Endor Labs

Cybersecurity Dual-Use Technology Priority Signal Founded 2021

Last updated: Jul 31, 2026

Endor Labs provides an application-security platform for code written by people and AI agents, combining program analysis, reachability-based software composition analysis, SAST, secrets detection, container security, and AI-security governance. Its central value proposition is to reduce noisy findings by relating vulnerabilities and policy decisions to the code paths and business context that actually matter.

Visit Website

Company Overview

Endor Labs began with dependency and open-source software risk, but its current product is broader: an application-security platform spanning first-party code, third-party components, containers, secrets, AI models, and the agentic development workflow. Its technical foundation is code intelligence: the company says it builds a graph of code and dependencies and uses deterministic program analysis alongside AI agents to identify reachable or otherwise consequential issues. In the open-source portion of the platform, this includes direct and transitive dependency discovery, phantom-dependency detection, reachability analysis, malicious-package detection, SBOM and VEX generation, remediation guidance, and policy enforcement. For first-party code, the platform adds AI-native SAST, code review, secret detection, and automated or assisted remediation.

The commercial problem is credible and growing. Modern applications combine internal code, package-manager artifacts, containers, infrastructure, and increasingly AI-generated code and models. Conventional scanners can produce more findings than engineering teams can investigate, while a vulnerable package is not necessarily exploitable in the deployed application. Endor Labs sells precision and workflow fit: security and development teams can prioritize findings using execution context, integrate checks into source control and CI/CD, and apply guardrails to AI coding agents, MCP servers, and package intake. Its public pricing page describes free developer access alongside paid tiers with deeper scanning, enterprise integrations, policy, reporting, and workflow features, which suggests a land-and-expand motion but does not by itself prove conversion or retention.

Competition is intense. Snyk, Mend, Sonatype, Black Duck, JFrog, GitHub Advanced Security, Palo Alto Networks, and other platform vendors address overlapping combinations of SCA, SAST, secrets, containers, and developer workflow. Endor Labs therefore needs to defend a measurable advantage in reachability accuracy, language and build-system coverage, remediation quality, deployment flexibility, or operating economics. The company reports strong growth and customer usage in its April 2025 Series B announcement, including 30x ARR growth since Series A, 166% net revenue retention, protection of more than five million applications, and more than one million weekly scans; these are company-reported claims that require normal customer and financial diligence rather than independent confirmation.

The dual-use case is substantive but should be stated carefully. Software supply-chain security, dependency provenance, vulnerability prioritization, SBOM/VEX evidence, and secure CI/CD controls are relevant to defense contractors, critical-infrastructure operators, and government software programs as well as commercial enterprises. Reachability analysis can help teams focus remediation on exploitable paths, while audit-ready evidence and deployment options can support secure-development and compliance workflows. No public source reviewed here establishes a specific defense deployment or government contract, so the national-security thesis is strategic applicability rather than verified defense traction. Restricted-network operation, data handling, authorization evidence, export controls, and procurement readiness remain important diligence questions.

Endor Labs has credible technical and market momentum for a private company that has progressed to Series B and a publicly listed workforce above 200. The main question is durability: larger platforms can copy individual features, AI-assisted analysis can create its own false positives or data-governance concerns, and buyers may consolidate vendors. The company merits strategic attention because its core product addresses a high-consequence software risk and maps to both enterprise and mission-software assurance, but scores should remain tempered by private-company disclosure limits, competitive intensity, and the absence of independently verified defense adoption in the public record reviewed.

Dual-Use Assessment

Military & Commercial Applications

Endor Labs has substantive dual-use potential because dependency governance, code analysis, SBOM/VEX evidence, malicious-package detection, and secure development controls apply to commercial software and to defense, critical-infrastructure, and government software supply chains. Public sources support the applicability, but do not establish a specific defense contract or deployment.

Strategic Fit Assessment

Research priority signal

Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.

Endor Labs is a credible strategic-priority signal for a dual-use software-security thesis: it addresses an expensive enterprise problem, has progressed from seed and Series A to a disclosed Series B, and its code-intelligence approach maps to software assurance in sensitive environments. The company-reported growth and customer-use metrics are encouraging but not independently verified here. Diligence should test retention, gross margins, reachability precision, language coverage, AI-data handling, deployment options, and whether defense-relevant buyers can procure and operate the product. This is a strategic assessment, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

The company can help organizations understand which code, dependencies, containers, models, and agent actions create material software risk, then produce evidence and controls around that understanding. That is strategically relevant to mission software and critical infrastructure because supply-chain compromise and vulnerable dependencies can propagate across many systems. The value is highest if Endor Labs can operate under restricted data and network conditions and prove that its prioritization reduces remediation burden without hiding important risk.

Key Technologies

  • Deterministic program analysis and application code graphs
  • Function-level reachability analysis for direct and transitive dependencies
  • AI-assisted SAST, code review, triage, and remediation
  • Software composition analysis with phantom-dependency and malicious-package detection
  • AI model, coding-agent, MCP-server, and package governance
  • Secrets and container reachability scanning
  • SBOM, VEX, policy, and CI/CD workflow automation

Use Cases & Applications

  • Prioritize exploitable dependency vulnerabilities in enterprise applications
  • Find and govern hidden or transitive dependencies in complex builds
  • Review and remediate security flaws in AI-generated pull requests
  • Detect exposed secrets and risky container paths before deployment
  • Screen open-source packages and AI models for security and provenance risk
  • Generate SBOM and VEX evidence for product-security and compliance programs
  • Apply guardrails to coding agents, MCP servers, and package installation
  • Support software assurance for defense contractors and critical-infrastructure operators

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.

This record lists 6 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

Investor Lens

What this entry is

Private startup

Why it may matter

Endor Labs may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.

How an independent investor should read this

Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.

Evidence to verify

  • Verify current status
  • Verify traction
  • Verify cap table/funding
  • Verify technical claims
  • Verify regulatory/export-control issues
  • Verify customer concentration

Main investor questions

  • Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
  • What customer, revenue, product, and technical evidence supports the company story?
  • What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
  • Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
  • What evidence would change the thesis or show that the profile is stale?

What not to infer

  • Inclusion does not imply endorsement.
  • Inclusion does not imply allocation availability or current fundraising.
  • Scores do not indicate investment suitability or expected returns.
  • Strategic importance does not automatically imply venture return potential.

Diligence questions

  • What evidence verifies Endor Labs's current customer traction, deployment status, and revenue concentration?
  • Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
  • Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
  • How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
  • What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.

Need a diligence readout?

Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.