All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Endor Labs sells application security to enterprise security teams, and its platform cuts the flood of dependency alerts by tracing whether a flagged vulnerability can actually be reached and run in a customer's code. A newer feature inventories the open-source AI models a team pulls from Hugging Face and scores their risk. Named customers include OpenAI, Rubrik, Atlassian, Dropbox, and Snowflake, and Endor reports 30x revenue growth since 2023 on $163 million raised, plus a Gartner Visionary placement it displays on its site. A funded rival could rebuild both the scanning and the model scoring, so what a competitor cannot quickly take is the named install base and the scanning context wired into those pipelines, a head start rather than a durable moat.
| Description | Endor Labs is an application security company whose reachability-based platform analyzes open source dependencies, code, and pipelines to cut alert noise, and whose AI Model Discovery line inventories and scores open source AI models from Hugging Face. | [f1] |
|---|---|---|
| Founded | 2021 | [f2] |
| HQ | Palo Alto, California, USA | [f3] |
| Funding | $163M total | [f4] |
| Latest funding | Series B ($93M, April 2025, led by DFJ Growth) | [f3] |
| Product | What it does |
|---|---|
| AURI Application Security Platform | Reachability-based AppSec platform built on a code context graph over code, dependencies, containers, and services, with SCA, AI SAST, secrets, and agentic remediation for evidence-backed findings. |
| Endor Labs AI Model Discovery | Discovers open source AI models from Hugging Face and scores them across security, activity, popularity, and operational integrity so teams can make informed model-usage decisions. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Endor Labs AI Model Discovery discovers open source AI models from Hugging Face and scores them across security, activity, popularity, and operational integrity to surface model risk. This capability is mapped to the AI Defense Matrix. [f5]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
The AURI platform builds a code context graph over code, dependencies, container images, and services, and applies reachability analysis, SCA, AI SAST, and agentic remediation to conventional applications and pipelines. This application-security work is mapped to the Cyber Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | Endor names the AppSec team drowning in scanner alerts as the buyer, but the pain stays qualitative (alert noise, the AI-generated-code surge TechCrunch cites), with the quantified 97.5% Cursor figure coming from a vendor case study rather than independent quantification across multiple non-vendor sources. [s2, s5, s1] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | Public docs and platform pages detail reachability, AI SAST, and secrets, but the cited external evidence is TechCrunch noting the model-scanning tool exists plus a vendor-hosted Cursor case study, with no third-party technical evaluation, benchmark, demo, or open-source release to corroborate the depth. [s2, s5, s10] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Multiple buyer-side signals converge, with Gartner tracking software supply chain security as a named category. The why-now enabler is the AI coding wave that since 2023 floods codebases with machine-generated code faster than AppSec can review it, the same shift Endor cited for its 2025 raise. Its AI model discovery and AI SAST lines address that emerging need. [s5, s3, s1] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Co-founders Varun Badhwar and Dimitri Stiliadis are serial security entrepreneurs who led Prisma Cloud through hypergrowth at Palo Alto Networks, a verifiable domain pedigree. DFJ Growth led the Series B with Salesforce Ventures, Lightspeed, Coatue, and Dell Technologies Capital, which reinforces the signal. [s7, s6] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 4/5 | Endor names enterprise reference customers including OpenAI, Rubrik, Atlassian, Dropbox, and Snowflake, with attributed case studies, and press reports 30x ARR growth since 2023 and over 1 million scans weekly. That named, corroborated traction supports the strong-evidence level rather than the independently-confirmed-scale level above it. [s5, s6, s10] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 | Endor raised $163 million across rounds through its 2025 Series B and shows visible output, protecting more than 5 million applications, but private margins and burn are not disclosed, so efficiency is not directly measurable. That holds the score at adequate. [s5, s6] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Press and Gartner place Endor in software composition analysis and supply chain security, so buyers slot it without vendor coaching. Its Gartner Visionary placement is displayed from the vendor's own site rather than wire-reported, and Visionary is not the Leader position, which holds the score below the independently-confirmed level. [s5, s1] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | Replacement requires reabsorbing the reachability context and reintegrating across repositories, pipelines, and containers, real embedded friction that raises the cost of leaving. A code platform or model provider could add open source model inventory, the AI piece Endor markets, which caps the score rather than lifting it. [s2, s4] |
Endor addresses the gap between how much code modern teams ship and how much application security can review, a gap that AI coding assistants widen. The buyer is the AppSec or engineering owner who must govern open source dependencies, code, and pipelines across many teams without drowning developers in non-actionable alerts.
