Some startups begin with an idea. Bloom Security began with a team. When the company emerged from stealth today with a $20 million seed round, first reported by Axios, the most striking detail was not the check size but the roster behind it: a founding trio forged at Palo Alto Networks and Dig Security, backed by angels who founded Dig Security, Demisto, Snyk, and Talon, and staffed by 30 employees, many of whom previously worked together at Dig Security.
The round was led by Glilot Capital Partners, with participation from Ten Eleven Ventures (1011vc), Okta Ventures, and Runtime Ventures.
Three Founders, One Lineage
CEO Itay Keren‘s résumé runs through two Palo Alto Networks acquisitions. He held engineering and sales engineering leadership roles at Palo Alto Networks, at Dig Security before its acquisition, and at Demisto before its own. His path into cybersecurity came after service as a Naval Officer, where he led teams in high-pressure environments.
Chief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks, concentrating on AI, identity, and data security. Before that, he led the research group at Dig Security and worked as a Senior Security Researcher at XM Cyber. His career began in the IDF’s Mamram Unit.
Chief Technology Officer Itay Frishman built core AISPM and DSPM solutions at Palo Alto Networks and Dig Security. His background includes cybersecurity R&D leadership in the IDF’s Unit 81.
The through line is unmistakable: enterprise security products built inside recognized companies, categories shaped from within, and an exit already on the shared record. “While this is technically our first company as founders, our team has built and integrated category-defining products before,” said Frishman. “We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.”
The Problem They Chose
Why would a team with this pedigree pick endpoint security, one of the industry’s most established markets? Because, in their telling, the endpoint itself has changed underneath the incumbents.
Devices that were once managed and predictable have become ecosystems of agentic software, MCP servers, browser extensions, and code packages that employees assemble daily. AI tools are no longer optional. They are how modern work gets done. Browsers, IDEs, and AI agents now ship with their own app stores and marketplaces, producing a software layer that grows faster than any security team can track. Existing security infrastructure was never built to see it.
“In the AI era, the employee device is no longer just a managed endpoint,” said Keren. “Every endpoint is now running software no one reviewed, connecting to services no one provisioned.”
Traditional EDR was built for malware: binaries, executables, malicious processes. On today’s endpoint, malware is only part of the problem. A misconfigured AI agent, a plugin with excessive data permissions, a screen recorder on an executive’s laptop, or a code library pulling from an untrusted source can each open a dangerous attack path. These are everyday tools. Risk starts with what is already running, and most security teams lack a way to control it.
“As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,” Keren added. “Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.”
The Product That Followed
Bloom Security’s platform integrates deep contextual visibility, proactive enforcement, granular remediation, and proactive prevention into a single architecture. It inventories every piece of software running across every endpoint, spanning tools, extensions, and code, and maps how each interacts with data and systems. It analyzes supply chain risk and examines configurations and permissions to establish actual exposure.
Balassiano, who shaped the product, describes context as its core. “The same tool can be completely acceptable on one endpoint and high-risk on another,” he said. “Risk depends on context: the user’s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.”
On the control side, teams can block risky installs before they reach employee endpoints, enforce secure configurations directly, and remediate risks without manual approval workflows or disruption to employee work. The company’s stated aim is a secure environment where productivity tools can be used to their full potential, free from unnecessary risk.
Backers Who Know the Founders’ Work
The angel list reads like a map of the founders’ professional world. Founders of Dig Security, where much of the team previously worked. Founders of Demisto, where Keren held leadership roles. Founders of Snyk and Talon, companies that defined their own security categories. These investors have watched this team operate up close.
The institutional side is equally notable. Kobi Samboursky, Founder and Managing Partner at lead investor Glilot Capital, tied the bet directly to the people and their timing. “AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee’s machine, entirely outside the reach of traditional controls,” he said. “Bloom identified this gap before the market did, and the business traction we’ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.”
Already in the Field
The traction Samboursky referenced is concrete. Bloom Security is deployed at dozens of large enterprises across the United States and Europe. Customers are gaining total visibility into their endpoints and replacing rigid, blanket policies with precise, contextual remediation. The company is focused on large enterprises navigating AI adoption at scale.
For a team that watched its previous companies get acquired by one of the industry’s largest players, the ambition this time is to build the defining company of a new layer. The Dig Security band is back together. Now the question is what they build as owners rather than operators.


















