Endor Labs
Endor Labs is an AI-native application security platform that combines agentic reasoning with deterministic program analysis to deliver full-stack, reachability-based software supply chain security for Fortune 500 enterprises, cloud-native and AI-first companies, and individual developers.
- Company typePrivate
- Founded2022
- HeadquartersPalo Alto, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Endor Labs does
Endor Labs is a Palo Alto-based, venture-backed application security company founded in 2022 that operates an AI-native platform for software supply chain security. Its core product, AURI, combines multi-agent AI reasoning with deterministic program analysis to deliver verifiable, reproducible evidence — data flow, call paths, and reachability — for security findings across source code, open-source dependencies, and container images. The platform unifies reachability-based SCA, AI SAST (multi-modal, 40+ languages), AI Security Code Review, AI Code Governance for AI coding agents, Secrets Detection, Malicious Package Detection (150+ supply-chain signals), Container Reachability (extended via the February 2026 Autonomous Plane acquisition), SBOM Hub, Package Firewall, Upgrade Impact Analysis, and Magic Patches.
Endor Labs sells primarily through enterprise SaaS subscriptions to Fortune 500, financial services, and cloud-native/AI-first companies — named customers include OpenAI, Atlassian, Citi, Snowflake, Netskope, Robinhood, Dropbox, Glean, Five9, Mysten Labs, Zebra Technologies, and Cursor — supported by a freemium developer tier (AURI free for individual developers, free VS Code extension, endorctl CLI, GitHub Action, GitHub App), distribution via Google Cloud Marketplace, and embedded partnerships with Microsoft Defender for Cloud and GitHub Advanced Security. Pricing is not publicly disclosed; enterprise contracts are quote-based with annual billing, while developer/free tiers support bottom-up adoption.
The company has raised at least $188 million in disclosed equity funding across a $25M seed (October 2022), $70M Series A (August 2023), and $93M Series B (April 2025, led by DFJ Growth and Salesforce Ventures), plus strategic investments from Citi Ventures and Silicon Valley CISO Investments. Endor Labs reports 30x ARR growth over 18 months as of April 2025, protects over 5 million applications, and has been recognized as a 2026 Gartner Magic Quadrant Visionary for Software Supply Chain Security and a 2023 Gartner Cool Vendor.
Endor Labs firmographics
Firmographics- Name
- Endor Labs
- Legal name
- Endor Labs
- Website
- https://endorlabs.com
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Endor Labs is an AI-native application security platform that combines agentic reasoning with deterministic program analysis to deliver full-stack, reachability-based software supply chain security for Fortune 500 enterprises, cloud-native and AI-first companies, and individual developers.
- Ownership category
- akta.pro rank
Endor Labs industry classification
Industry- Product category
- Application Security Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372)
- akta.pro primary industry
- Endpoint Security Managed Services (EDR/XDR) (BPAEADAH)
Keywords
Where Endor Labs is headquartered
LocationHeadquarters
- HQ city
- Palo Alto
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Endor Labs business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Enterprise SaaS Subscriptions: Endor Labs generates revenue through SaaS subscriptions for its application security platform, sold primarily to enterprise and Fortune 500 customers (OpenAI, Atlassian, Citi, Snowflake, Netskope, Robinhood, Five9, Mysten Labs, Zebra, Dropbox, Glean, Astronomer, Starburst, Grip Security, Jellyfish). The company reports 30x ARR growth over 18 months as of April 2025 and serves highly regulated industries including financial services, insurance, and group companies.
- Freemium Developer Tier: AURI is offered free to individual developers as a self-serve product, serving as a land-and-expand motion that drives bottom-up adoption within engineering teams before converting to enterprise contracts.
- Marketplace Distribution (Google Cloud Marketplace): Endor Labs is available on the Google Cloud Marketplace, enabling procurement via cloud committed spend for enterprise customers.
- GitHub Advanced Security Integration: Endor Labs' SCA capabilities are integrated into GitHub Advanced Security as a native add-on for joint customers, extending the platform's reach through GitHub's developer ecosystem.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise — Quote-based, contact sales via Book a Demo |
| Freemium | Monthly | Free for individual developers (AURI) |
| Freemium | Pay-as-you-go | Free 30-day trial of Endor Labs platform |
Go-to-market motion6 records
Distribution channels6 records
Marketing channels13 records
Endor Labs product offering
Product offeringCore offering
Endor Labs operates an AI-native application security platform that combines agentic reasoning with deterministic program analysis to secure the software supply chain. Its core product AURI delivers full-stack reachability analysis across source code, open-source dependencies, and container images, providing verifiable evidence (data flow, call paths, reachability) for every security finding with up to 95% false positive reduction. The platform is sold primarily as an enterprise SaaS subscription with a freemium developer tier and is distributed via Google Cloud Marketplace, Microsoft Defender for Cloud, and GitHub Advanced Security.
