Listing Thumbnail

    Endor Labs AppSec Platform

     Info
    Sold by: Endor Labs 
    Ship secure software by default, by giving security teams clarity on what matters
    4.8

    Overview

    Endor Labs is the AppSec platform built to secure modern software - fast, open source-driven, and increasingly AI-generated. Our platform brings together intelligent code reviews, code scanning, risk-based prioritization, and efficient remediation in one complete graph of the software estate, giving teams visibility into change, software risks across both open source, AI and human generated code, and delivering clear, actionable fixes. Everything is driven by flexible policies and APIs that integrate to scale with development.

    Highlights

    • Endor Labs graphs your entire software estate, understanding how your first-party code interacts with dependencies like OSS packages, containers, and AI models. Endor Labs' consolidated security code scanning (SCA, SAST, container scanning, secret scanning, malware analysis, and AI model discovery) leverages this context to provide accurate, correlated, and actionable security findings.
    • Endor Labs secures AI-generated code and boosts AppSec productivity through security feedback directly to coding agents in IDEs, multi-agent pull request reviews, and model usage governance.
    • Endor Labs streamlines open-source remediation while keeping builds stable. First, Upgrade Impact Analysis inspects every code path to see whether moving to a secure library version will break direct or transitive dependencies. When the analysis shows zero functional conflicts, developers can upgrade with confidence and close the CVE immediately.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Endor Labs AppSec Platform

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Description
    Cost/unit
    (10) EL-CODE-PRO
    Endor Labs (10) EL-CODE-PRO
    $7,200.00
    (10) EL-OSS-PRO
    Endor Labs (10) EL-OSS-PRO
    $12,960.00

    Vendor refund policy

    All fees are non-cancellable and non-refundable except as required by law.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Support

    Vendor support

    Please contact our Support Team via support@endor.ai . Clients can expect direct support from our team once the product has been purchased.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.8
    9 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    89%
    11%
    0%
    0%
    0%
    0 AWS reviews
    |
    9 external reviews
    External reviews are from G2 .
    Security and Investigations

    Easy SCA Integration with Clear, Actionable Vulnerability Insights

    Reviewed on Mar 18, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Endor Labs is how easy it is to integrate their SCA scans into our repositories and get clear visibility into open-source vulnerabilities. The tool provides actionable insights that help us address security risks early in the development cycle, making our workflow more secure and efficient.
    What do you dislike about the product?
    The tool is overall very helpful, but one area for improvement could be faster scan times on larger repositories. While the results are accurate and detailed, optimizing performance for bigger projects would make the experience even smoother.
    What problems is the product solving and how is that benefiting you?
    Endor Labs helps us identify and manage vulnerabilities in our open-source dependencies early in the development process. By providing clear visibility and actionable insights, it allows our team to address security risks before they make it into production, improving overall code security and compliance. This has helped us save time, reduce potential security incidents, and maintain confidence in the software we ship.
    Computer & Network Security

    Great product, delivered on outcomes

    Reviewed on Mar 12, 2026
    Review provided by G2
    What do you like best about the product?
    Easy to use, reduced our FPs significantly, helped democratize the VM program into engineering directly. Support is quick and efficient. UI is intuitive. Deployment was easy and quick.
    What do you dislike about the product?
    Very little, I enjoy the product very much. Only callout would be to have the Slack threat intel alerts be customer specific rather than global.
    What problems is the product solving and how is that benefiting you?
    Reducing false positives and noise from third party vulns that don't affect us in practice. Reduced our security related engineering efforts without hurting the risk reduction outcomes.
    Muhammad S.

    Leader in the SCA technology

    Reviewed on Dec 08, 2025
    Review provided by G2
    What do you like best about the product?
    Reachability analysis feature, detailed and useful recommendations, higher accuracy, flexibility of integration and usage, user friendly UI.
    What do you dislike about the product?
    Endor Labs need to make more of the API capabilities available in the UI.
    What problems is the product solving and how is that benefiting you?
    Open source vulnerability and license risks in the software supply chain and generation and management of SBOM reports.
    Information Technology and Services

    Took the SCA scans to whole another level with their reachability analysis

    Reviewed on Oct 23, 2025
    Review provided by G2
    What do you like best about the product?
    We appreciate Endor Labs for several reasons that have significantly benefited my team and me. Their support team is always helpful, promptly assisting us whenever we encounter obstacles and even implementing feature requests that directly address our issues. This active and responsive customer support is crucial in our daily operations. The Reachability Analysis feature has been a lifesaver, enabling our engineers to allocate their efforts effectively and focus only on impactful upgrades, which prevents the unnecessary use of vulnerable functions from open-source libraries.

    Endor Labs' solution gives our team confidence and speed in tackling supply chain security concerns, as it ensures that all libraries are thoroughly scanned for vulnerabilities. Their centralized dashboard is incredibly convenient for quickly checking the usage of dependencies in our code, drastically reducing the time spent on security checks. Their innovative approach to Software Composition Analysis (SCA) is impressive; they prioritize actionable alerts based on reachability, thereby lessening the overwhelming number of findings we might typically have to sift through.


    Moreover, setting up Endor Labs was straightforward, which made the initial integration almost seamless. Overall, their extended support and impactful innovations in addressing SCA findings serve as a compelling reason for us to continue using and recommending Endor Labs.
    What do you dislike about the product?
    Nothing so far, they have been good at what they are doing to security landscape.
    What problems is the product solving and how is that benefiting you?
    Endor Labs scans and vets open-source libraries for security, preventing supply chain attacks and offering a centralized dashboard to streamline dependency management. It saves engineers' time with Reachability Analysis, improving efficiency and prioritizing critical issues.
    James K.

    Jellyfish Enables Data-Driven AppSec with Endor Labs

    Reviewed on Aug 15, 2024
    Review provided by G2
    What do you like best about the product?
    Endor Labs is, in a good way, simplistic. The data we care about is quickly available to us. Our prior SCA tooling reachability analysis wasn't robust and we couldn't determine which vulnerabilities could truly threaten our business, so we couldn't manually research reachability or perform upgrades without knowing if they mattered. Our risk models were overly aggressive to compensate, which has now been dramatically improved by using Endor Labs.
    What do you dislike about the product?
    Endor Labs is a new entrant into the SCA space, and has only been around for a short period of time (2022). There is always a risk of engaging with a critical vendor that you depend on for Security and Compliance, when they are a relatively new business.

    We are happy with all of their current features.
    What problems is the product solving and how is that benefiting you?
    Software Composition and reachability analysis. Our prior tooling had limitations in reachability, which Endor has solved for.
    View all reviews