High-Level Overview
Endor Labs is a technology company specializing in modern application security (AppSec) solutions designed for the AI-driven era of software development. It builds a comprehensive AppSec platform that deeply analyzes software by constructing a complete function call graph across first-party, open-source, and AI-generated code. This approach enables Endor Labs to intelligently identify and prioritize real security vulnerabilities, reducing false positives by about 92%, which allows security teams and developers to focus on critical risks without slowing down innovation. Its platform unifies multiple security functions—including software composition analysis (SCA), static application security testing (SAST), secrets scanning, container scanning, and CI/CD security—into a single, remediation-focused solution. Endor Labs serves leading enterprises such as OpenAI, Rubrik, and Dropbox, helping them secure complex software supply chains and accelerate secure software delivery[1][2][3].
Origin Story
Founded in 2021 in Palo Alto, California, by Varun Badhwar and Dimitri Stiliadis, both serial entrepreneurs with prior experience leading Prisma Cloud at Palo Alto Networks, Endor Labs emerged to address the growing challenges of securing software in a world increasingly reliant on open source and AI-generated code. The founders recognized the need to reduce the noise of excessive security alerts and provide actionable insights that enable faster remediation. The company launched publicly in 2022 and quickly gained traction, raising $70 million in a Series A round in 2023 and $93 million in Series B in 2025, becoming the fastest-growing AppSec company. Its team includes experts from top tech firms like Meta, Uber, Amazon, and Cisco, and it has built a strong research arm called Station 9 focused on open source risk and dependency management[3][4].
Core Differentiators
- Proprietary Function Call Graph Analysis: Endor Labs’ unique technology traces data paths through function calls to determine if vulnerabilities are exploitable, drastically reducing false positives and alert fatigue.
- Unified AppSec Platform: Combines SCA, SAST, secrets scanning, container scanning, and CI/CD security into one integrated platform, simplifying security workflows.
- AI-Driven Automation: Uses AI to automate code reviews, prioritize vulnerabilities, and enable guardrails for AI coding assistants to write secure code by default.
- Strong Developer Experience: Enables developers to fix vulnerabilities six times faster with clear, actionable remediation guidance.
- Deep Program Analysis: Provides comprehensive visibility across first-party, open-source, and AI-generated code, supporting modern monorepo architectures and complex software supply chains.
- Research and Innovation: Station 9 research team produces influential reports on open source risks and dependency management, reinforcing Endor’s thought leadership.
- Rapid Integration: Easy to set up with advanced build systems like Bazel and CI/CD pipelines, supporting fast adoption in engineering organizations[1][2][3][5].
Role in the Broader Tech Landscape
Endor Labs is riding the critical trend of securing software supply chains amid the software development revolution, where AI-generated code is rapidly becoming dominant. With estimates that 80% of code will soon be AI-generated, traditional AppSec tools struggle to keep pace with the volume and complexity of new code. Endor Labs addresses this by combining deep program analysis with AI-driven automation, enabling organizations to shift security left and embed it seamlessly into fast development cycles. This timing is crucial as software supply chain attacks and open source vulnerabilities continue to rise, making effective risk prioritization and remediation essential. By unifying fragmented security tools and focusing on actionable insights, Endor Labs influences the broader ecosystem by enabling secure innovation and helping enterprises maintain trust in their software delivery[1][2][4][6].
Quick Take & Future Outlook
Looking ahead, Endor Labs is positioned to lead the evolution of AppSec into the "vibe coding era," where AI coding assistants generate large volumes of code with minimal human oversight. Its recent launch of an agentic AI AppSec platform reflects a forward-looking strategy to not only secure AI-generated code but also to use AI to scale security operations efficiently. As AI adoption in software development grows, Endor Labs’ ability to integrate AI for both detection and remediation will likely become a key competitive advantage. The company’s continued expansion of its platform capabilities and research initiatives suggests it will deepen its influence on how organizations manage software supply chain risks and secure modern development pipelines. This trajectory ties back to its founding mission: helping organizations ship secure software fast with clarity on what truly matters[4][5][8].