Tool review · Checked against vendor sites, September 2026
Bloom Security review (2026): inventory for the AI-native endpoint
The verdict
Bloom Security is the pick when the first job is knowing everything running on your endpoints, including AI tools, extensions and packages, and blocking risky ones from npm, the Chrome Web Store and Open VSX. It ties for top visibility, but its public pages do not yet describe deployment, tool-call decisions or agent attribution.
What does Bloom Security do?
- Discovers software, extensions, AI and everything running on endpoints, including who built it, what it can access and where it came from; monitors changes fleet-wide.
- Identifies risk using marketplace intelligence, static analysis and behavioral sandboxing.
- Defines what AI agents can access, execute and transmit, and scales back overpermissioned MCP servers and configurations.
- Removes risky tools, revokes permissions and fixes misconfigurations; blocks malicious, vulnerable or policy-violating packages and skills across npm, Chrome Web Store, Open VSX and others.
- Founders previously worked at Palo Alto Networks and Dig Security. Offices in Wilmington, Delaware and Tel Aviv. SOC 2 listed.
Source: bloom.security · Bloom about · Reviewed Sep 2026
How does Bloom Security deploy?
Not published on the pages we reviewed.
Source: bloom.security · Bloom about · Reviewed Sep 2026
How does Bloom Security score?
Discovers software, extensions, AI tools and everything running on the endpoint, with who built it and what it can access.
Defines what AI agents can access, execute and transmit and scales back overpermissioned MCP servers; runtime tool-call decisions not detailed.
Blocks malicious or policy-violating packages and skills across npm, Chrome Web Store and Open VSX.
Not described on the pages we reviewed.
Deployment method not published.
Endpoint focused, including non-AI software.
Limited public company information; SOC 2 listed; investors and pricing not published.
Where is Bloom Security strongest?
- Broad endpoint inventory that includes non-AI software and extensions (9 out of 10, tied highest).
- Supply-chain controls for packages and extensions.
What should buyers check before choosing Bloom Security?
- Deployment method, tool-call enforcement and audit detail are not published.
- Investors and pricing are not published.
Who should shortlist Bloom Security?
Shortlist Bloom Security if you want one inventory of every extension, package and AI tool on developer machines before you set agent policy.
What does Bloom Security cost?
Contact sales. Pricing is not published.
Frequently asked questions
Does Bloom Security cover MCP servers?
Bloom says it automatically scales back overpermissioned MCP servers and configurations.
Related
- Shadow AI
- Buyer's checklist
- Alternatives to Bloom Security
- Compare Bloom Security with the top-ranked tools
Head to head
Sources
- bloom.security · Reviewed Sep 2026
- Bloom about · Reviewed Sep 2026