Product overview
Endor Labs offers a single AI-native application security platform organized around the core AURI security-intelligence product, surrounded by a portfolio of integrated modules covering every stage of software supply-chain security. The platform unifies SCA with Reachability, AI SAST, AI Security Code Review, AI Code Governance for AI coding agents, Secrets Detection, Malware Prevention (Malicious Package Detection), Container Reachability, SBOM Hub, Package Firewall, Endor Patches, Upgrade Impact Analysis, AI Model Discovery, Artifact Signing, CI/CD Discovery, and Repository Security Posture Management. These modules share reachability-based analysis and threat-intelligence infrastructure that together filter up to 95% of false positives and deliver end-to-end code-to-container visibility. The platform is delivered through the endorctl CLI, the Endor Labs MCP server, a Visual Studio Code extension, and pre-built CI/CD integrations for GitHub, GitLab, Bitbucket, Jenkins, and CircleCI, and extends into Microsoft Defender for Cloud, GitHub Advanced Security, and the Google Cloud Marketplace. The Autonomous Plane product, acquired in February 2026, brings dynamic and static container analysis into the platform as part of the full-stack reachability offering.
Differentiator
Problem solved
Functional benefit
Brands
- AURI: Security intelligence platform for agentic AI software development; an independent, integrated policy and enforcement layer for AI coding agents combining agentic reasoning with deterministic program analysis.
- LeanAppSec
Products and services
- Endor Labs Application Security Platform Endor Labs' unified AI-native application security platform providing code-to-container security analysis with reachability, exploitability analysis, and audit-ready evidence, sold as enterprise SaaS subscriptions to Fortune 500, financial services, insurance, and cloud-native customers (OpenAI, Atlassian, Citi, Snowflake, Netskope, Robinhood, Five9).
- AURI - Security Intelligence for Agentic Software Development AURI is Endor Labs' security intelligence platform for agentic AI software development, combining agentic reasoning with deterministic program analysis to deliver full-stack reachability across code, dependencies, and container images for every AI coding agent. Offered free to individual developers with enterprise options; integrates via MCP, Hooks, Skills, and CLI across Cursor, GitHub Copilot, Claude, and Gemini.
- Opengrep Opengrep is an open-source static code analysis engine forked from Semgrep that provides a community-governed, vendor-neutral alternative for source code security scanning across languages, available as a standalone open-source project within the Endor Labs ecosystem.
- Autonomous Plane (Container Reachability) Cloud-native application security product acquired in February 2026 that provides dynamic and static container analysis integrated into Endor Labs' full-stack reachability offering, delivering code-to-container reachability for enterprise customers.
- endorctl CLI endorctl is a command-line interface and developer tool that runs Endor Labs SCA, SAST, secrets, container, and malware scans locally and in CI, supporting Bazel, GitHub Actions, GitLab, Bitbucket, Jenkins, and CircleCI integrations and serving as the developer entry point for free PLG adoption.
- Risk Explorer Risk Explorer is a public-facing, free threat research and risk intelligence tool at riskexplorer.endorlabs.com that surfaces CVE and supply chain risk data for open-source packages and the broader OSS ecosystem.
Quantifiable outcome
- Up to 95% reduction in false positives / 95% noise reduction across code, dependencies, and container images
- +10 more outcomes
Companies that use Endor Labs
Customer profileNamed customers16 records
Segments5 records
Ideal customer profiles5 records
Endor Labs technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration17 records
AI capability12 records
Feature10 records
Endor Labs partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered flagship and core.
- Autonomous PlaneflagshipEndor Labs acquired Autonomous Plane, a cloud-native application security company founded by Kyle Quest (creator of DockerSlim), in February 2026. The acquisition adds full-stack reachability combining source code analysis with static and dynamic container analysis, filtering out up to 90% of false positives. Both companies are Palo Alto-based. Deal terms were not disclosed.
- GitHub CopilotcoreEndor Labs integrates with GitHub Copilot in VS Code, providing security intelligence directly inside the AI coding workflow.
- CursorflagshipEndor Labs integrates with Cursor (Anysphere) AI Code Editor, securing AI-generated code at the source via a new Cursor integration powered by the Endor Labs platform. Cursor is also a customer.
- Google Cloud MarketplacecoreEndor Labs is available on Google Cloud Marketplace as a distribution channel, allowing enterprise customers to procure via cloud committed spend.
- GitHub Advanced SecurityflagshipGitHub Advanced Security integrates Endor Labs SCA, extending Microsoft's alliance from Defender for Cloud to GitHub and enabling joint customers to 'go from finding to fixing' within the GitHub ecosystem.
- Hugging FacecoreEndor Labs created a way to evaluate open source AI models for security and quality on Hugging Face, supporting AI Model Discovery and AI model scoring capabilities launched January 2025.
- Microsoft Defender for CloudflagshipMicrosoft Defender for Cloud natively integrates with Endor Labs, making Defender for Cloud the first CNAPP to provide true code-to-runtime reachability per Microsoft's Vlad Korsunsky quote. The collaboration was extended to GitHub in February 2025.
- Karl Mattson (CISO)flagshipKarl Mattson, a cybersecurity veteran, joined Endor Labs as the company's first Chief Information Security Officer in September 2024, bringing leadership in cyber defense to the team.
