● ENDOR LABS / APPLICATION SECURITY● AURI LAUNCHED MARCH 2026● PACKAGE FIREWALL / BEFORE INSTALL● $93M SERIES B / APRIL 2025● ENDOR LABS / APPLICATION SECURITY● AURI LAUNCHED MARCH 2026● PACKAGE FIREWALL / BEFORE INSTALL● $93M SERIES B / APRIL 2025

Company profile / The software supply chain

The Security Alert That Never Needed Fixing

Endor Labs built a business around a costly question: does the vulnerable code ever run? As AI agents start writing and installing software, that question has moved from the backlog to the developer’s desk.

The vulnerability was real. The package was in the application. The ticket was in a developer’s queue. And then came the awkward question: could the application ever call the vulnerable part? In many software security programs, that question arrives after the ticket, the triage meeting, and perhaps the upgrade. Endor Labs built a company by moving it to the front.

The short version
  • Endor Labs sells tools that find risks in code, open source packages, containers and AI coding workflows.
  • Its distinguishing habit is to show whether risky code is reachable, with evidence a developer can inspect.
  • Zebra Technologies says this cut its non-actionable SCA alerts by 97%; that is one customer’s reported result.
  • Its newer products check package installs and record what coding agents do before a pull request exists.

A conventional software composition analysis tool compares an application’s dependency list with vulnerability databases. Useful, certainly. But a list of packages is not a map of an application. A library may contain a vulnerable function the application never uses. Its mere presence can still produce an alarming finding. For a security team, that is a question to investigate. For a developer receiving dozens of such findings, it can feel like an unpaid second job.

The flaw in the list

Varun Badhwar and Dimitri Stiliadis founded Endor Labs in Palo Alto in 2021 after confronting application security problems while working on Prisma Cloud at Palo Alto Networks. Their first wedge was open source software. Endor’s method builds a picture of an application’s dependencies and call paths, then asks whether the affected function is actually reachable from the code that ships. That does not prove a system is safe. It gives teams a much better reason to act on one finding before another.

Varun Badhwar, co-founder and CEO of Endor Labs
The founder
Varun Badhwar. His company’s rather profitable question for a scanner: show the route from the application to the risky function.

The distinction becomes plain at Zebra Technologies. The company had put SCA into developer pull requests, but the resulting alerts were too numerous and too poorly ranked to build much trust. Its security team ran a competitive evaluation and chose Endor Labs for reachability, developer workflow, and software bill of materials support. Zebra reports a 97% drop in non-actionable alerts within weeks. It also reports that catching problems earlier cut remediation effort by more than 60%. Those numbers come from a customer account, not a controlled comparison across all users.

“Endor Labs helped us cut through the noise and focus on what matters.”Michael Hammond / Zebra Technologies
97%Fewer non-actionable SCA alerts / Zebra
97.5%Noise reduction / Cursor
99%Noise reduction / Grip Security

Customer-reported outcomes from three separate case studies. The baselines and workflows differ.

Cursor, the AI coding tool maker, provides a second angle. Its team wanted to fix vulnerable dependencies without casually destabilizing a fast-moving product. Endor Labs says its approach helped Cursor reduce noise by 97.5% and make remediation more deliberate. Grip Security, another customer, replaced an SCA tool that had marked many findings reachable when its engineers found they were not. Grip reported a 99% reduction in noise. The arithmetic is attractive; the more interesting change is social. A developer is more likely to accept a security request when the request arrives with a call path rather than a warning label.

Then the developer became an agent

The original product addressed a familiar sequence: code is written, dependencies are chosen, scanners run, security sends findings. AI coding agents disturb that order. They can write code, add a package, execute an install script, and edit a deployment file in one session. The risky act may happen before review. Endor Labs’ answer has been to move its checks into the tools and moments where the act occurs.

AI coding assistant beside a code diff, with an Endor Labs security-check prompt
The coding assistant is already editing. The Endor Labs prompt asks for a security check before the change moves on.

In March 2026 the company introduced AURI, its security intelligence layer for developers and coding agents. Free local tools include a skills plugin, an MCP server, and a command-line interface. AURI checks code, secrets, and dependencies as work is happening; paid tiers add reachability, policies, reporting, and team controls. Endor Labs describes a code context graph that links files, functions, repositories, dependency paths, change history, and ownership. The aim is to let an automated reviewer judge an issue in the setting of the application, rather than issue a generic warning.

A second product, Package Firewall, changes the timing again. It can sit between developer machines or CI systems and public package registries, applying malware, vulnerability, and license rules before installation. This matters because malicious code can run in an install script; a later pull-request scan may arrive after the damage. Endor Labs also offers coding agent governance: an inventory of agents, models, MCP servers and skills, with policies and records of consequential actions. Its September 2026 extension to VS Code packages shows how far the supply-chain idea has traveled from the original dependency file.

The price of getting specific

The company sells subscriptions to security and engineering teams, with paid Core and Pro tiers and product licenses. Public pricing is by inquiry; the individual developer tier is free. Its customers range from software firms such as Cursor and Rubrik to larger organizations including Citi and Zebra. Enterprise purchasing is available through cloud marketplaces. Integrations with Microsoft Defender for Cloud and Wiz put its application findings beside cloud exposure data, so a team can ask whether vulnerable code is both reachable and deployed somewhere consequential.

Funding followed the expanding map. Endor Labs announced a $70 million Series A financing in 2023, but that figure included conversion of a previously announced $22 million seed; adding the two as separate cash raises would tell the wrong story. In April 2025 it raised $93 million in a Series B led by DFJ Growth. At the time, it reported 30-fold annual recurring revenue growth since the Series A and more than five million protected applications. The valuation and paid customer count were not disclosed in those announcements.

There is a limit to the central trick. Reachability helps rank known vulnerabilities in legitimate software. It is less comforting when a malicious package executes during installation, or when an agent has permission to run a dangerous command. That is why the firewall and agent controls make sense as additions, even if each adds more policy work for a buyer. The practical lesson for any security team is modest and portable: before sending a developer a ticket, attach the path by which the risk reaches the application. If the path begins earlier, at installation or an agent action, put the check there. A shorter queue is pleasant. A queue people believe is useful.