The Endor Labs Experience





Our FedRAMP environment requires more rigor than you would normally get in any other kind of product release, with near zero tolerance for vulnerabilities. Endor Labs’ reachability analysis and consolidated findings reduced the number of true positives requiring remediation, which is a huge time- and money-saver.”
Without the tedium and minutia of tracking down individual items that might not matter, we can focus on the remaining vulnerabilities that would impact customers and our FedRAMP compliance."
Endor Labs catches malicious dependencies before we even hear about a CVE. Their security research team goes beyond automated detection to help us verify the threat so we can act early and decisively.”
We recently removed Checkmarx in favor of Endor. I like them as they allow us to eliminate the need to fix vulns when they are on unused code paths (a hard to resolve problem with SBOM based scanners). When we used Snyk (prior to Cx), we were overwhelmed with all the unrelated findings. Endor scans are also much faster than Cx (and no strict parallelism limits that stall CI) which we appreciate. Their support teams have been great to us and got us very early warning of the latest NPM malware issues (~6h before Cx notified us)."
Endor Labs' exceptional timeliness and proactive communication during the recent spate of npm malware attacks allowed us to expedite our internal investigation and remediation. I've never experienced that level of support from a vendor before."
“When it comes to malware attacks, Endor Labs helps me sleep better at night because I know we can quickly figure out whether we’re impacted, and if not, move on with our day.”
If it wasn’t for reachability, this program would fail. A little extra effort up front to onboard is worth the deep application context we use every day."
Reachability is table stakes these days. That's why we switched to Endor recently which actually builds the entire call graph and is incremental. Its comments are informational so for level1 triage can be done by the devs. Moreover, now we can actually do SLA and ticketing which is always a struggle with os Trivy."
























