Autonomous Plane
Autonomous Plane was a cloud-native application security startup founded by Kyle Quest, creator of the widely used open-source container-optimization tool DockerSlim. The company built…
+ Add to CompareOverview
Autonomous Plane was a cloud-native application security startup founded by Kyle Quest, creator of the widely used open-source container-optimization tool DockerSlim. The company built full-stack reachability technology that pairs static dependency-graph analysis of source code with automatic runtime profiling of running containers, allowing security teams to see exactly which vulnerable packages and code paths are actually exploitable in production rather than merely present in a manifest.
By tracing risk continuously from source code through to the running container image, Autonomous Plane’s approach is designed to filter out the large share of vulnerability-scanner findings — vendors describe up to 90% — that are technically present but never reachable by an attacker, letting engineering and security teams focus remediation effort on what matters.
Endor Labs acquired Autonomous Plane in February 2026 to extend its AI-native application security platform with this full-stack, code-to-container reachability capability. Terms were not disclosed.
Innovation Matrix Assessment
Went from founding to a full-stack code-to-container reachability capability and acquisition by a category leader within roughly a year, a fast validation cycle for a deeply technical niche.
Directly reduces alert fatigue for AppSec teams by distinguishing exploitable vulnerabilities from theoretically-present ones, cutting remediation workload as Endor Labs' stated rationale for the deal.
Acquired by Endor Labs in February 2026 to fold full-stack reachability into its platform -- real market validation, though as a private acquisition target financial and customer-count details were never disclosed.
Extends reachability analysis, an established application-security technique, to span the container runtime layer rather than stopping at source code -- a meaningful but incremental extension of prior art.
As a pre-acquisition startup with no independent customer references or third-party benchmarking available, efficacy rests on the founder's track record and the acquirer's technical due diligence rather than published evidence.
Reducing false positives in vulnerability management is a durable, widely shared pain point across AppSec teams, and the code-to-container reachability approach is likely to keep spreading regardless of this deal's outcome.
Why CISOs Should Care
Gives application security teams a way to cut through vulnerability-scanner noise by proving which flagged issues are actually reachable from source code through to a running container, so scarce remediation effort goes to real exposure rather than theoretical findings.
What Makes It Different
Combines static dependency-graph analysis of source code with automatic runtime profiling of containers into a single full-stack reachability picture, rather than reachability analysis scoped to only the code layer or only the container layer.
The Matrix Verdict
62/100 — INCREMENTAL INNOVATOR
A narrowly focused, technically credible reachability-analysis team whose acquisition by Endor Labs within roughly a year of emerging validates the approach; Category Pioneer for the specific code-to-container reachability niche, assessed at the moment of acquisition rather than as an ongoing independent vendor.
Editorial Note: Claims vs. Verified Findings
Founder's DockerSlim pedigree and the acquisition itself are independently documented via PR Newswire and multiple trade press; the '90% false positive reduction' figure is a vendor (Endor Labs) claim at time of acquisition and is not independently benchmarked here.
Sources
- PR Newswire -- https://www.prnewswire.com/news-releases/endor-labs-acquires-autonomous-plane-expanding-ai-native-application-security-with-full-stack-reachability-from-code-to-container-302684888.html
- SecurityBrief -- https://securitybrief.news/story/endor-labs-buys-autonomous-plane-for-container-security
Alternatives to Autonomous Plane
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…