Glow

Cybersecurity Dual-Use Technology Priority Signal Founded 2025

Last updated: Aug 2, 2026

Glow is an Israeli-founded, AI-native endpoint security company that emerged from stealth on 22 July 2026 with $180M in disclosed funding at a $1.2B valuation, selling a prevention-first platform that inventories and controls every piece of software, developer tool, and AI agent running on corporate devices. Its thesis is that classic detect-and-respond EDR is structurally mismatched to an era in which employees install AI agents, MCP servers, and open-source packages faster than security teams can see them.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Glow attacks a visibility-and-control gap that widened sharply as generative AI moved onto employee laptops. The endpoint is where an organization's software actually executes, and it is now where employees unilaterally introduce AI coding assistants, autonomous agents, browser extensions, MCP connectors, and open-source packages — often within hours of a tool going viral, and always ahead of procurement. Glow's own framing of the shift is that the share of corporate devices running AI software rose from roughly 15% to roughly 45% within a year, and that a large majority of what runs on a managed device (the company claims 67%) is invisible to the tools already installed on it. The consequence is that the endpoint agent stack an enterprise pays for — EDR, MDM, DLP — reports on a fraction of reality, and its central assumption, that the security team will detect and respond after something malicious runs, breaks when the risky artifact is a legitimate-looking npm package, an unvetted AI agent with broad local permissions, or a developer tool with credential access. Glow's product is therefore built around three functions the company names publicly: **Asset Intelligence** (continuous discovery and validation of endpoints and every software layer on them, maintaining what it calls a living inventory that stays accurate), **Software Control** (autonomous remediation and policy enforcement agents that decide what is allowed to enter and what gets removed), and **Safe AI Adoption** (shadow-AI discovery plus governed enablement of sanctioned AI tooling). The posture is prevention rather than post-hoc detection: keep the risky artifact out, rather than alert on it after execution.

**Core technology and how it actually works.** Glow's architecture pairs a device-resident sensing and enforcement layer with a cloud reasoning layer built from specialized AI agents rather than a single monolithic model. Those agents continuously map the environment, score risk in real time against enterprise context, and then act — quarantining, removing, or gating software without a human writing a rule per artifact. CEO Roi Tiger has publicly drawn the contrast with incumbent EDR: existing products focus primarily on detecting threats after they emerge, whereas Glow is designed to prevent risky software, AI agents, and developer tools from entering enterprise environments in the first place. On the model layer, Glow has said it uses frontier models from Anthropic and Google (Gemini) served via Amazon Bedrock, combined with proprietary software that supplies the enterprise-specific context — an important diligence detail, because it locates the company's defensible work in the context/reasoning engine, the device telemetry, and the enforcement plumbing rather than in model training. Publicly cited early results are operational rather than benchmark-style: the platform has blocked malicious npm packages before installation, surfaced rogue AI agents running on employee machines, and identified devices whose existing endpoint tooling was missing or silently degraded — the last of which is a meaningfully differentiated capability, since a decayed EDR agent is a failure mode most EDR consoles report poorly on themselves. Typical deployments are described as spanning tens of thousands of devices. The company lists SOC 2, ISO 27001, and GDPR compliance on its site.

**Market, customers, and go-to-market.** Glow is selling into the endpoint security market, which press coverage of the launch sizes at roughly $40 billion, against incumbents with entrenched agents and multi-year enterprise contracts. Its wedge is not to rip out EDR immediately but to occupy the adjacent, newly urgent budget line — AI governance and software control on the endpoint — where CISOs face board-level pressure and no incumbent has a settled answer. Go-to-market is a classic Cyberstarts-style, CISO-led enterprise motion, and the company's public proof points reflect it: named customer logos on its site include Fanatics, Qualtrics, Antares Capital, Xactly, and Hospital Sisters Health System, with attributed endorsements from Larry Dolan (SVP, CISO at Fanatics), Kyle Weckman (CISO, Antares Capital), Eli Edelkind (CISO, CAVA), and Scott Crowder (SVP & CIO, BMC Software). Sector concentration so far is healthcare, retail, and financial services — regulated, device-heavy industries where unmanaged software is both a compliance and a breach problem. COO Emily Heath, herself a former CISO at United Airlines and DocuSign, is a strong signal of a buyer-empathy-led motion. Glow showcased the platform publicly at Black Hat USA 2026 (3-5 August, Las Vegas), roughly two weeks after emerging from stealth.

