Skip to content

Endor Labs

Application security platform using function-level reachability analysis to prioritize open-source and supply chain risk.

Visit Website ↗ + Add to Compare Claim This Company
65/100Incremental Innovator

Overview

Endor Labs builds static call graphs to determine whether vulnerable functions in dependencies are actually invoked by an application, suppressing alerts that are not reachable.

The platform also covers secrets, container scanning, malicious-package detection and SBOM generation, and is adding checks for AI-generated code.

Innovation Matrix Assessment

Innovation Velocity 7/10

Extended from SCA reachability to AI-code checks; steady product advance.

Operational Value 7/10

Reachability filtering reduces alert triage for AppSec teams.

Market Momentum 7/10

$93M Series B (Apr 2025) led by DFJ Growth; totals reported between $188M and $233M.

Category Disruption 6/10

Function-level reachability is a differentiated approach, though others offer reachability.

Real-World Efficacy 5/10

Noise reduction figures (80-92%) are vendor-derived; no independent tests found.

Enduring Relevance 7/10

Dependency risk grows with AI-generated code.

Why CISOs Should Care

Reduces dependency alert noise so developers fix only vulnerabilities that can actually be reached.

What Makes It Different

Language-specific call-graph analysis instead of package-level matching.

The Matrix Verdict

65/100 — INCREMENTAL INNOVATOR

Endor Labs is an Incremental Innovator near Meaningful, with differentiated technology and good funding but efficacy evidence that is largely vendor-reported.

Editorial Note: Claims vs. Verified Findings

The 80% and 92% noise-reduction figures are vendor claims. Funding is from press and research aggregators and totals conflict.

Sources