Endor Labs
AppSec platform securing software supply chains & AI-generated code

Endor Labs
AppSec platform securing software supply chains & AI-generated code
450+ Data Points Per Product and Company
Track competitive landscapes, evaluate vendor risk for investments, or find the right security stack for your clients.
Endor Labs Description
Endor Labs provides an application security platform focused on securing software supply chains, from open source dependencies to AI-generated code. The company was founded in 2021 in Palo Alto, California by Varun Badhwar and Dimitri Stiliadis, who previously led Prisma Cloud at Palo Alto Networks. The platform addresses security challenges in modern software development by helping teams identify, prioritize, and fix vulnerabilities in their code. It uses deep program analysis and reachability-based software composition analysis (SCA) to determine which vulnerabilities actually matter based on whether vulnerable code paths are reachable in production. This approach reduces alert fatigue by focusing on exploitable issues rather than all theoretical vulnerabilities. Endor Labs expanded from its initial focus on SCA to a comprehensive AppSec platform that covers the entire software development lifecycle. The platform provides automated remediation capabilities, extensive dataset coverage, and integrates with CI/CD pipelines. It addresses security concerns across open source dependencies, internally developed code, microservices architectures, and AI-generated code. The company raised a $70 million Series A in 2023 and a $93 million Series B in 2025, backed by investors including DFJ Growth, Lightspeed Venture Partners, Coatue, and Dell Technologies Capital. Endor Labs has offices in Palo Alto, Delft (Netherlands), and Bengaluru (India). The platform serves engineering and security teams dealing with the accelerating pace of software development driven by code reuse, automation, and AI coding assistants.
POPULAR
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox