Bloom Security, a cybersecurity company focused on governing AI-era software on corporate devices, has emerged from stealth with a $20m seed round.

The round was led by Glilot Capital Partners and Ten Eleven Ventures, with participation from Okta Ventures and Runtime Ventures. Angel investors who founded Dig Security, Demisto, Snyk and Talon also backed the raise. The company said its platform is already live at dozens of large enterprises in the US and Europe.

The funding targets a shift in how employees work. AI assistants, browser extensions, MCP servers and code packages are woven into daily workflows, and browsers, IDEs and AI agents now come with their own marketplaces where fresh software can be bolted on. The result is a software layer on corporate devices that grows faster than security teams can catalogue or evaluate.

Bloom argues the danger extends beyond malware; legitimate, popular tools can become hazardous when they carry excessive permissions, are misconfigured or touch sensitive data in unforeseen ways. Examples cited by the firm include badly configured AI agents, over-permissioned plugins, screen recorders and code libraries drawing from untrusted sources, a class of exposure that sits outside the remit of conventional EDR products.

Bloom Security's platform builds a complete inventory of tools, extensions and code running across an organisation's endpoints, and analyses how each component interacts with data and systems, alongside supply-chain risks, configurations and permissions.

Its central thesis is that risk is contextual rather than absolute, since an application safe on one device may be dangerous on another depending on the user's role and access. Beyond monitoring, security teams can block risky installations before they land on devices, enforce secure configurations and remediate issues without manual approval workflows.

The founding team draws on backgrounds at Palo Alto Networks, Dig Security, Demisto and XM Cyber, and the 30-person company includes many former Dig Security colleagues.

Bloom Security co-founder and CEO Itay Keren said, 'In the AI era, the employee device is no longer just a managed endpoint. Every endpoint is now running software no one reviewed, connecting to services no one provisioned.'

He added, 'As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality. Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.'

Bloom Security co-founder and chief product officer Ofir Balassiano said, 'The same tool can be completely acceptable on one endpoint and high-risk on another. Risk depends on context: the user's role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.'

Bloom Security co-founder and CTO Itay Frishman said, 'While this is technically our first company as founders, our team has built and integrated category-defining products before. We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.'