AI-powered application security platform for code risk prioritization
Endor Labs builds an AI-driven AppSec platform that combines static analysis (SAST/DAST), software composition analysis (SCA), and agentic workflows to identify and remediate code vulnerabilities. The tech stack—Go, gRPC, GraphQL, Bazel, Kubernetes, PostgreSQL—reflects a backend-heavy architecture optimized for parsing complex codebases at scale. Active adoption of Gemini and RAG signals a strategic pivot toward AI-assisted vulnerability triage and knowledge retrieval, directly addressing stated pain points around pinpointing critical risks in complex software.
Notable leadership hires: Sales Director
Endor Labs is an application security platform founded in 2021 and headquartered in Palo Alto, serving development and AppSec teams at companies ranging from startups to Fortune 500 enterprises. The product scans code—including legacy C++, modern monorepos, and AI-generated code—to surface vulnerabilities, prioritize remediation, and propose fixes with business context. Compliance frameworks supported include FedRAMP, PCI, SLSA, and NIST SSDF. The company is actively scaling: 19 engineering and sales roles posted in the last 30 days, with senior and principal hires concentrated in engineering, and a new Sales Director role indicating go-to-market acceleration.
Core platform built on Go, gRPC, GraphQL, and Bazel, deployed on Kubernetes with PostgreSQL. Analysis engines include SAST, DAST, and SCA. CI/CD via Jenkins and GitLab CI/CD. Recently adopting Gemini and RAG for vulnerability triage.
Endor Labs is an AppSec platform that uses AI agents and static/dynamic analysis to identify, prioritize, and remediate code vulnerabilities in human-written and AI-generated code. Specializes in supply chain security, open source risk, and SDLC compliance.
Other companies in the same industry, closest in size
Endor Labs's technology stack, projects, and hiring signals are inferred from public hiring and company data — career pages, public listings, and company web presence — then clustered and de-duplicated. Figures are estimates that refresh over time. Read our full methodology →
This is not an official vendor or customer list. It is a technology-adoption signal inferred from public data, intended for B2B research.