The problem is evidenced beyond Endor's own framing. Gartner tracks software supply chain security as a named category, and press coverage ties the urgency to the surge of AI-generated code that outpaces manual review.
Reachability is Endor's answer to the noise. It determines whether a known vulnerability is actually invocable through an application's code paths, which reframes the buyer's problem from counting CVEs to fixing the ones that matter. [s2, s5, s1]
Endor's AURI platform is built on a code context graph that maps how code, dependencies, container images, and services connect. On top of that graph it runs full-stack reachability, AI SAST, secrets detection, and agentic remediation, and the vendor reports large noise reductions such as Cursor's 97.5% in an attributed case study.
The AI capabilities split into two parts. AI Model Discovery inventories open source AI models from Hugging Face and scores them on security, activity, popularity, and operational integrity, and an Agent Kit installs Endor security agents inside AI coding assistants.
The platform applies agentic AI reasoning and deterministic program analysis together, which is the same automation direction its AppSec peers describe. The reachability graph and the open source dataset behind it are the technical core a buyer evaluates.
Outside documentation now describes the mechanism. Microsoft's Defender for Cloud documentation states that Endor Labs reachability findings feed natively into its cloud security posture surfaces, including Cloud Security Explorer and Attack Path analysis, that the GitHub app clones and scans every repository in an organization on a 24-hour cycle, and that an unreachable verdict removes a finding from remediation duty under compliance standards such as FedRAMP. Academic work from Paderborn University, SAP, and Fraunhofer IEM names Endor Labs SCA among the popular commercial scanners while documenting a gap in dependency scanning generally, since dependencies that have been recompiled, rebundled, or repackaged evade approaches that read project metadata. [s2, s3, s4, s12, s13]
Endor sits in a crowded application security field. The peer group the reviewed sources establish is the commercial SCA set named by the 2026 Paderborn, SAP, and Fraunhofer IEM study: Snyk, Mend, Black Duck, and SonarQube. The reviewed sources do not compare Apiiro, Cycode, or Legit Security with Endor, so no ranking against them is drawn.
The competitive risk runs in two directions. Consolidating code-security suites pull buyers toward a single vendor, and code platforms or model hosts could move into the open source model inventory space Endor's AI line occupies.
Endor's defensible edge is the enterprise install base and the reachability context accumulated in customer pipelines. A larger vendor could add the AI-model-discovery feature Endor now markets, which is the most absorbable part of the offering.
Independent researchers place Endor Labs in a defined peer group and read it less favorably than the company does. A 2026 study from Paderborn University, SAP, and Fraunhofer IEM lists Endor Labs SCA alongside Snyk, Mend, Black Duck, and SonarQube, calls that group metadata-based, and reports that nearly half of the 1,808 most popular open source Java Maven projects on GitHub carry at least one modified, hidden dependency with a known vulnerability that metadata-based scanning misses. Endor's own materials do not use the metadata-based label, so the characterization runs against the code-level reachability positioning the company leads with. [s2, s4, s6, s14]
Endor's traction is anchored by named enterprise references. Press named OpenAI, Rubrik, Snowflake, and Dropbox as customers, the homepage customer logo wall also names Atlassian, Glean, Robinhood, and Zebra, and attributed case studies such as Cursor carry quantified results.
Endor pairs that customer evidence with disclosed growth and a displayed analyst placement. It reports 30x ARR growth since its 2023 Series A and over a million scans each week, and it displays a Gartner Visionary placement in software supply chain security on its site.
The motion sells the platform to enterprise AppSec and engineering teams, and the AI line gives the sales team a current reason to re-engage accounts as AI coding spreads across the development organization.
Analyst coverage reaches past the placement Endor displays on its own site. Omdia published an On the Radar profile of the company in May 2024, written by chief analyst Rik Turner, describing Endor Labs as a governance platform for selecting, securing, and maintaining open source software. The report body sits behind an Omdia subscription, so the reviewed evidence here is its public abstract. [s5, s6, s10, s11]
Endor Labs was founded in 2021 in Palo Alto by Varun Badhwar and Dimitri Stiliadis and came out of stealth in October 2022. Both founders are serial security entrepreneurs who led Prisma Cloud through hypergrowth at Palo Alto Networks.
