Dossier · Private startup · 4 independent sources

Bloom Security

Cybersecurity Dual-Use Technology Priority Signal

Last updated: Sep 4, 2026

Bloom Security is an Israeli cybersecurity startup building endpoint security for the AI-native workplace, where employees and autonomous systems install agents, extensions, plugins, MCP servers, and code packages that legacy EDR and MDM tools may not fully inventory or govern. Its platform combines live endpoint discovery, contextual risk analysis, supply-chain prevention, AI guardrails, active enforcement, and remediation in one control plane.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Bloom Security is aimed at a specific change in enterprise risk: the endpoint is no longer just an operating system, a set of managed applications, and a known collection of executable files. Employees now install coding assistants, browser extensions, IDE plugins, open-source packages, local models, MCP servers, autonomous agents, and other software that can read local files, access credentials, call external services, or transmit company data. Traditional endpoint detection and response is valuable for identifying known malicious behavior, but it does not necessarily answer the operational question Bloom is targeting: is this tool safe on this particular endpoint, for this particular user, with this user's access and the other software already present? Bloom's public product thesis is that security teams need continuous visibility and active control over the whole endpoint ecosystem, including AI tools and non-binary software. The platform therefore presents itself as a complete endpoint solution with live inventory, contextual risk analysis, granular remediation, active prevention, and AI guardrails. The practical outcome is intended to be a smaller attack surface, fewer unmanaged tools, and a way for organizations to let employees use useful AI without accepting uncontrolled access to sensitive systems.

**Core technology and how it works.** Bloom describes a device and control-plane architecture rather than a single detection model. Its live-inventory layer discovers the operating system, local data, installed applications, extensions, AI tools, code libraries, agents, and related components, then monitors changes across the fleet. Its contextual analysis combines marketplace intelligence, static analysis, and behavioral sandboxing to assess how a tool was built, what it can access, where it came from, and how it behaves in the local environment. That context is important because a package that is harmless in one workstation may be dangerous on a developer machine with production credentials or on an administrator's laptop. Bloom also claims enforcement across ecosystems such as npm, the Chrome Web Store, and Open VSX, allowing security teams to apply policy to the points where packages and extensions enter the environment. The AI Guardrails capability is intended to define what agents can access, execute, and transmit, while automatically reducing over-permissioned MCP configurations to safer defaults. The company has not publicly disclosed model architectures, telemetry volumes, endpoint-agent internals, policy language, or independent performance benchmarks, so the technical description should be treated as a product-level account rather than a verified claim of proprietary machine-learning superiority.

**Market, customers, and go-to-market.** Bloom is selling into the overlap of endpoint security, software supply-chain security, AI governance, and enterprise application control. The immediate buyer is likely a CISO or endpoint-security leader whose organization has accumulated overlapping EDR, MDM, application-control, browser-security, and AI-governance tools but still cannot establish what is actually running on employee machines. The wedge is timely because security teams are being asked to approve AI adoption while employees and developers can download new tools faster than a conventional review process can evaluate them. Bloom's platform can be positioned as an additive control plane for discovery and prevention, but long-term enterprise value depends on whether it consolidates or displaces existing agents rather than becoming another endpoint sensor. The company has public addresses in Tel Aviv and Wilmington, Delaware, and its launch materials emphasize continued research and product-team expansion in Israel. The public record does not name commercial customers, contract values, annual recurring revenue, renewal rates, or deployment counts. The reference quote on the official website is attributed to Bradley Schaufenbuel, a VP and CISO at an unnamed HCM market leader; that is evidence of buyer resonance, not proof of a disclosed customer relationship. Initial go-to-market is therefore best understood as enterprise security sales supported by a technically credible founding team and investor networks, with customer scale still to be established.

