In a landscape where artificial intelligence is fundamentally rewriting the rules of digital warfare, a new player has emerged to claim the spotlight. Glow, a Palo Alto-based cybersecurity startup, officially exited stealth mode this week with a staggering $180 million Series A funding round. The investment values the company at $1.2 billion, granting it immediate unicorn status—a rare feat for a firm that has yet to publicly disclose its revenue metrics.
Founded in 2025 by a powerhouse team of former executives from Meta, Snowflake, and Claroty, Glow is positioning itself as the guardian of the modern enterprise endpoint. As AI agents and generative tools proliferate across corporate networks, Glow’s leadership argues that traditional security models are becoming obsolete, necessitating a shift from reactive detection to proactive, environment-aware prevention.
The Main Facts: A Billion-Dollar Bet on Proactive Security
The $180 million funding round was led by a consortium of elite venture capital firms, including Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures. Participation also included heavyweights such as Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures.
Glow’s core mission is to solve a problem that many CISOs are only just beginning to articulate: the "endpoint sprawl" caused by AI. As employees increasingly leverage local AI models, autonomous agents, and complex developer tools on their laptops and servers, the attack surface of the average enterprise has expanded exponentially. Glow’s platform aims to monitor, control, and secure these disparate assets through a combination of continuous environmental mapping and real-time policy enforcement.
Unlike legacy endpoint detection and response (EDR) tools—which are designed to identify threats after they have already manifested—Glow operates on a prevention-first philosophy. By utilizing specialized AI agents, the platform creates a "context-aware" barrier, ensuring that only verified, secure software and AI agents can execute within the corporate perimeter.
A Chronology of the Rise: From Meta and Snowflake to Palo Alto
The genesis of Glow is rooted in the collective experience of its founders, who witnessed the rapid shift toward cloud and SaaS infrastructures over the past decade.
- 2025 (Founding): Glow is established by Roi Tiger (CEO), Omer Singer, Ophir Arie, and Arnon Joseph. The team brings a unique blend of expertise from Meta’s engineering leadership, Snowflake’s cybersecurity strategy, and Claroty’s research and development division.
- Early 2026 (The Catalyst): The industry experiences a seismic shift as high-profile AI models, such as Anthropic’s Mythos, demonstrate advanced capabilities in identifying and exploiting software vulnerabilities. This event serves as a wake-up call for the cybersecurity sector, validating Glow’s thesis that AI-assisted attacks require an AI-native defense.
- Mid-2026 (Stealth Execution): Despite remaining in stealth, the startup successfully deploys its platform across major global organizations in the healthcare, retail, and financial sectors.
- Late 2026 (Public Launch): Glow emerges from stealth with $180 million in capital, establishing its headquarters in Palo Alto and confirming a workforce of nearly 100 employees, with a significant presence in Israel.
Supporting Data: Why the Market is Pivoting
The demand for a new category of endpoint security is driven by quantifiable shifts in the threat landscape. According to industry data, enterprises are seeing an unprecedented increase in AI-driven phishing, automated malware generation, and "shadow AI"—the unauthorized use of AI tools by employees that bypasses corporate security protocols.
Glow’s operational data, while limited, provides a glimpse into the necessity of its platform. Tiger notes that the platform has already successfully:
- Blocked malicious npm packages: By analyzing third-party software components before they are installed, Glow has prevented potential supply chain attacks.
- Identified Rogue AI Agents: The platform has successfully flagged internal AI agents attempting to pull in unauthorized or high-risk software components.
- Audited Security Posture: Glow has uncovered instances where traditional endpoint detection tools were missing or had been inadvertently disabled, closing critical visibility gaps.
The platform utilizes a "hybrid" AI approach. It leverages foundation models from Anthropic and Google’s Gemini (delivered via Amazon Bedrock) while layering on proprietary, custom-built software. This proprietary layer provides the "enterprise context" necessary to ensure that AI decisions are reliable, compliant with internal policies, and free from the hallucinations that plague generic large language models.
Official Responses: The Philosophy of Prevention
The leadership at Glow is vocal about why the current endpoint market—dominated by titans like CrowdStrike, Microsoft, SentinelOne, and Palo Alto Networks—is not enough to stop the next generation of threats.
"If you think of the past decade, everything was moving to the cloud and SaaS," CEO Roi Tiger explained in a recent interview. "Suddenly, AI lands on the endpoint in a way we’ve never seen. The tools we used for the cloud are simply not sufficient for the unique, decentralized nature of local AI agents running on employee machines."
Emily Heath, the startup’s Chief Operating Officer, adds a layer of CISO-level credibility to the mission. Having served at United Airlines and DocuSign, and having sat on the board of Wiz, Heath is intimately familiar with the scaling challenges of enterprise security. Her involvement signals to the market that Glow is not just an experimental R&D project, but a platform built to integrate into the complex, high-stakes environments of global Fortune 500 companies.
Implications: A New Category or a Passing Trend?
The emergence of Glow raises a critical question for the cybersecurity industry: Is "AI-native endpoint security" a distinct market category, or is it a feature that incumbents will eventually absorb?
The Case for a New Category
Proponents argue that traditional EDR is "signature-based" or "behavior-based" at a level that doesn’t understand the intent of an AI agent. Because AI agents can dynamically change their behavior, a security tool must be able to understand the context of the code the agent is writing or the data it is accessing. Glow’s ability to map the "intent" of developer tools and AI agents represents a fundamentally different approach to security.
The Challenge of Incumbents
The cybersecurity market is notoriously difficult to disrupt. With Microsoft and CrowdStrike deeply embedded in the enterprise stack, Glow must prove that its "preventative" approach offers a significantly lower Total Cost of Ownership (TCO) or a drastically higher security efficacy than the incumbent solutions.
Furthermore, as enterprises continue to struggle with "vendor fatigue," they may be hesitant to add yet another agent to their employee devices. Glow’s success will likely depend on its ability to demonstrate that it can play nicely with existing security stacks while providing a unique, high-value layer of intelligence that current tools miss.
The Broader Security Outlook
The rise of tools like Anthropic’s Mythos has fundamentally changed the risk-benefit analysis of AI deployment. Companies are now forced to choose between the productivity gains of AI and the catastrophic potential of AI-assisted exploits. Glow’s funding suggests that investors believe the future of enterprise security lies in "guardrailing" this innovation—allowing employees to use AI, but doing so within a sandbox that is continuously monitored and secured by an equally intelligent system.
As Glow scales its operations from 100 employees to a broader global footprint, the eyes of the cybersecurity world will be fixed on whether this unicorn can translate its $1.2 billion valuation into long-term market dominance. Whether or not it becomes the standard for the next decade of endpoint security, Glow has already succeeded in doing one thing: it has forced the entire industry to confront the reality that when it comes to AI, the perimeter is no longer at the firewall—it’s on the endpoint.
