Glow exited stealth on Wednesday with $180 million in Series A funding and a $1.2 billion valuation. The startup is building an endpoint security platform purpose-built for a world where AI agents, not humans, are the primary actors on enterprise devices. The question every cybersecurity founder and CISO should ask: is this a new category or a feature that CrowdStrike and SentinelOne will absorb?
Here are the three key differences that separate Glow from the incumbents.
Background
Founded in 2025 by former Meta VP of engineering Roi Tiger and ex-Snowflake security head Omer Singer, Glow raised from Sequoia Capital, Cyberstarts, Greenoaks Capital, and Redpoint Ventures. The company already has paying customers in healthcare, retail, and financial services. It employs roughly 100 people, 70 percent of them in Israel.
The pitch is simple: CrowdStrike and SentinelOne were built for a world where humans use laptops. That world is ending. AI coding agents, automated developer tools, and browser-based AI assistants now run directly on endpoints. They install packages, modify files, connect to APIs, and make network calls without human supervision. Traditional endpoint detection and response tools lack visibility into this behavior.
Glow claims its platform has already prevented malicious npm packages from being installed, identified AI agents running code that attempts to exfiltrate data, and blocked tools from connecting to unauthorized cloud services. It uses Anthropic and Google Gemini models through Amazon Bedrock, augmented with proprietary context software that improves detection accuracy in enterprise environments.
Key Insights
The core architectural difference between Glow and the incumbents comes down to what each platform was designed to monitor.
| Capability | Glow | CrowdStrike Falcon | SentinelOne Singularity |
|---|---|---|---|
| Primary monitor | AI agent behavior | Human behavior | Human behavior + file integrity |
| Agent detection | Native (designed for it) | Partial (agent as process) | Partial (agent as process) |
| Package install monitoring | npm, pip, gem | Limited | Limited |
| AI model stack | Anthropic + Gemini + proprietary | Proprietary ML + threat intel | Proprietary ML + Purple AI |
| Deployment | Agent on device | Agent on device + cloud | Agent on device + cloud |
| Valuation | $1.2B (pre-revenue disclosed) | $65B (public) | $10B (public) |
Glow's bet is that agentic behavior cannot be modeled by signature-based or human-behavior baselines. An AI coding agent installing a package looks nothing suspicious to CrowdStrike because there is no anomalous user behavior alerting the analyst. But to Glow, which was built to understand agent intent, that same install is a signal.
This is a bet on a category shift. The last time endpoint security saw a genuine category change was the move from signature-based AV to behavioral EDR around 2014. CrowdStrike and SentinelOne won that transition. Glow is betting the next transition is agent-native security.
What This Means for Founders
If your startup runs AI coding agents on developer machines or uses browser-based AI assistants that access production data, you have a blind spot that traditional EDR does not cover. CrowdStrike and SentinelOne can tell you if a human actor does something abnormal. They cannot tell you if an AI agent installs a malicious npm package or exfiltrates API keys through a tool like Claude Code or Cursor.
- Micro-evals are the gap. The problem with AI agents on endpoints is not that they are loud. It is that they look exactly like a developer using a new tool. Glow's approach of modeling agent behavior specifically addresses this.
- Incumbents will respond. CrowdStrike's Charlotte AI and SentinelOne's Purple AI are both evolving, but neither was designed to monitor AI agents. They were designed to help human analysts do their jobs faster. Glow's agent-first architecture gives it a 12 to 18 month lead.
- Watch the pricing. Glow has not disclosed pricing yet. CrowdStrike Falcon runs about $100 to $200 per seat per year for core EDR. If Glow prices at a premium, it will need to show ROI in prevented agent attacks. That is a hard metric to prove before the attacks become common.
The bottom line: Glow is not a replacement for CrowdStrike or SentinelOne today. It is a complement for teams that use AI agents in production. If you run agents on endpoints, trial Glow alongside your existing EDR. If you do not use agents yet, wait and watch. The category will clarify within 12 months.
Disclosure
Some of the links in this article are affiliate links. If you sign up through these links, we may earn a small commission at no extra cost to you. This helps us keep The Break Daily free for everyone.