**Traction, funding, and third-party validation.** Bloom announced its launch from stealth on July 30, 2026 with a $20 million Seed round led by Glilot Capital Partners, with participation from Ten Eleven Ventures, Okta Ventures, and Runtime Ventures. The round also included cybersecurity angels associated with Dig Security, Demisto, Snyk, and Talon, giving the company a syndicate with relevant experience in cloud data security, security operations, software supply chain, and enterprise-browser protection. Axios reported the financing and identified CEO Itay Keren, while CTech independently described the company as an Israeli startup founded in 2025 by Keren, Ofir Balassiano, and Itay Frishman. The official investor announcement confirms the financing, Israeli launch location, and the company's focus on the AI-native endpoint. Startup Nation Finder records a November 2025 founding date, a 1-10 employee range, a released product, and an Israeli company-registration entry, although those directory details should be treated as a snapshot rather than a current audited cap table or headcount report. Bloom's own site gives a more useful product-level validation by documenting specific controls and by showing a live hiring posture in Israel. What remains missing is equally important: no independently measured detection or prevention rate, no named customer list, no formal certification publicly tied to the platform, no patent portfolio disclosed, and no evidence yet of a large production deployment. The $20 million round is a strong ecosystem signal, but it is not itself evidence that the product has won a mature market.

**Founders and team background.** Bloom's three founders bring unusually direct experience for the problem they are addressing. CEO Itay Keren previously held engineering and sales-engineering leadership roles at Palo Alto Networks and at Dig Security and Demisto, both of which were acquired by Palo Alto Networks. CPO Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks, previously led security research at Dig Security and XM Cyber, and began his career in the IDF's Mamram technical unit. CTO Itay Frishman is described by Bloom as an engineering leader who built core AI security posture-management and data-security posture-management solutions at Palo Alto Networks and Dig Security, with prior cybersecurity R&D leadership in the IDF's Unit 81. This background matters because the product sits at the boundary between endpoint telemetry, data access, application behavior, and security policy rather than in a single conventional antivirus category. The founders have seen how large vendors integrate acquired technology into broad platforms, how enterprise buyers evaluate risk controls, and how difficult it is to turn research concepts into production security products. At the same time, the team is still small and the public record does not disclose its broader engineering bench, advisory structure, or operational leadership. The central team diligence question is whether experience inside a major platform translates into the speed, product focus, and support capacity required to build a new endpoint control plane from a Seed-stage company.

**Competitive dynamics and edge.** Bloom enters a market with powerful distribution and several adjacent Israeli challengers. CrowdStrike and SentinelOne already own endpoint agents, telemetry, and security-console relationships at many target accounts; Microsoft Defender for Endpoint and Intune can bundle application-control and device-management features into existing enterprise agreements; Tanium competes on real-time asset inventory and software control; and Island competes for the browser and distributed-workforce security budget. Koi Security, although a distinct company, is the closest conceptual comparison in the local database because it also addresses AI agents, MCP servers, extensions, packages, and endpoint software that traditional tools miss. Glow is another distinct local comparison, with a broader prevention-first endpoint platform and a much larger disclosed capitalization. Bloom's plausible edge is the combination of four elements: a live inventory that treats agents and extensions as first-class assets; contextual, per-endpoint risk judgment instead of static allowlists; prevention at the software-supply-chain entry point; and founders who understand the enterprise-security acquisition and platform landscape from inside Palo Alto Networks. The product could be more useful than a narrow AI scanner because it connects discovery, policy, remediation, and prevention. None of those advantages is yet a proven moat. Incumbents can extend their agents, dedicated competitors can specialize more deeply in AI components, and the endpoint agent itself can become a procurement objection. Bloom must show that its context produces fewer false positives, catches meaningful risks earlier, and reduces total security-tool cost rather than adding another console.

**Defense, security, and resilience dual-use relevance.** Bloom's dual-use relevance is credible because the core problem is not limited to ordinary commercial laptops. Defense contractors, government agencies, hospitals, utilities, financial institutions, and other critical-infrastructure operators increasingly depend on developer workstations and administrative endpoints where an unapproved extension, malicious package, over-permissioned AI agent, or compromised update can become a path to sensitive data or operational disruption. A continuously validated inventory, contextual software-risk engine, package and extension enforcement, and agent permission controls could help those organizations harden the software perimeter around systems that cannot rely solely on network segmentation or periodic compliance audits. The supply-chain angle is particularly relevant to resilience: blocking a malicious component before installation can be less costly than detecting it after it has executed, while identifying a silently degraded security agent can close a blind spot that conventional consoles may not report accurately. Bloom's Israeli provenance also places it within a security ecosystem with substantial experience in endpoint, cloud, industrial, and intelligence environments. The connection remains an adjacency, not a fielded defense capability. Public sources reviewed here do not establish an Israeli Ministry of Defense contract, classified deployment, defense-prime customer, government authorization, air-gapped operating mode, or use in an operational mission. For public-sector adoption, diligence would need to test sovereign or self-hosted deployment, data residency, offline policy behavior, tamper resistance, audit retention, identity integration, export controls, and performance under degraded connectivity. Bloom is therefore dual-use through its defensive control technology and resilience applications, not because it has disclosed a military-specific product.