**Traction, funding, and third-party validation.** Glow disclosed $180 million at a $1.2 billion valuation on 22 July 2026, led by Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures, with participation from Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures. Reporting differs on the round structure and this is worth flagging precisely: the company's own announcement and several outlets present the $180M as a single headline raise (some describing it as a Series A), while CTech reports it as three stacked rounds disclosed together — a roughly $20M seed from Sequoia and Cyberstarts, a roughly $60M Series A at about a $400M valuation with Index and Greenoaks, and a roughly $100M Series B at the $1.2B mark. Either way the substance is the same: a company founded in 2025 was marked up roughly 3x within about a year and never publicly shipped a product until launch day. Headcount is close to 100, with roughly 65-70 people in Israel and the remainder in the United States. The strongest external validation is the combination of the syndicate (Sequoia plus Cyberstarts, whose CISO network is the sharpest early-signal machine in Israeli cyber), the named enterprise logos with on-record CISO quotes, and the seniority of the operating team. What is not disclosed is revenue, ARR growth, customer count, or net retention — the standard gaps for a company at this stage of publicity.

**Founders and team background.** The founding team is unusually senior for a one-year-old company. CEO and co-founder **Roi Tiger** spent nine years at Meta, most recently as VP of Engineering, arriving through Meta's acquisition of Onavo, the Israeli mobile-analytics company he co-founded — a background that is directly on-point (endpoint telemetry at consumer scale) and also a reputational liability, since Onavo's data-collection practices became a well-documented controversy for Meta. CTO and co-founder **Omer Singer** was Snowflake's Head of Cybersecurity Strategy and a Unit 8200 veteran, giving the company depth in security data modeling and in selling to security-data buyers. VP of R&D and co-founder **Ophir Arie** was VP of R&D at Claroty, a Talpiot and Unit 8200 graduate, bringing hard-edged experience building agents and asset-discovery systems for environments where you cannot simply reboot the endpoint. The executive bench extends the pattern: CPO **Arnon Joseph** spent eight years at Meta as a Senior Director of Product, and COO **Emily Heath** was CISO at United Airlines and DocuSign, a Cyberstarts partner, and a Wiz board member through the $32 billion Google acquisition. This is a team assembled to sell to Fortune 500 CISOs from day one.

**Competitive dynamics.** Glow is entering the most heavily defended segment in security software, and its edge is timing and architecture rather than a novel primitive. (1) Against **CrowdStrike** and **SentinelOne**, the incumbent EDR/XDR duopoly, Glow argues category mismatch — detection-and-response versus prevention-and-control — but both incumbents have enormous distribution, their own agent already installed, and every incentive to ship AI-governance features into an existing console. (2) Against **Microsoft Defender for Endpoint** and Intune, the bundling threat is structural: 'good enough and already paid for' has killed better point products before. (3) Against **Tanium** and **Nexthink**, Glow's Asset Intelligence pillar competes directly on endpoint discovery and software inventory, a mature market where the incumbents' claim is completeness at scale. (4) Against the shadow-AI cohort — enterprise-browser and AI-governance players such as **Island**, **Prompt Security**, and a rapidly growing set of AI-agent security startups including Israeli peers **Koi Security**, **Neo**, and **Bloom Security** — Glow competes for the same emerging budget line with a device-layer rather than browser-layer or identity-layer approach. (5) The quiet fifth competitor is **the endpoint agent budget itself**: security teams resist adding another agent, so Glow must either displace something or prove it consolidates. Its most defensible differentiators are the control-plane position (allow/deny at install time), the ability to audit the health of other endpoint agents, and a context engine tuned to AI-era artifacts that legacy application-control products (which think in executables, not agents and MCP servers) do not model well.

**Defense, security, and resilience dual-use relevance.** The dual-use case here is real but should be stated as infrastructure relevance rather than a fielded defense capability. Software-supply-chain compromise and unvetted autonomous agents on privileged endpoints are among the most consequential vectors facing government, defense-industrial, and critical-infrastructure operators — the class of problem exemplified by malicious package injection and by AI agents holding credentials with lateral reach. A prevention-first control plane that maintains an accurate inventory of everything executing on a device, blocks unvetted packages at install time, and detects silently degraded security agents maps directly onto the hardening requirements of defense primes, government IT estates, hospital systems, utilities, and other operators of essential services; the healthcare and financial customers already disclosed are the commercial expression of the same requirement. The team's provenance reinforces the adjacency: Unit 8200 and Talpiot backgrounds, and a co-founder from Claroty, whose entire business is protecting industrial and critical-infrastructure environments. Calibration matters, though. As of August 2026 there is no disclosed government, defense, or critical-infrastructure contract, no FedRAMP or IL-level authorization in the public record, and no Israeli MoD or allied-military engagement announced. Glow is dual-use in the same sense that endpoint security generally is — the same product hardens a bank and a defense agency — not because it has built anything military-specific. Any national-security thesis rests on the sovereignty and resilience value of allied-controlled endpoint control planes and on future public-sector accreditation, both of which remain to be demonstrated.