The background pairs application-security domain depth with proven company-building, since both founders are serial entrepreneurs who led Prisma Cloud through hypergrowth at Palo Alto Networks.
Investor backing adds a signal. DFJ Growth led the $93 million Series B with Salesforce Ventures and existing backers Lightspeed, Coatue, and Dell Technologies Capital, established investors whose participation signals conviction in the team.
Outside recognition arrived early. Dark Reading covered Endor Labs in July 2023 as one of four finalists in the Black Hat USA startup competition and reported Varun Badhwar's claim that a third of the research and development team have earned doctorates, which puts a research-depth marker on the engineering bench beyond the founders. [s7, s6, s15]
Endor maintains a trust center at trust.endorlabs.com, which is live but sits behind a Cloudflare human-verification challenge that blocks automated retrieval, so its full document list could not be read in the reviewed sources.
Endor's own blog reports a clean SOC 2 Type I audit result, the commercial baseline expected of a vendor that reads source code and dependencies. The accessible reviewed sources confirm only SOC 2 Type I, and because the trust center was not retrievable, any SOC 2 Type II or ISO status could not be verified from this evidence.
This attestation eases enterprise procurement without creating a barrier a funded rival could not also clear. No accessible cited source verifies a federal authorization or a mandatory sector-specific certification. [s9, s8]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Apiiro | competes with | Apiiro is a directly comparable application security and software supply chain platform with a patented code-analysis engine and a larger raise. | |
| Cycode | competes with | Cycode is a directly comparable application security posture management platform with native scanners and a code-to-runtime context graph. | |
| Legit Security | competes with | Legit Security is a comparable AppSec posture management platform unifying code scanning, secrets, supply chain, and remediation across the SDLC. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Snyk | competes with | Snyk competes on developer-first open source and code security with a large install base and a free tier that broadens its reach. |
Add analyzed competitors to compare them side by side with Endor Labs.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
Endor competes in application security on the same terms as its closest posture-management rivals. Its reachability code context graph, its dataset built from public open source code, and its Hugging Face model discovery could each be rebuilt by a funded rival, and SOC 2 is a procurement floor any competitor can clear. What rivals cannot quickly take is the named enterprise install base, OpenAI, Rubrik, Atlassian, and Dropbox, and the scanning context built up in those pipelines. That is a head start, not a moat. It is most defensible where deep reachability integration raises switching cost, weakest where the model-discovery feature it markets is the easiest piece for a larger code platform to copy.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Endor delivers software the customer configures and runs against its own code and pipelines. Reachability scoring, AI SAST, and agentic remediation are automated output, not a human-expertise service that accepts accountability. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Wiring Endor into repositories, pipelines, and the AI agent toolchain builds accumulated reachability context and tuned policy a team must reabsorb to leave. The cost is real in re-integration effort rather than broken production, which places it at the exposed-but-sticky middle level. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Endor reports a clean SOC 2 Type I audit, a table-stakes attestation for a vendor that reads source code, and no accessible cited source verifies a federal authorization or mandatory sector certification that bars a rival. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Building a code context graph and computing full-stack reachability across code, dependencies, and containers to tell whether a vulnerability is invocable is genuinely hard engineering. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 3/3 | Endor's named references are AI labs and large enterprises including OpenAI, Rubrik, Atlassian, Dropbox, and Snowflake, an evidenced demanding buyer, and the motion is enterprise and evaluation-led. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Endor sits in the development and CI path and at the AI coding agent, an important position, but removing it costs the buyer reachability coverage and accumulated context rather than breaking production software. That places it at the middle level. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | Endor's code context graph analyzes a customer's own code and code relationships through deep program analysis, but the public sources do not evidence a proprietary cross-customer corpus or exclusive dataset a rival could not rebuild. That keeps the data position at the lowest level. |
Endor sells to application security and engineering teams at companies whose developers ship code, including AI-generated code, faster than security can review it. The platform targets the alert-noise problem that reachability is built to cut, separating invocable vulnerabilities from the long tail that scanners flag.
The buyer is the AppSec or product-security owner, not an individual developer. Endor's named references span AI labs and large enterprises, including OpenAI, Rubrik, Atlassian, Dropbox, and Snowflake, which places the segment at the demanding, high-stakes end of the market.
The AI line addresses the same buyer from a newer angle. AI Model Discovery frames open source AI models as assets the AppSec owner must inventory and score, which extends the existing relationship rather than opening a separate market.
