$180M Backs Glow's Server-Side Endpoint Defense for AI Agents
Cybersecurity startup Glow has emerged from stealth with $180 million in funding to shift enterprise endpoint defense to a server-side prevention model.
Cybersecurity startup Glow emerged from stealth with $180 million in total funding and a $1.2 billion valuation, targeting AI-native endpoint defense. The platform addresses the rapid adoption of autonomous AI tools inside enterprises, shifting security from localized execution to a server-side prevention model.
Corporate AI tool usage on employee devices has jumped from 15% to 45% over the past year, according to Glow’s internal research. This rapid adoption creates a $40 billion addressable market for modern defense platforms capable of parsing complex vulnerabilities, including Mythos-class threats originating from advanced language models.
Server-Side Prevention Architecture
Glow bypasses the reactive localized execution of traditional Endpoint Detection and Response (EDR) tools. The system relies on server-side monitoring agents that reduce local performance drag and minimize false positive rates. By shifting compute off the local hardware, the platform continually maps an organization’s computing environment and analyzes risks in real-time.
A dedicated reasoning engine sits at the core of the defense strategy. It proactively authorizes or removes software and scripts prior to execution. This engine specifically monitors for the execution of unauthorized AI agents and the pulling of unverified code packages by automated developer tools.
The prevention engine deploys its own autonomous agents to enforce granular execution policies. This oversight provides critical visibility when employees grant external AI agents permission to modify local files, invoke developer pipelines, or manage data via APIs directly on their laptops.
Shifting the EDR Paradigm
The rise of AI-driven multi-step cyberattacks has fundamentally changed the requirements for endpoint defense. Legacy security tools from providers like CrowdStrike and Microsoft were not originally designed to oversee autonomous software acting independently on behalf of employees.
| Feature | Traditional EDR | Glow Architecture |
|---|---|---|
| Execution Model | Local device | Server-side compute |
| Security Stance | Reactive (“known-bad”) | Prevention-first reasoning |
| AI Oversight | Limited telemetry | Continuous mapping and policy enforcement |
Enterprise customers in the financial services, healthcare, and retail sectors have already deployed the platform. These industries face strict regulatory compliance requirements regarding data provenance and access control, which are complicated by the integration of opaque AI tools.
Capital and Leadership
The $180 million total capital comes from three consecutive rounds raised over approximately 12 months. The final $100 million Series B was led by Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures. The prior $60 million Series A valued the company at $400 million.
The executive team draws heavily from large-scale enterprise engineering and cybersecurity. CEO Roi Tiger formerly served as VP of Engineering at Meta. CTO Omer Singer headed cybersecurity strategy at Snowflake. Additional founders include VP of R&D Ophir Arie from Claroty, COO Emily Heath from United Airlines, and CPO Arnon Joseph from Meta. Glow currently employs roughly 100 people, with 65 based in Israel.
If you manage enterprise security boundaries, the proliferation of local AI tooling requires new visibility mechanisms. Relying on signature-based local EDR to catch anomalous agent behavior will increasingly miss unauthorized API orchestration. Shifting to server-side telemetry aggregation provides the necessary context to evaluate AI agents and scripts securely before execution.
Get Insanely Good at AI
The book for developers who want to understand how AI actually works. LLMs, prompt engineering, RAG, AI agents, and production systems.
Keep Reading
How to Use Symbolic Execution for Automated BPF Analysis
Learn how Cloudflare uses the Z3 theorem prover to instantly generate magic packets and reverse-engineer BPF bytecode for security research.
JadePuffer Ransomware Deploys Autonomous Llama 4 Cyberattack
The JadePuffer ransomware attack marks the first confirmed use of an autonomous LLM agent executing an end-to-end cyberattack without human intervention.
Microsoft Reimagines OpenClaw for a Secure Microsoft 365 Copilot
Microsoft is developing a high-security, always-on AI agent for Microsoft 365 Copilot that aims to fix the vulnerabilities of the popular OpenClaw framework.
OpenClaw Users Warned to Assume Compromise After Major Breach
The popular OpenClaw AI agent framework faces a security crisis as researchers uncover critical RCE vulnerabilities and thousands of exposed instances.
NVIDIA Unveils NemoClaw at GTC as a Security-Focused Enterprise AI Agent Platform
NVIDIA introduced NemoClaw, an alpha open-source enterprise agent platform built to add security and privacy controls to OpenClaw workflows.