**Growth stage, trajectory, and key diligence risks.** Glow is an early-stage company with late-stage resources: founded 2025, ~100 employees, a shipped and deployed product, marquee logos, and $180M raised at a $1.2B valuation before its first Black Hat. The bull case is straightforward — an exceptional team, an unambiguous and newly urgent problem, a control-plane position with natural expansion room, and the best-networked syndicate in Israeli cyber. The diligence risks are equally clear. (1) **Valuation-ahead-of-evidence risk**: a $1.2B mark on a company with no disclosed revenue is a bet on the team and the category, and it sets a high bar for the next round. (2) **Incumbent bundling risk**: Microsoft, CrowdStrike, and SentinelOne can ship overlapping AI-governance capability into agents that are already deployed, compressing Glow's window. (3) **Agent-fatigue and displacement risk**: enterprises resist a fifth endpoint agent; Glow must consolidate spend, not add to it, and consolidation sales are slower. (4) **Model-dependency and cost risk**: reliance on third-party frontier models via Bedrock exposes unit economics and behavior to vendors Glow does not control, and puts the durable moat in context and enforcement rather than in the model. (5) **Prevention false-positive risk**: an autonomous system that removes or blocks software will eventually block something a business needs; a single high-profile productivity incident is a serious enterprise-sales setback, and the 2024 CrowdStrike outage set the industry's tolerance for endpoint-agent failure very low. (6) **Founder reputational risk**: the Onavo history will surface in procurement conversations at privacy-sensitive and public-sector buyers, precisely the accounts a dual-use thesis depends on. (7) **Disclosure gaps**: revenue, customer count, retention, and the exact round structure are not confirmable from public sources. Progression toward 'mid' would be evidenced by disclosed ARR or customer counts, a public-sector or defense accreditation, displacement wins against an incumbent EDR, and evidence that the prevention model holds up operationally at six-figure device counts.

Dual-Use Assessment

Military & Commercial Applications

Glow's dual-use character is genuine but is infrastructure relevance rather than a defense-specific capability, and should be assessed as such. (1) Threat-vector overlap: software-supply-chain compromise and unvetted autonomous AI agents holding local credentials are among the most consequential vectors against government IT estates, defense-industrial base suppliers, and critical-infrastructure operators; Glow's demonstrated behaviors — blocking malicious npm packages before installation, surfacing rogue AI agents, and detecting endpoints whose existing security agents are missing or silently degraded — map directly onto hardening requirements those operators share with commercial enterprises. (2) Control-plane value: an accurate, continuously validated inventory of everything executing on a device, with allow/deny enforcement at install time, is the kind of capability national cyber authorities have pushed toward for a decade (software bill-of-materials and application-control mandates), applied to the AI-agent era. (3) Team provenance: Unit 8200 and Talpiot backgrounds among the founders, and a co-founder who ran R&D at Claroty (industrial and critical-infrastructure security), give the company credible fluency in operator-grade environments. (4) Sector footprint: disclosed customers in healthcare (Hospital Sisters Health System) and financial services (Antares Capital) are regulated, resilience-sensitive verticals adjacent to critical-infrastructure requirements. Calibration: as of August 2026 there is no disclosed government, defense, or critical-infrastructure contract, no FedRAMP or equivalent public-sector authorization in the public record, and no announced Israeli MoD or allied-military engagement. Glow is dual-use in the way endpoint security generally is — one product hardens a bank and a defense agency alike — not because it has built anything military-specific. The strategic case rests on allied ownership of an endpoint control plane and on future public-sector accreditation, neither of which is yet demonstrated.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Glow presents a high-conviction team and category thesis priced well ahead of disclosed commercial evidence, and both halves of that sentence should carry equal weight in diligence. (1) Team quality is the primary asset: a CEO who spent nine years at Meta as VP of Engineering after co-founding Onavo (endpoint telemetry at consumer scale), a CTO who ran cybersecurity strategy at Snowflake, a VP R&D from Claroty, a CPO from Meta, and a COO who was CISO at United Airlines and DocuSign and a Wiz board member through the $32B Google acquisition — a bench that can reach Fortune 500 CISOs from day one. (2) Category timing is favorable and non-speculative: AI software presence on corporate devices rose sharply within a year, incumbents have no settled answer, and the buyer has board-level urgency, which is why the round drew Sequoia, Cyberstarts, Greenoaks, and Redpoint together. (3) Architectural position is defensible if held: an install-time allow/deny control plane plus authoritative asset inventory sits upstream of detection and creates natural expansion into adjacent controls. (4) Early proof points are concrete rather than narrative — named logos (Fanatics, Qualtrics, Antares Capital, Xactly, Hospital Sisters Health System) with on-record CISO endorsements, and deployments in the tens of thousands of devices. Counterweights that must dominate the assessment: (a) a $1.2B valuation on a company with no disclosed revenue, ARR growth, or retention data; (b) severe incumbent-bundling exposure to Microsoft, CrowdStrike, and SentinelOne, any of which can ship overlapping AI-governance features into an already-deployed agent; (c) endpoint agent fatigue, which forces a slower consolidation sale rather than an additive one; (d) dependency on third-party frontier models for core reasoning, which leaves unit economics and behavior partly outside the company's control; (e) prevention-side false-positive risk, where a single high-profile productivity outage is disproportionately damaging in this category; and (f) founder reputational history around Onavo, which will surface in privacy-sensitive and public-sector procurement. This is a strategic and technical fit assessment, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Glow's strategic value lies in owning the decision point for what software is permitted to execute inside an organization, at exactly the moment that question became about autonomous agents rather than applications. (1) Control-plane leverage: whoever adjudicates install-time allow/deny across a device fleet holds a structurally powerful position — upstream of detection, upstream of DLP, and directly in the path of the software supply chain that has produced the most consequential compromises of the past five years. (2) AI-era relevance: enterprise adoption of autonomous agents is outrunning governance, and an inventory-plus-enforcement layer purpose-built for agents, developer tools, and MCP-style connectors addresses a gap that neither legacy application-control nor identity-centric AI-security products model well. (3) Resilience adjacency: the same capability that hardens a hospital system or a bank is the capability a defense-industrial supplier, utility, or government IT estate needs, and the founding team's Unit 8200, Talpiot, and Claroty provenance makes that translation credible rather than aspirational. (4) Allied-ecosystem depth: an Israeli-rooted endpoint control plane with a top-tier U.S. syndicate adds sovereign-adjacent optionality in a layer where allied nations increasingly prefer trusted-vendor supply, though realizing that requires public-sector accreditation Glow does not yet hold. (5) Talent and syndicate gravity: the round pulled Sequoia, Cyberstarts, Greenoaks, and Redpoint simultaneously, concentrating exactly the network that has produced Israel's recent security outcomes. The ceiling on strategic value is set by execution against incumbents and by whether the company converts commercial traction into public-sector and critical-infrastructure deployment; absent that, the strategic weight is that of a well-backed commercial security vendor with credible resilience adjacency rather than a national-capability asset.

