Every AI tool a developer installs is software no one approved. Glow is the first security platform built for that threat model.
ENTRY ANGLES
AI agent compliance registry as standalone SaaS · CI/CD dependency validation for AI-generated code
VERTICALS
CAPABILITIES
Security architecture, Compliance tooling, CI/CD integrations, SIEM/CMDB integrations
An employee installs a VS Code extension. It runs a background process, reads their codebase, and sends data to a server their IT team never reviewed. Eleven days later a vendor alert surfaces it. This isn't an edge case — it's the routine exposure pattern that followed AI coding tools becoming standard issue, as developers started running constellations of plugins, agents, and tooling that nobody formally approved.
Roi Tiger spent nine years at Meta, most recently overseeing Onavo — the VPN that gave Facebook visibility into every application on users' devices. He understood from the inside what continuous endpoint access reveals. Glow uses that architectural logic defensively: three AI agents mapping everything on a device, assessing risk continuously, and blocking unapproved software before installation rather than detecting it afterward. The company emerged from stealth in July 2026 with $180 million at a $1.2 billion day-one valuation backed by Sequoia, Cyberstarts, Greenoaks, and Redpoint. Glow has already blocked malicious npm packages from customer environments and intercepted AI agents attempting to install unauthorized tooling. Healthcare, retail, and financial services were paying before the public launch.
Glow isn't entering the $20 billion endpoint detection market. It's defining a governance category that didn't need to exist until AI agents became standard equipment. A developer laptop in 2026 runs not just an approved software stack but a changing constellation of AI coding assistants, browser extensions, MCP servers, and autonomous agents — software that arrives and updates daily, installed by employees doing their jobs normally.
CrowdStrike and SentinelOne were built to detect behavioral anomalies. An employee installing a VS Code extension isn't anomalous. It looks identical to installing a legitimate development tool, because it is one — a development tool that also exfiltrates code. The architecture for detecting unusual behavior has no response to harmful behavior that looks usual.
The fastest entry is building the AI agent registry as a standalone compliance product. Regulated industries need a real-time inventory of which AI agents are running, what external services they connect to, and who authorized each one — for audit purposes, before the security enforcement question becomes relevant. "Which AI agents accessed patient data between January and March" is a compliance question organizations need to answer now; "were they malicious" comes later. Building the registry with integrations into existing SIEM and CMDB tools reaches a paying market Glow doesn't yet serve as a separate product.
The supply chain entry is more targeted: a CI/CD integration that validates AI-suggested code dependencies against known-malicious package registries before they reach a device. Glow monitors the endpoint; nothing currently monitors the AI generation step where the compromised package recommendation first appears.