Back
TechCrunch AILaunchTechCrunch AI2026-07-22

Glow Exits Stealth at $1.2B to Secure AI Agents on Enterprise Endpoints

Glow has emerged from stealth with a $1.2B valuation targeting a new class of endpoint security risks created by AI agents, copilots, and developer tools operating inside enterprise environments. The company argues that traditional endpoint detection tools weren't built for the threat surface that autonomous AI tooling creates.

Original source

Glow launched publicly today after an undisclosed stealth period, announcing a $1.2 billion valuation backed by unnamed investors. The company's pitch centers on a specific and increasingly visible enterprise problem: the rapid deployment of AI agents, coding assistants, and autonomous tooling inside corporate networks has created endpoint risks that legacy EDR and XDR platforms weren't designed to handle. Traditional endpoint security models assume humans are the primary actors on managed devices; Glow argues that AI agents operating with delegated credentials and broad filesystem or network access require a fundamentally different detection and policy model.

The threat class Glow is targeting is concrete. AI coding agents can read, write, and exfiltrate code repositories. Autonomous workflow tools can invoke APIs with stored credentials. MCP servers and locally-run model runtimes create new process trees and network connections that existing behavioral detection baselines don't account for. Glow claims its platform profiles AI agent behavior at the process and syscall level, builds baselines for normal agentic activity, and surfaces anomalies that would be invisible to tools trained on human-initiated actions.

The company has not yet disclosed pricing, published technical documentation, or named design partners publicly. What's available is a product walkthrough video, a waitlist, and a founding team with backgrounds in endpoint security and ML infrastructure. The $1.2B valuation at launch — before public revenue disclosures — reflects investor conviction that AI-native endpoint risk is a durable and growing category, not a momentary gap that incumbent vendors will close quickly.

Glow enters a market where CrowdStrike, SentinelOne, and Microsoft Defender already have significant enterprise distribution and are actively adding AI-related detection capabilities. The company's differentiation claim is specificity: purpose-built for agentic workloads rather than AI features bolted onto a human-behavior detection engine. Whether that specificity is a durable wedge or a feature gap that incumbents close in 18 months is the central question for Glow's trajectory.

Panel Takes

The Skeptic

The Skeptic

Reality Check

The threat is real — AI agents with delegated credentials and broad filesystem access are a genuine detection gap that CrowdStrike and SentinelOne are not fully covering yet. But a $1.2B valuation with no public customers, no published detection methodology, and no pricing page isn't a security company, it's a pitch deck with a waitlist. What kills this in 18 months: CrowdStrike ships an 'AI agent behavioral baseline' module, prices it into existing enterprise contracts, and Glow's differentiation evaporates before they've closed enough logos to matter.

The Founder

The Founder

Business & Market

The buyer here is the CISO, and the budget comes from endpoint security or cloud security tooling — both well-established line items with real purchase authority. That's a legitimate wedge. The problem is distribution: CrowdStrike and SentinelOne already own the endpoint agent on every managed device in the enterprise, which means Glow either needs to run alongside them (a hard sell) or displace them (a very hard sell). The moat only exists if agentic workload detection requires a fundamentally different data model than existing EDR telemetry — and that's a technical claim Glow hasn't substantiated publicly yet.

The Futurist

The Futurist

Big Picture

Glow's core thesis is falsifiable and worth taking seriously: within three years, AI agents will be primary actors on enterprise endpoints, and the behavioral baselines that underpin modern EDR — built entirely on human-initiated process trees — will be structurally blind to the most dangerous threat vectors. If that's true, the category Glow is creating isn't a niche, it's the next generation of endpoint security. The dependency that has to hold: enterprise AI agent adoption continues accelerating faster than incumbent vendors can retrain their detection models on agentic telemetry. The second-order effect if Glow wins is significant — they'd sit on the most comprehensive dataset of AI agent behavior inside production enterprises, which is a data asset with value well beyond security.

The Builder

The Builder

Developer Perspective

The primitive here, stripped of the launch language, is syscall and process-level behavioral profiling scoped specifically to AI agent runtimes — think eBPF-based telemetry with a detection model trained on agentic process trees instead of human ones. That's actually a technically interesting and non-trivial problem, because the normal baselines for 'is this process doing something weird' break completely when the process is a coding agent that's supposed to read your entire repo. But there's no repo, no API docs, no SDK, and no technical blog post — just a demo video and a waitlist. I can't evaluate the craft when there's nothing to evaluate.

Bookmarks

Loading bookmarks...

No bookmarks yet

Bookmark tools to save them for later