AI-powered application security platform for code risk prioritization
Endor Labs builds an AI-driven application security platform focused on reducing noise and accelerating remediation for development teams. The stack—Go, gRPC, Kubernetes, cloud infrastructure (AWS/GCP/Azure), plus observability (Prometheus, Grafana, Mimir, Pyroscope)—reveals a backend-heavy architecture designed for scale. Active pain points around scaling backend infrastructure, cost optimization, and zero-downtime migrations signal a company managing real production load. Hiring is decelerating (5 roles in last 30 days) after earlier growth, with seniority skewed senior/principal, suggesting a shift from hiring velocity to execution depth.
Endor Labs is an application security platform launched in 2021, based in Palo Alto. The product uses AI agents and open-source security intelligence to help engineering and AppSec teams identify, prioritize, and fix code vulnerabilities faster than traditional scanners. Coverage spans software composition analysis (SCA), SAST, container scanning, and AI-generated code detection. The platform supports legacy codebases (C++, Maven, Gradle) and modern monorepo structures (Bazel), with compliance alignment to FedRAMP, PCI, SLSA, and NIST SSDF. The 51–200 person org is sales-supplemented (4 active sales roles) and engineering-led, with active infrastructure and demand-generation initiatives targeting SMB and mid-market accounts.
Endor Labs runs on Go, gRPC, GraphQL, and Kubernetes. Cloud hosting spans AWS, GCP, and Azure. Observability is built on Prometheus, Grafana, Mimir, and Pyroscope. Infrastructure-as-code tooling includes Terraform and OpenTofu. IDE integrations use TypeScript with Language Server Protocol and Model Context Protocol.
Core projects include software supply chain security and software composition analysis products, cloud-scale backend infrastructure, IDE plugins for security insights, full-cycle sales process buildout, demand generation, and observability platform scaling. Infrastructure challenges center on zero-downtime cloud migrations and cost optimization.
Other companies in the same industry, closest in size