| TL;DR: Enterprise endpoint security was built to catch threats it can recognize. But AI changed the game. Employees now install AI agents and developer tools that look like normal software but can quietly pull in malicious packages. Glow raised $180 million to fix this problem. Its platform maps what is running across enterprise devices and decides whether it belongs there before anything goes wrong. |
Modern endpoint security combines prevention with detection and response. Vendors such as CrowdStrike, SentinelOne, Microsoft, and Palo Alto Networks already offer preventive controls alongside detection capabilities.
Roi Tiger, co-founder and CEO of Glow, argues those tools were not built for what AI has placed on the endpoint. Glow frames the problem as continuous governance: knowing what software, AI agents, and developer tools are on employee devices.
The question is whether those things should be there at all. That argument sits behind Glow’s $180 million all-equity Series A, which valued the Palo Alto-based startup at $1.2 billion.
The Problem the Existing Stack Was Not Designed to Solve
For much of the endpoint-security era, products were built around malicious code and external attackers seeking access. Threats like malware, ransomware, and phishing remain real and have not gone away. AI has added a different and newer challenge on top of them.
Generative AI tools, autonomous agents, and developer software are now installed directly on employee devices. This happens with IT’s knowledge sometimes, and without it other times. These tools may behave like ordinary workplace software. That makes it difficult for malicious signatures to reveal whether they belong there.
Existing endpoint tools can block applications and enforce policies. However, the reality is these controls are fragmented. They do not provide a single continuously updated view of everything running across the endpoint.
That is the gap Glow is building to close.
What Is Already Happening in Customer Environments
Tiger put the shift plainly

Source – TechCrunch
According to Glow, that shift is already producing problems in customer environments. Its platform has prevented malicious npm packages from being installed across those environments.
Npm packages are third-party software components used to build applications. The company has also identified AI agents attempting to pull in those same malicious packages. It has detected devices where endpoint detection and response tools were missing or operating with reduced functionality. This shows how endpoint controls can quietly become inconsistent across large organizations.
Tiger is direct about how Glow differs from existing tools. He says existing EDR products focus primarily on detecting threats after they emerge. That’s why the company is designed to prevent risky software, AI agents, and developer tools from entering enterprise environments first. The platform uses specialized AI agents to continuously map enterprise environments, assess risk in real time, and enforce security policies.
A New Layer That Existing Tools Were Not Built Around
Enterprises already use endpoint tools to prevent, detect, and respond to threats. However, security teams need to understand which agents, developer tools, and software packages are running across employee devices. They need to know how those things are being used and whether they should be there. Those controls may currently live across different security and IT tools with no consolidated view.
Glow is betting enterprises need one view that connects software inventory, AI usage, and organizational policy. Endpoints were already difficult to govern before generative AI arrived. Shadow IT, developer packages, and unsanctioned SaaS tools existed long before AI agents did. The technology now enters enterprises faster than security teams can review it. AI agents have made that speed and volume problem significantly worse.
What Glow Is Actually Building
The company does not position the product as an EDR with an additional AI feature. It presents it as a separate control layer for endpoint software and AI governance. The platform continuously maps software, AI agents, and developer tools running across enterprise devices. Policies are enforced against that inventory in real time. This approach helps identify and block risky software and AI agents before they enter the environment.
Moreover, the platform uses AI models from Anthropic and Google’s Gemini through Amazon Bedrock. The company also builds its own software layer on top to give those models enterprise-specific context. That layer is designed to improve reliability for security tasks. The question the platform answers is not “what attacked us” but “what is on our devices and should it be there.”
Recommended Read: Prime Intellect Raised $130M to End Enterprise Dependence on OpenAI and Anthropic. Anthropic’s Temporary Fable Suspension Shows Why That Matters.
What Security Buyers Are Now Being Asked to Decide
For chief information security officer and security leaders, Glow raises a practical question. Their existing stack is designed to prevent known threats and catch suspicious activity. Glow is asking whether those tools also continuously govern what software and agents are permitted to run. The real question is whether that governance happens before something becomes an incident.
The uncomfortable reality for most security teams is that they had security stacks in place. However, they just had no visibility into the layer where these problems were quietly developing.
Glow is making a direct bet that watching it is now non-negotiable. Whether security buyers move before an incident forces the decision or after is, at this point, the only question that matters.