Endor's AURI platform is built on a code context graph that maps how code, dependencies, container images, and services connect. On top of it run full-stack reachability, AI SAST, secrets detection, and agentic remediation, and the vendor reports large noise cuts such as Cursor's 97.5% in an attributed case study.
The AI capabilities split into two parts. AI Model Discovery inventories open source AI models from Hugging Face and scores them on security, activity, popularity, and operational integrity, and an Agent Kit installs Endor security agents inside AI coding assistants.
Endor combines agentic AI reasoning with deterministic program analysis, the same automation direction its AppSec peers describe. The reachability graph is the technical core, and the cited materials emphasize open source packages and code relationships, so the reviewed public sources do not verify a protected non-public corpus behind it.
Endor's motion sells the platform to enterprise AppSec and engineering teams, and press named OpenAI, Rubrik, Snowflake, and Dropbox as customers. The homepage customer logo wall also names Atlassian, Glean, Robinhood, and Zebra, and attributed case studies such as Cursor carry quantified results.
Disclosed growth reinforces the enterprise pitch. Endor reports 30x ARR growth since its 2023 Series A and over a million scans each week, and it displays a Gartner Visionary placement in software supply chain security on its site.
The AI line gives the sales team a current reason to re-engage existing accounts as AI coding spreads, layering model discovery and AI SAST onto the reachability platform a buyer already runs.
Endor's pricing page names the packaging without naming a number. Six products are sold separately, Code, Open Source, AI Coding Agent Governance, Package Firewall, Patches, and SBOM Hub, each behind a request for pricing, and buyers who want the whole platform are pointed to a sales conversation about bundling.
The pricing metric is disclosed. Endor states that pricing is seat-based and varies by SKU, with seats defined by contributing developers. Editions run from a free Developer tier to paid Core and Pro tiers.
What the public record withholds is the price level. No figures appear for any product or edition, so buyers reach a number through a quote. The absence is a disclosure gap in the price level rather than in the pricing model.
The catalog records a SaaS deployment for Endor Labs AI Model Discovery. The platform integrates with the code, dependencies, containers, and CI/CD it analyzes, and with AI coding agents, so the integration surface spans the development toolchain rather than a single console.
Endor positions AURI as an independent enforcement layer that integrates with AI coding agents through hooks, skills, MCP, or a CLI. That places part of the delivery surface at the developer's AI assistant rather than only in a central console.
The operational burden sits with the customer's AppSec and engineering teams, who tune policy and act on findings. This is software the buyer runs, not a managed service that accepts accountability for outcomes.
Endor maintains a trust center at trust.endorlabs.com, which is live but sits behind a Cloudflare human-verification challenge that blocks automated retrieval, so its full document list could not be read in the reviewed sources.
Endor's own blog reports a clean SOC 2 Type I audit result, the commercial baseline expected of a vendor that reads source code and dependencies. The accessible reviewed sources confirm only SOC 2 Type I, and because the trust center was not retrievable, any SOC 2 Type II or ISO status could not be verified from this evidence.
This attestation eases enterprise procurement without creating a barrier a funded rival could not also clear. No accessible cited source verifies a federal authorization or a mandatory sector-specific certification.
Endor positions AURI as an integrated but independent security layer that gives AI coding agents security context wherever they work, enforcing policy across every agent rather than letting an agent verify its own output.
The integration surface spans repositories, CI/CD, containers, and AI coding assistants through hooks, skills, MCP, and a CLI. That reach into the development and agent toolchain is where the platform earns its place in a buyer's stack.
The ecosystem position cuts both ways. The same toolchain breadth that embeds Endor also puts it on ground that code platforms and model hosts could contest, a competitive risk the reviewed sources do not settle either way.
Endor Labs was founded in 2021 in Palo Alto by Varun Badhwar and Dimitri Stiliadis and came out of stealth in October 2022. Both founders led Prisma Cloud through hypergrowth at Palo Alto Networks.
The founding background pairs application-security domain depth with proven company-building, since both founders are serial entrepreneurs who led Prisma Cloud through hypergrowth at Palo Alto Networks.
