Endor Labs
Application security platform using function-level reachability analysis to prioritize open-source and supply chain risk.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Endor Labs builds static call graphs to determine whether vulnerable functions in dependencies are actually invoked by an application, suppressing alerts that are not reachable.
The platform also covers secrets, container scanning, malicious-package detection and SBOM generation, and is adding checks for AI-generated code.
Innovation Matrix Assessment
Extended from SCA reachability to AI-code checks; steady product advance.
Reachability filtering reduces alert triage for AppSec teams.
$93M Series B (Apr 2025) led by DFJ Growth; totals reported between $188M and $233M.
Function-level reachability is a differentiated approach, though others offer reachability.
Noise reduction figures (80-92%) are vendor-derived; no independent tests found.
Dependency risk grows with AI-generated code.
Why CISOs Should Care
Reduces dependency alert noise so developers fix only vulnerabilities that can actually be reached.
What Makes It Different
Language-specific call-graph analysis instead of package-level matching.
The Matrix Verdict
65/100 — INCREMENTAL INNOVATOR
Endor Labs is an Incremental Innovator near Meaningful, with differentiated technology and good funding but efficacy evidence that is largely vendor-reported.
Editorial Note: Claims vs. Verified Findings
The 80% and 92% noise-reduction figures are vendor claims. Funding is from press and research aggregators and totals conflict.
Sources
Alternatives to Endor Labs
ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…