Key Takeaways
- Glow hit $1.2B valuation with zero public revenue data, the latest cybersecurity unicorn minted on narrative alone
- The startup bets AI agents now live on employee laptops, not just in the cloud — a shift that may be real or merely well-timed marketing
- Anthropic's Mythos model, which hunts vulnerabilities autonomously, gave Glow its origin story and its urgency in one stroke
- Founders from Meta and Snowflake are selling a platform that runs on Anthropic and Gemini models — not their own
A cybersecurity startup founded in 2025 just commanded a $1.2 billion valuation before showing a single dollar of verified revenue. That sentence should make anyone who covers this industry pause. Glow emerged from stealth Wednesday with $180 million in fresh equity, a cap table stacked with Sequoia, Cyberstarts, Greenoaks, and a syndicate of smaller funds, and a thesis that artificial intelligence has fundamentally inverted the endpoint security problem. The money is real. The valuation is real. The product is real enough to have paying customers across healthcare, retail, and financial services. What remains unproven is whether the market shift Glow describes is actually happening at the scale its pitch requires.
The endpoint security category has been declared dead, reborn, consolidated, and disrupted so many times that skepticism is the only rational starting point. CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, and a graveyard of acquired vendors have spent two decades perfecting the art of watching what runs on a laptop. Glow's argument is that AI changes the physics of that problem. Not because attackers use AI to write better phishing emails — they do, but that's incremental. Glow's case rests on a sharper claim: AI agents now execute code on employee devices with autonomy that traditional sensors cannot see, contextualize, or control. If that's true, the entire detection-and-response stack needs rewriting. If it's aspirational, Glow is just the best-funded entrant in a crowded "next-gen endpoint" lottery.
The company's timing is suspiciously precise. Anthropic's Mythos model, unveiled earlier this year, demonstrated an AI that can discover and exploit software vulnerabilities without human guidance. That announcement did two things for Glow. It handed the startup a credible existential threat to wave at boards and budget holders. It also signaled that the frontier labs now view offensive cyber capability as a benchmark worth publishing. Glow's founders — former Meta engineering VP Roi Tiger, ex-Snowflake security strategist Omer Singer, ex-Claroty R&D head Ophir Arie, and Meta engineering leader Arnon Joseph — know how to read those signals. They left institutions that move slowly to build a company that can cite Mythos in its Series A deck while the ink is still drying.
Tiger's framing is clean: the last decade pushed everything to cloud and SaaS; now AI lands on the endpoint in a way we've never seen. It's a soundbite engineered for partner keynotes. The architecture backing it is less novel. Glow's platform uses specialized AI agents to continuously map enterprise environments, assess risk in real time, and enforce policy. Those agents run on Anthropic and Google Gemini models accessed through Amazon Bedrock. Glow builds the orchestration, context injection, and reliability layers. In other words, the differentiated intelligence belongs to Anthropic and Google. Glow provides the plumbing. That's a viable business — many great companies have been built on plumbing — but it caps the moat. If Anthropic or Google decide the endpoint orchestration layer is strategic, they own the models and the distribution. Glow's IP lives in the integration.
The customer claims follow the standard stealth-exit playbook: paying logos across verticals, deployments spanning tens of thousands of devices globally, zero names, zero counts, zero retention metrics. Tiger declined to disclose any of it. That's his right. It's also the norm for companies that raise at this valuation before revenue scales to match. The unicorn-before-metrics club has grown crowded in cybersecurity. Some members grow into their valuations. Others become cautionary tales about narrative outpacing product-market fit. Glow's Series A size — $180 million all-equity — suggests investors are paying for option value on a massive market, not traction that justifies the multiple. The capital gives Glow runway to prove the thesis. It also creates pressure to manufacture evidence that the thesis is real.
COO Emily Heath brings the only operator credential in the founding orbit: former CISO at United Airlines and DocuSign, board member at Wiz through its $32 billion sale to Google, partner at Cyberstarts. She knows what buyers actually evaluate. That matters more than the Meta and Snowflake logos on the engineering side. Enterprise security purchases are won in procurement reviews, not architecture diagrams. Heath's presence signals Glow intends to sell like a grown-up, not just build like a lab.
The broader question is whether "AI on the endpoint" is a platform shift or a feature war. Microsoft is embedding Copilot across Windows. Google is pushing Gemini into Chrome OS and Android. Apple Intelligence arrives on macOS. Every major endpoint sensor vendor is bolting on LLM-powered triage. Glow's bet is that a standalone control plane — one that sits above the OS, the EDR sensor, the MDM, the browser, the developer toolchain — becomes the necessary abstraction layer. That only wins if enterprises accept a new privileged agent on every device, managed by a startup with no track record, running on models it doesn't own. Possible. Not inevitable.
Glow's $1.2 billion price tag is a wager on velocity. The company must prove that AI agents on endpoints create risks existing tools cannot see, that its orchestration layer catches what the model providers' own extensions miss, and that enterprises will pay a premium for that delta — all before the next funding cycle demands revenue that matches the valuation. The money is in the bank. The clock started Wednesday.