DFJ Growth led the $93 million Series B with Salesforce Ventures and existing backers Lightspeed, Coatue, and Dell Technologies Capital. That backing from established investors signals conviction in the team and the category.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Endor Labs homepage: AI-native application security platform | official | 2026-06-25 |
| f2 | Endor Labs: Our Story, founded in Palo Alto | official | 2026-06-25 |
| f3 | Endor Labs Series B: Palo Alto dateline | press | 2026-06-25 |
| f4 | TechCrunch: Endor Labs lands $93M, total raised $163 million | press | 2026-06-25 |
| f5 | AI Defense Matrix Catalog mapping (Endor Labs AI Model Discovery) | other | 2026-06-25 |
| f6 | Endor Labs AURI platform: reachability and code context graph | official | 2026-06-25 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Endor Labs homepage: customer logo wall and Gartner Visionary banner “World-class teams choose Endor Labs. The customer logo wall names Atlassian, Cursor, Dropbox, Glean, Robinhood, and Zebra. Endor Labs named a Visionary in the Gartner Magic Quadrant for Software Supply Chain Security.” | official | 2026-06-25 |
| s2 | Endor Labs AURI platform: reachability and code context graph “AURI's proprietary code context graph combines deep program analysis, proprietary threat intelligence, and agentic AI reasoning to deliver evidence-backed findings instead of alert noise. Reachability determines whether a known vulnerability in a dependency is actually invocable.” | official | 2026-06-25 |
| s3 | Endor Labs documentation: Secure AI Coding and model discovery “AI models and machine learning components have become integral parts of modern software development. Install ready-to-use Endor Labs security agents in your AI coding assistant.” | official | 2026-06-25 |
| s4 | AI Defense Matrix Catalog: Endor Labs AI Model Discovery mapping “Discovers open-source AI models from Hugging Face and scores them across security, activity, popularity, and operational integrity to surface model risk.” | other | 2026-06-25 |
| s5 | TechCrunch: Endor Labs lands $93M, total raised $163 million “The Series B brings the startup's total capital raised to $163 million. Endor now protects more than 5 million applications and runs over a million scans each week for customers including OpenAI, Rubrik, Snowflake, and Dropbox. 30x annual recurring revenue growth since our Series A in 2023.” | press | 2026-06-25 |
| s6 | Endor Labs: $93 million Series B led by DFJ Growth, named customers “Endor Labs today announced its oversubscribed $93 million Series B funding round led by DFJ Growth, with participation from Salesforce Ventures and existing backers including Lightspeed Venture Partners, Coatue, Dell Technologies Capital, Section 32, and Citi Ventures.” | press | 2026-06-25 |
| s7 | Endor Labs: Our Story, founders and Palo Alto founding “2021 Founded in Palo Alto, CA. Our founders, Varun Badhwar and Dimitri Stiliadis, are successful serial entrepreneurs who faced these challenges when they were leading Prisma Cloud through its hypergrowth phase at Palo Alto Networks.” | official | 2026-06-25 |
| s8 | Endor Labs blog: clean SOC 2 Type I audit result “We're excited to announce we have received a clean audit result on our SOC2 Type 1 certification. The successful completion of this SOC 2 Type I audit confirms our commitment to security and privacy.” | official | 2026-06-25 |
| s9 | Endor Labs Trust Center: live behind Cloudflare human verification “trust.endorlabs.com. Performing security verification. This website uses a security service to protect against malicious bots.” | official | 2026-06-25 |
| s10 | Endor Labs customer case study: Cursor noise reduction “Cursor. 97.5% noise reduction. Travis McPeak, Security, Cursor (Anysphere). Endor helps us do it quickly so we can deliver the most secure AI product possible.” | official | 2026-06-25 |
| s11 | Omdia On the Radar (Rik Turner, 23 May 2024): Endor Labs offers software supply chain security “Endor Labs is a developer of software supply chain security (SSCS) technology, providing a governance platform designed for selecting, securing, and maintaining open source software (OSS). Only individuals with an active subscription will be able to access the full article.” | research | 2026-09-01 |
| s12 | Microsoft Defender for Cloud documentation: Endor Labs integration and reachability levels “Reachability analysis findings from Endor Labs are natively integrated with existing Defender Cloud Security Posture Management (CSPM) experiences, including Cloud Security Explorer and Attack Path analysis.” | research | 2026-09-01 |
| s13 | Schott, Ponta, Fischer, Klauke, Bodden (Paderborn, SAP, Fraunhofer IEM): Bytecode-centric Detection of Known-to-be-vulnerable Dependencies in Java Projects “Popular commercial SCA tools include Endor Labs SCA (22), Snyk Open Source SCA (23), Mend SCA (26) and Black Duck SCA (15). However, there are still challenges that modern dependency scanners do not overcome, especially when it comes to dependency modifications” | research | 2026-09-01 |
| s14 | Schott, Ponta, Fischer, Klauke, Bodden: Uncovering Hidden Inclusions of Vulnerable Dependencies in Real-World Java Projects “Commercial SCA tools include Endor Labs SCA (Labs, 2024), Snyk Open Source SCA (Limited, 2024), Mend SCA (Mend.io, 2024), Black Duck SCA (Inc, 2024) and SonarQube (Sarl, 2026). These tools are metadata-based and primarily rely on metadata files to identify dependencies.” | research | 2026-09-01 |
| s15 | Dark Reading (Karen Spiegelman, 7 July 2023): Startup Spotlight, Endor Labs focuses on reachability “The company, one of four finalists in Black Hat USA's 2023 startup competition, looks for the vulnerabilities an attacker could actually access. Where Endor really stands out, Badhwar says, is with its staff: A third of the R&D team have earned doctorates.” | press | 2026-09-01 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Endor Labs homepage: customer logo wall and Gartner Visionary banner “World-class teams choose Endor Labs. The customer logo wall names Atlassian, Cursor, Dropbox, Glean, Robinhood, and Zebra. Endor Labs named a Visionary in the Gartner Magic Quadrant for Software Supply Chain Security.” | official | 2026-06-25 |
| s2 | Endor Labs AURI platform: reachability and code context graph “AURI's proprietary code context graph combines deep program analysis, proprietary threat intelligence, and agentic AI reasoning to deliver evidence-backed findings instead of alert noise. Reachability determines whether a known vulnerability in a dependency is actually invocable.” | official | 2026-06-25 |
| s3 | Endor Labs documentation: Secure AI Coding and Agent Kit “AI models and machine learning components have become integral parts of modern software development. Install ready-to-use Endor Labs security agents in your AI coding assistant.” | official | 2026-06-25 |
| s4 | AI Defense Matrix Catalog: Endor Labs AI Model Discovery mapping “Discovers open-source AI models from Hugging Face and scores them across security, activity, popularity, and operational integrity to surface model risk.” | other | 2026-06-25 |
| s5 | TechCrunch: Endor Labs lands $93M, total raised $163 million “The Series B brings the startup's total capital raised to $163 million. Endor now protects more than 5 million applications and runs over a million scans each week for customers including OpenAI, Rubrik, Snowflake, and Dropbox. 30x annual recurring revenue growth since our Series A in 2023.” | press | 2026-06-25 |
| s6 | Endor Labs: $93 million Series B led by DFJ Growth, named customers “Endor Labs today announced its oversubscribed $93 million Series B funding round led by DFJ Growth, with participation from Salesforce Ventures and existing backers including Lightspeed Venture Partners, Coatue, Dell Technologies Capital, Section 32, and Citi Ventures.” | press | 2026-06-25 |
| s7 | Endor Labs: Our Story, founders and Palo Alto founding “2021 Founded in Palo Alto, CA. Our founders, Varun Badhwar and Dimitri Stiliadis, are successful serial entrepreneurs who faced these challenges when they were leading Prisma Cloud through its hypergrowth phase at Palo Alto Networks.” | official | 2026-06-25 |
| s8 | Endor Labs blog: clean SOC 2 Type I audit result “We're excited to announce we have received a clean audit result on our SOC2 Type 1 certification. The successful completion of this SOC 2 Type I audit confirms our commitment to security and privacy.” | official | 2026-06-25 |
| s9 | Endor Labs Trust Center: live behind Cloudflare human verification “trust.endorlabs.com. Performing security verification. This website uses a security service to protect against malicious bots.” | official | 2026-06-25 |
| s10 | Endor Labs customer case study: Cursor noise reduction “Cursor. 97.5% noise reduction. Travis McPeak, Security, Cursor (Anysphere). Endor helps us do it quickly so we can deliver the most secure AI product possible.” | official | 2026-06-25 |
| s11 | Endor Labs pricing page: seat-based metric, product SKUs, no published prices “Products sold separately with Get pricing and no figure shown: Code, Open Source, AI Coding Agent Governance, Package Firewall, Patches, SBOM Hub. Plans: Developer FREE, Core, Pro. Pricing is seat-based, varying by SKU, seats defined by contributing developers. Bundling runs through sales.” | official | 2026-08-01 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.