**Growth stage, trajectory, and key diligence risks.** Bloom is classified as early: it was founded in 2025, launched publicly in July 2026, raised a substantial Seed round, and has a released platform, but the public record does not establish revenue, retention, customer count, or scaled deployment. Its trajectory depends on whether AI changes the endpoint-security buying center faster than incumbents can absorb the category. A successful path would make Bloom the control layer for everything a user or agent installs, then expand from visibility into enforcement, remediation, AI governance, and software-supply-chain assurance. The main risks are (1) incumbent bundling by Microsoft, CrowdStrike, and SentinelOne; (2) agent fatigue and long enterprise replacement cycles; (3) false positives from autonomous blocking or permission reduction that interrupt legitimate developer or business work; (4) false negatives in rapidly changing packages, extensions, and agent ecosystems; (5) the cost and privacy burden of collecting enough endpoint context to make reliable per-user decisions; (6) competition from narrower AI-security vendors and browser or identity platforms; and (7) insufficient public evidence that the product works outside demonstrations. The $20 million round gives Bloom time to build, but it also raises the milestone bar for the next financing. Useful diligence milestones include named production customers, independently measured prevention and remediation outcomes, a clear endpoint-agent architecture, security attestations, evidence of displacement or consolidation, and a public-sector or defense-industrial evaluation. Until those appear, Bloom is a high-quality early Israeli cyber entry with strong team signals and strategic relevance, but with commercial proof and technical differentiation still to be earned.

Dual-Use Assessment

Military & Commercial Applications

Bloom's core endpoint control technology has credible commercial and defense or resilience applicability because defense contractors, government agencies, hospitals, utilities, and other critical-infrastructure operators face the same software-supply-chain and unmanaged-AI risks as commercial enterprises, often with higher consequences. Live inventory, contextual risk analysis, package and extension prevention, AI-agent permission controls, and remediation can reduce the chance that a compromised component reaches a privileged endpoint or that a silently degraded security tool creates an unreported blind spot. The dual-use case is defensive infrastructure adjacency, not a demonstrated military capability: public sources do not establish an Israeli Ministry of Defense contract, classified deployment, defense-prime customer, government authorization, air-gapped mode, or operational mission use. Public-sector diligence should test sovereign deployment, data residency, tamper resistance, offline behavior, audit retention, and degraded-connectivity performance.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Bloom is a high-signal early-stage company whose priority case rests on a credible product wedge and an unusually relevant founding team, not on a recommendation to invest. (1) The problem is concrete: security teams cannot reliably govern the fast-growing set of agents, extensions, packages, and local tools that execute on endpoints. (2) The architecture connects live inventory, contextual analysis, supply-chain prevention, AI guardrails, and remediation, giving Bloom a chance to own a broader control workflow than a narrow AI scanner. (3) The founders previously built and operated enterprise security products at Palo Alto Networks, Dig Security, Demisto, XM Cyber, and in Israeli technical units. (4) A $20 million Seed led by Glilot with Ten Eleven, Okta Ventures, Runtime Ventures, and relevant cyber angels is meaningful ecosystem validation. The counterweights are material: no named customers, revenue, retention, independent efficacy benchmarks, public deployment counts, or government accreditation; powerful incumbent bundling; endpoint-agent fatigue; and the possibility that Bloom's claimed context and prevention advantages become features in larger platforms. The next diligence gate is production evidence showing lower risk, fewer tools, or lower total security cost for customers.

