Why We Invested In Bloom

Author: Kobi Samboursky, Co-Founder & Managing Partner, Glilot Capital

Date: 30/07/2026

Knowledge-Hub

The modern enterprise endpoint has become a security vacuum. And most organizations are only beginning to realize it.

For the past two years, I kept having the same conversation with CISOs across our portfolio and beyond. Their teams had deployed best-in-class EDRs. They felt covered. But when you asked about the AI coding assistant running with full filesystem access on every developer machine, or the MCP servers quietly connecting internal workflows to external APIs, the confidence faded. These tools weren’t being ignored. They were simply beyond what existing security infrastructure was built to govern.

Coding assistants, browser extensions, IDE plugins, MCP servers, the tools that define how people work today, operate outside the reach of existing security infrastructure. They accumulate permissions gradually, connect to external services, and execute with a level of autonomy that no one designed the security stack to control. The result isn’t a gap in visibility. It’s an uncontrolled attack surface that’s actively being exploited.

That disconnect was impossible to ignore as an investor.

When I first met Itay Keren, Ofir Balassiano, and Itay Frishman, what struck me was how precisely they had mapped this, and how clearly they understood that seeing the problem wasn’t enough. Bloom doesn’t just inventory what’s on the endpoint. It analyzes risk in context, enforces policy, remediates misconfigurations, and blocks malicious software before it ever reaches the machine. Most tools aren’t malicious, they’re risky in the wrong context. The same tool carries different risk depending on who’s running it, what data they can reach, and what else is installed alongside it. Bloom governs all of it, and does it without slowing anyone down.

The team’s background made this conviction credible. Itay Keren, Ofir Balassiano, and Itay Frishman were part of the core team at Dig Security, built it from the ground up, and saw it acquired by Palo Alto Networks. For Itay Keren, it was his second acquisition, having gone through the same at Demisto. They had already done this once, building enterprise security from the ground up. They knew exactly what they were going back to build. They didn’t come together around a pitch. They came together around a problem they had all watched go unsolved from the inside. Their in-house research speaks for itself: architectural vulnerabilities discovered across major AI coding IDEs, supply chain flaws that could have affected hundreds of thousands of endpoints, all caught and remediated for Bloom customers before public disclosure.

Bloom is already deployed across large enterprises, securing tens of thousands of endpoints. The market timing is right.

We’re proud to lead Bloom Security’s $20M seed round with participation of 1011 Ventures, Okta Ventures, Runtime Ventures, Aurora Capital, and a group of angels who built Demisto, Dig Security, Snyk, and Talon. This is exactly the kind of company Glilot was built to back: one that identifies a structural security problem clearly, has the team to solve it, and is already doing the work.

Scroll to Top
Contact Info

Fill out the form below, and we will be in touch shortly.

Contact Information
I am:
Company Stage:
Company Sector: