TL;DRBloom Security has raised $20M in seed funding led by Glilot Capital and Ten Eleven Ventures to secure the AI-era endpoint. The company argues that EDR was built for malware, not for the AI agents, MCP servers, browser extensions, and code packages now running on every employee device. Its platform provides contextual visibility across all endpoint software and enforces risk-based policies without blanket lockdowns. Already deployed at dozens of large US and European enterprises.
Work does not look like it did three years ago. Employees now assemble their own toolkits daily: AI agents that act on their behalf, browser extensions that reshape how they read and write, code packages pulled from public registries, MCP servers connecting one tool to another. AI tools are no longer optional. They are how modern work gets done. The device on every desk has quietly become an ecosystem, and almost none of the security stack guarding it was built with that in mind.
Into this gap steps Bloom Security, which launched from stealth today with a $20 million seed round, first reported by Axios, led by Glilot Capital Partners and Ten Eleven Ventures (1011vc), with participation from Okta Ventures and Runtime Ventures, plus angel backing from founders of Dig Security, Demisto, Snyk, and Talon.