Strategic Value to U.S.-Israel Alliance

Bloom's strategic value is concentrated in endpoint control at a moment when the software perimeter is expanding faster than enterprise governance. (1) A live inventory of AI agents, extensions, packages, and local code can provide decision-makers with a more accurate picture of what actually executes on sensitive machines. (2) Prevention at software-entry points can reduce the blast radius of supply-chain compromise before post-execution detection and response are required. (3) AI guardrails and permission reduction address the unusual risk of legitimate users or agents taking consequential actions with excessive access. (4) The same control layer could harden defense contractors, public agencies, hospitals, utilities, and other resilience-sensitive operators, although no public defense deployment is disclosed. Strategic value is capped until Bloom proves that its endpoint agent is reliable, privacy-preserving, low-friction, and materially better than bundled controls from Microsoft or incumbent EDR vendors.

Key Technologies

  • Live endpoint inventory covering operating systems, local data, applications, browser and IDE extensions, AI tools, agents, MCP servers, and code libraries
  • Contextual endpoint risk analysis combining marketplace intelligence, static analysis, behavioral sandboxing, user role, access, and local software relationships
  • Supply-chain prevention and policy enforcement across npm, Chrome Web Store, Open VSX, and other software-entry ecosystems
  • AI guardrails that govern what agents can access, execute, and transmit and can reduce over-permissioned MCP configurations
  • Fleet-wide active prevention, granular remediation, quarantine, and one-click correction of risky software and configurations
  • Agentic endpoint control plane that treats non-binary software, extensions, packages, and autonomous tools as security assets

Use Cases & Applications

  • Discovering shadow AI agents, MCP servers, browser extensions, IDE plugins, and local automation on employee endpoints
  • Blocking malicious, vulnerable, typosquatted, or policy-violating npm packages and other open-source components before installation
  • Governing AI-agent permissions on developer and administrator workstations that can access source code, credentials, or production systems
  • Continuously assessing browser and IDE extensions for excessive data access, unauthorized downloads, or policy bypass behavior
  • Maintaining auditable software inventories for regulated healthcare, financial-services, government, and defense-industrial environments
  • Detecting and remediating endpoints where EDR, MDM, DLP, or other security tooling is missing, misconfigured, or silently degraded
  • Enabling controlled adoption of approved AI tools while enforcing organization-wide policy across heterogeneous endpoint fleets
  • Hardening critical-infrastructure and public-sector workstations against software-supply-chain compromise and unauthorized autonomous actions

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 7 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • Bloom Security — Official Website Verifies the company's AI-native endpoint-security positioning, live inventory, contextual risk analysis, granular remediation, active prevention, AI guardrails, software-entry ecosystems, Israeli and U.S. addresses, and the public CISO testimonial.
  • About Bloom — Endpoint Security Rebuilt Verifies the founders, their Palo Alto Networks, Dig Security, Demisto, XM Cyber, Mamram, and Unit 81 backgrounds, the company's Israeli operating presence, and its hiring posture.
  • Why We Built Bloom Verifies Bloom's product thesis that endpoints now include AI agents, extensions, applications, local data, code, and supply-chain components, and describes the intended inventory, contextual reasoning, remediation, and prevention workflow.
  • Bloom Security Launches with $20 Million Seed to Secure the AI-Native Endpoint Investor announcement verifying the July 30, 2026 launch from stealth, $20 million Seed, Glilot lead, Ten Eleven, Okta Ventures, Runtime Ventures, relevant cyber angels, and Tel Aviv location.
  • Bloom Security raises $20M seed Independent funding coverage verifying the Seed round, Glilot and Ten Eleven leadership, CEO Itay Keren, and Bloom's endpoint-security focus.
  • Palo Alto Networks veterans launch Bloom Security with $20 million bet on the AI endpoint Israeli business-press coverage verifying the 2025 founding, the three founders, the $20 million Seed, investor participation, and the problem of traditional security tools missing AI-era endpoint software.
  • Bloom Security — Startup Nation Finder company profile Ecosystem profile verifying the released product, November 2025 founding snapshot, 1-10 employee range, Israeli registration and location, and the company classification as an endpoint-security startup.
  • Profile update timestamp Last updated in the Claw & Talon database on Sep 4, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.