Bloom Security Raises $20 Million to Protect Endpoints with the 'Onion Method'

Israeli startup Bloom Security has exited stealth mode with a $20 million seed round led by Gallei Capital. The company offers a new approach to endpoint security, using a tiered 'onion method' to analyze risks posed by AI agents and browser extensions.

Source
Bloom Security Raises $20 Million to Protect Endpoints with the 'Onion Method'
Photo: Geektime / עובדי Bloom ואנדפוינט, השיבה-אינו המשרדי. תמונה: פיני סילוק

Bloom and Andpointe employees. Photo: Pini Silok

The explosion of AI tools has brought a significant headache for information security teams. Employee computers are no longer just simple endpoints; they are complex environments running agents, browser add-ons, and open-source code libraries. The core issue is that these tools are connected directly to sensitive organizational data, often operating without any oversight from IT or security teams.

To address this, the Israeli startup Bloom Security exited stealth mode today (Thursday) and announced a $20 million seed round led by the Gallei Capital fund.

The Onion Method

"Our starting point is the opposite of classic EDR: we don't run the entire 'brain' on the endpoint," explains Itai Keren, co-founder of Bloom, in a conversation with Geektime. "A sensor sits on the computer to observe activity, while the heavy, in-depth analysis happens in our systems. This significantly reduces the overhead associated with traditional EDR."

According to Keren, the difference lies in how agents operate. "We don't scan the entire endpoint repeatedly—that's what chokes the machine. We work in layers, which we call the 'onion method.' The first scan is light and broad, providing a big picture. Only when something seems suspicious and requires a deep dive do we activate an additional, focused pipeline for that specific path." Keren notes that this tiered scanning ensures employees experience no performance lag, preventing them from bypassing the security measures.

Toxic Combinations

Instead of just looking for malicious files, the system identifies "Toxic Combinations." "Take the same AI agent," Keren demonstrates. "On a marketing laptop, it helps draft emails—that's fine. The exact same agent on a developer’s computer sits next to company code, passwords, and production permissions. It’s the same software and the same permissions, but two completely different worlds of risk. Our relationship graph allows us to see the context: what the tool can touch and what it does in practice." This contextual analysis significantly reduces false positives.

Keren cites a real-world incident at a Fortune 500 company where a development manager downloaded an AI agent from an open repository. It looked harmless, but it contained a hidden prompt that altered telemetry settings and opened an outbound network connection to exfiltrate sensitive data.

Why not the giants?

When asked why companies like CrowdStrike, Palo Alto, or Microsoft haven't added this to their products, Keren explains: "It's not a feature; it's an infrastructure. EDR is built to monitor the OS layer and processes—memory, network, and process behavior. The layer we operate in—marketplaces, extensions, IDE plugins, MCP servers, AI add-ons—is simply not in their field of view. This requires a different data model and a different place in the stack. Our approach coordinates context across identity, data, secrets, and the entire software graph—something EDR wasn't built to do."

Bloom was founded in 2025 by Itai Keren, Ofir Blesiano, and Itai Frishman, veterans of IDF technology units and former employees of cyber companies Dig Security and Demisto, both acquired by Palo Alto Networks.

Related News