewed is running on devices everywhere, connected to services no one provisioned. Bloom Security has raised $20 million on the belief that this deserves its own answer. The market will now weigh in.

Charlotte