Skip to content

Autonomous Plane

Autonomous Plane was a cloud-native application security startup founded by Kyle Quest, creator of the widely used open-source container-optimization tool DockerSlim. The company built…

+ Add to Compare
62/100Incremental Innovator

Overview

Autonomous Plane was a cloud-native application security startup founded by Kyle Quest, creator of the widely used open-source container-optimization tool DockerSlim. The company built full-stack reachability technology that pairs static dependency-graph analysis of source code with automatic runtime profiling of running containers, allowing security teams to see exactly which vulnerable packages and code paths are actually exploitable in production rather than merely present in a manifest.

By tracing risk continuously from source code through to the running container image, Autonomous Plane’s approach is designed to filter out the large share of vulnerability-scanner findings — vendors describe up to 90% — that are technically present but never reachable by an attacker, letting engineering and security teams focus remediation effort on what matters.

Endor Labs acquired Autonomous Plane in February 2026 to extend its AI-native application security platform with this full-stack, code-to-container reachability capability. Terms were not disclosed.

Innovation Matrix Assessment

Innovation Velocity 7/10

Went from founding to a full-stack code-to-container reachability capability and acquisition by a category leader within roughly a year, a fast validation cycle for a deeply technical niche.

Operational Value 7/10

Directly reduces alert fatigue for AppSec teams by distinguishing exploitable vulnerabilities from theoretically-present ones, cutting remediation workload as Endor Labs' stated rationale for the deal.

Market Momentum 6/10

Acquired by Endor Labs in February 2026 to fold full-stack reachability into its platform -- real market validation, though as a private acquisition target financial and customer-count details were never disclosed.

Category Disruption 6/10

Extends reachability analysis, an established application-security technique, to span the container runtime layer rather than stopping at source code -- a meaningful but incremental extension of prior art.

Real-World Efficacy 4/10

As a pre-acquisition startup with no independent customer references or third-party benchmarking available, efficacy rests on the founder's track record and the acquirer's technical due diligence rather than published evidence.

Enduring Relevance 7/10

Reducing false positives in vulnerability management is a durable, widely shared pain point across AppSec teams, and the code-to-container reachability approach is likely to keep spreading regardless of this deal's outcome.

Why CISOs Should Care

Gives application security teams a way to cut through vulnerability-scanner noise by proving which flagged issues are actually reachable from source code through to a running container, so scarce remediation effort goes to real exposure rather than theoretical findings.

What Makes It Different

Combines static dependency-graph analysis of source code with automatic runtime profiling of containers into a single full-stack reachability picture, rather than reachability analysis scoped to only the code layer or only the container layer.

The Matrix Verdict

62/100 — INCREMENTAL INNOVATOR

A narrowly focused, technically credible reachability-analysis team whose acquisition by Endor Labs within roughly a year of emerging validates the approach; Category Pioneer for the specific code-to-container reachability niche, assessed at the moment of acquisition rather than as an ongoing independent vendor.

Editorial Note: Claims vs. Verified Findings

Founder's DockerSlim pedigree and the acquisition itself are independently documented via PR Newswire and multiple trade press; the '90% false positive reduction' figure is a vendor (Endor Labs) claim at time of acquisition and is not independently benchmarked here.

Sources