Endor Labs

Application security with reachability analysis

Security & Safety Enterprise Has API
Researched · Published
RECATOOLS Score
7.5 / 10
Capability
8
Value for money
6
Ease of use
7
ASEAN readiness
6
API quality
7
Founded
2021
HQ
Palo Alto, California, USA
Users
Launched
Developer

Overview

Endor Labs uses graph-based reachability analysis to filter SCA findings down to actually-exploitable vulnerabilities — cuts noise by 80%+ vs traditional tools. Also offers AI-aware features for ML-supply-chain security. Founded by ex-Prevoty / ex-Imperva team.

Advertisement

Use cases

SCA noise reduction Reachability analysis ML supply chain

What you can produce with Endor Labs

  • Scan your repositories' open-source dependencies and filter CVE findings down to the ones whose vulnerable functions your code actually calls.
  • Cut dependency-alert noise dramatically so developers remediate a short, reachable-risk list instead of triaging hundreds of raw CVEs.
  • Evaluate a new open-source package before adoption using scores for its security posture, maintenance activity, and popularity.
  • Generate remediation guidance that identifies the safest upgrade path, flagging version bumps likely to introduce breaking changes.
  • Enforce security policies in CI by blocking pull requests that introduce reachable vulnerabilities or disallowed licences.
  • Produce SBOMs and VEX documents for compliance requests, annotated with exploitability context rather than bare component lists.
  • Scan AI-related supply-chain surfaces, including ML models and MCP servers, for risks before they reach production.
Advertisement

ASEAN Perspective

Endor Labs in Southeast Asia

ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).

RECATOOLS Verdict

Endor Labs is a strong software-supply-chain security platform whose core differentiator is reachability analysis — instead of flooding teams with every CVE in every dependency, it determines whether vulnerable code is actually called, dramatically cutting false positives and letting AppSec teams focus on real risk. It has broadened into SBOMs, secrets detection, CI/CD posture and securing AI-generated code, making it a serious contender against Snyk and the legacy SCA crowd.

The noise-reduction value is real but it is an enterprise tool with enterprise pricing and a security-team audience — overkill for hobby projects. Like any analysis engine, reachability isn't infallible and benefits from tuning. Globally sold, English-first, API and CI integrations are solid; ASEAN engineering orgs with mature AppSec functions can adopt it readily. A genuinely good choice in its category for teams fighting alert fatigue.

Independent AI-assisted assessment by RECATOOLS.

What people say

Endor Labs is still independent and growing fast. It raised a US$93M Series B in April 2025 led by DFJ Growth (with Salesforce Ventures and Lightspeed participating), bringing total funding to about US$188M, and analyst estimates put ARR around US$15M at the end of 2025, up roughly 131% year on year. The company has also leaned hard into AI: beyond its original software-composition-analysis roots, it now markets an AI-native application security platform (branded AURI) with AI code review and MCP/ML-supply-chain scanning, positioning itself for codebases increasingly written by agents.

User sentiment is strongly positive but thin in volume: on G2 the product holds 4.8/5 across just nine reviews, most of them five-star, so treat the number as directional rather than statistical. What those reviewers consistently praise is the core pitch actually working — function-level reachability analysis that filters CVE noise down to vulnerabilities your code can actually reach, which security engineers describe as transformative for prioritisation. Instead of drowning developers in hundreds of alerts, teams report focusing remediation on the small reachable fraction, and the ability to justify ignoring the rest with call-graph evidence is repeatedly called out as the differentiator against traditional SCA tools.

The caveats are the usual ones for a young enterprise security vendor. Pricing is quote-based and generally regarded as premium, sized for organisations with real appsec budgets rather than small startups. The public review base is small, language and ecosystem coverage for reachability varies by stack, and teams switching from incumbent scanners should budget for integration work across CI pipelines and ticketing.

Endor Labs fits mid-size to large engineering organisations with heavy open-source dependency trees, drowning in scanner findings and needing defensible prioritisation — especially those already worrying about AI-generated code and MCP-server risk. Teams that just need a free baseline scanner will find OSS alternatives sufficient.

Summary of public user & expert reviews, compiled by RECATOOLS.

About this listing

Researched on
Published on

This entry was compiled from publicly available data including Endor Labs's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Endor Labs unless explicitly stated.

Data accuracy

Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.

For the latest details, please refer to Endor Labs directly →

Spotted something out of date? Suggest an update →

Advertisement