Best AI Security markBest AI Security

Tool review · Checked against vendor sites, September 2026

Bloom Security review (2026): inventory for the AI-native endpoint

The verdict

Bloom Security is the pick when the first job is knowing everything running on your endpoints, including AI tools, extensions and packages, and blocking risky ones from npm, the Chrome Web Store and Open VSX. It ties for top visibility, but its public pages do not yet describe deployment, tool-call decisions or agent attribution.

Rank 9 of 9

Best for endpoint software and extension inventory

Visit Bloom Security

What does Bloom Security do?

  • Discovers software, extensions, AI and everything running on endpoints, including who built it, what it can access and where it came from; monitors changes fleet-wide.
  • Identifies risk using marketplace intelligence, static analysis and behavioral sandboxing.
  • Defines what AI agents can access, execute and transmit, and scales back overpermissioned MCP servers and configurations.
  • Removes risky tools, revokes permissions and fixes misconfigurations; blocks malicious, vulnerable or policy-violating packages and skills across npm, Chrome Web Store, Open VSX and others.
  • Founders previously worked at Palo Alto Networks and Dig Security. Offices in Wilmington, Delaware and Tel Aviv. SOC 2 listed.

Source: bloom.security · Bloom about · Reviewed Sep 2026

How does Bloom Security deploy?

Not published on the pages we reviewed.

Source: bloom.security · Bloom about · Reviewed Sep 2026

How does Bloom Security score?

HIGHEST IN GUIDE
Endpoint and agent visibilityWeight 22%9/10

Discovers software, extensions, AI tools and everything running on the endpoint, with who built it and what it can access.

LOWEST IN GUIDE
MCP and tool-call controlWeight 20%6/10

Defines what AI agents can access, execute and transmit and scales back overpermissioned MCP servers; runtime tool-call decisions not detailed.

LOWEST IN GUIDE
Policy granularityWeight 15%7/10

Blocks malicious or policy-violating packages and skills across npm, Chrome Web Store and Open VSX.

LOWEST IN GUIDE
Agent vs human identity and auditWeight 12%4/10

Not described on the pages we reviewed.

LOWEST IN GUIDE
Deployment footprintWeight 13%4/10

Deployment method not published.

Coverage beyond the endpointWeight 8%5/10

Endpoint focused, including non-AI software.

Maturity and transparencyWeight 10%4/10

Limited public company information; SOC 2 listed; investors and pricing not published.

Total

How we score

Where is Bloom Security strongest?

  • Broad endpoint inventory that includes non-AI software and extensions (9 out of 10, tied highest).
  • Supply-chain controls for packages and extensions.

What should buyers check before choosing Bloom Security?

  • Deployment method, tool-call enforcement and audit detail are not published.
  • Investors and pricing are not published.

Who should shortlist Bloom Security?

Shortlist Bloom Security if you want one inventory of every extension, package and AI tool on developer machines before you set agent policy.

What does Bloom Security cost?

Contact sales. Pricing is not published.

Frequently asked questions

Does Bloom Security cover MCP servers?

Bloom says it automatically scales back overpermissioned MCP servers and configurations.

Related

Head to head

Sources