Key Technologies

  • Specialized cloud-side AI agents that continuously map the endpoint environment, score risk against enterprise context in real time, and enforce policy autonomously rather than via hand-written per-artifact rules
  • Prevention-first software control: allow/deny enforcement at software-installation time for applications, developer tools, browser extensions, open-source packages, and AI agents (e.g., blocking malicious npm packages before install)
  • Endpoint Asset Intelligence — continuous discovery and validation of devices and every software layer on them, maintaining a self-correcting live inventory rather than a periodically refreshed CMDB snapshot
  • Security-agent health verification: detection of endpoints where existing EDR/MDM tooling is missing, misconfigured, or silently degraded — a self-reporting blind spot of incumbent agents
  • Shadow-AI discovery and governed enablement: inventory of unsanctioned AI tools, agents, and MCP-style connectors on corporate devices, with policy paths to sanction rather than simply block
  • A proprietary enterprise-context and reasoning engine layered over third-party frontier models (Anthropic and Google Gemini served via Amazon Bedrock) to translate raw telemetry into environment-specific risk decisions
  • Autonomous remediation agents that quarantine or remove non-compliant software at scale across deployments spanning tens of thousands of devices

Use Cases & Applications

  • Blocking malicious or typosquatted open-source packages (e.g., npm) on developer laptops before installation, closing a primary software-supply-chain vector
  • Discovering and governing shadow AI — unsanctioned AI assistants, autonomous agents, and connectors installed by employees on managed corporate devices
  • Continuous software and device inventory for regulated industries needing defensible audit evidence of what executes on endpoints (SOC 2, ISO 27001, GDPR postures)
  • Detecting and remediating endpoints where EDR, MDM, or DLP agents are absent, stale, or silently failing — closing coverage gaps incumbent consoles under-report
  • Enforcing developer-tool policy in engineering organizations without blocking legitimate productivity, via context-aware allow/deny rather than blanket application whitelisting
  • Consolidating overlapping endpoint control, application-allowlisting, and AI-governance tooling into a single agent to reduce endpoint agent sprawl
  • Hardening device fleets in healthcare and financial-services environments where unmanaged software is simultaneously a breach risk and a regulatory exposure
  • Prospective hardening of government, defense-industrial, and critical-infrastructure IT estates against AI-agent and supply-chain compromise (adjacency; no disclosed public-sector contract to date)

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 8 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Glow may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Glow's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.