- Claude (Anthropic)coreEndor Labs integrates with Claude via Anthropic's plugins/AI-plugins platform (claude.com/plugins/ai-plugins), enabling security intelligence inside the Claude AI coding workflow.
- Gemini (Google)coreEndor Labs integrates with Gemini via Google's Gemini API documentation, extending security intelligence to the Google AI coding ecosystem.
- GitLabcoreEndor Labs integrates with GitLab for CI/CD scanning, MR comments, and AI coding security workflows, with a dedicated GitLab App and endorctl CLI integration.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
Endor Labs competitors and assessment
Company assessmentDirect peers
- Semgrep: Semgrep is a developer-focused SAST platform using static analysis with custom rules — Endor Labs forked Semgrep to create Opengrep and competes head-to-head for code-scanning workloads.
- Socket: Socket provides supply chain security focused on malicious open-source package detection, directly competing with Endor Labs' Malware Prevention / Malicious Package Detection module.
- Snyk: Snyk is the leading developer-first application security platform offering SCA, SAST, container, and IaC security to enterprise developers. It is Endor Labs' most direct competitor across SCA and the broader AppSec platform category.
- Checkmarx: Checkmarx provides enterprise SAST, SCA, and application security testing, competing directly with Endor Labs' AI SAST and SCA-with-reachability modules for Fortune 500 AppSec teams.
- Veracode: Veracode offers a comprehensive AppSec portfolio including SAST, DAST, and SCA, serving large regulated enterprises — overlapping with Endor Labs' financial-services and Fortune 500 customer base.
- Sonar (SonarQube): Sonar (SonarSource/SonarQube) provides code quality and security analysis integrated into developer workflows, directly comparable to Endor Labs' AI SAST and developer-tooling approach.
- Chainguard: Chainguard secures the software supply chain through hardened container images and artifact signing, overlapping with Endor Labs' container scanning, artifact signing, and supply-chain posture modules.
- Mend (formerly WhiteSource): Mend provides SCA, SAST, and application security focused on open-source dependency management — competing with Endor Labs' SCA-with-reachability and Upgrade Impact Analysis modules.
Broad incumbents
- GitHub Advanced Security: GitHub Advanced Security offers Dependabot (SCA), Code Scanning (SAST), and secret scanning natively inside the GitHub ecosystem. As both a partner and a potential competitor, it competes broadly across Endor Labs' portfolio for developer mindshare.
Emerging players
- Aikido Security: Aikido Security is an emerging all-in-one AppSec platform offering SCA, SAST, secrets, and cloud security with a freemium developer-first motion — competing with Endor Labs' PLG funnel and integrated platform approach.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Endor Labs social profiles
Digital presenceEndor Labs compliance and trust
Trust signalCompliance10 records
Endor Labs financial estimates
Financial estimateRevenue estimate
Valuation estimate
Endor Labs leadership team
Management profileNumber of profiles
Profiles6 records
Endor Labs subsidiaries and ownership
Company hierarchySubsidiaries1 record
Endor Labs funding detail
Funding detailFunding overview
Funding rounds5 records
Investors10 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Endor Labs M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Endor Labs
What does Endor Labs do?
Endor Labs operates an AI-native application security platform that combines agentic reasoning with deterministic program analysis to secure the software supply chain. Its core product AURI delivers full-stack reachability analysis across source code, open-source dependencies, and container images, providing verifiable evidence (data flow, call paths, reachability) for every security finding with up to 95% false positive reduction. The platform is sold primarily as an enterprise SaaS subscription with a freemium developer tier and is distributed via Google Cloud Marketplace, Microsoft Defender for Cloud, and GitHub Advanced Security.
Is Endor Labs a public or private company?
Endor Labs is a private company. It is classified as venture growth investor backed and is currently operating.
When was Endor Labs founded?
Endor Labs was founded in 2022. It employs 101 to 250 people.
Where is Endor Labs based?
Endor Labs is headquartered in Palo Alto, United States, in the North America region.
How does Endor Labs make money?
Four revenue lines are on record. Enterprise SaaS Subscriptions are the primary driver. The others are freemium Developer Tier, marketplace Distribution (Google Cloud Marketplace) and gitHub Advanced Security Integration.
Who are Endor Labs's main competitors?
Direct peers on record are Semgrep, Socket, Snyk, Checkmarx, Veracode, Sonar (SonarQube), Chainguard and Mend (formerly WhiteSource). GitHub Advanced Security is listed as a broad incumbent. Aikido Security is listed as an emerging player.
Does Endor Labs have an API?
Yes. Endor Labs offers a developer-facing API alongside its endorctl CLI for programmatic access to scanning, findings, projects, and platform administration. The API supports API key-based authentication (manage API keys section), webhooks for event-driven integrations, and data exporters. An MCP (Model Context Protocol) server is available to securely deploy Endor Labs capabilities within IDEs and AI coding workflows. Developer documentation is at docs.endorlabs.com.
What industry is Endor Labs in?
Endor Labs's product category is Application Security Software. Its primary akta.pro industry code is BPAEADAH, Endpoint Security Managed Services (EDR/XDR). Its NAICS code is 54151 and its SIC code is 7372.