Egnyte Accelerates FedRAMP & Protects Engineering Velocity with Endor Labs
Egnyte is a leading provider of cloud content collaboration and governance solutions. Pursuing FedRAMP authorization, the product security team adopted Endor Labs to add reachability-grade evidence that its existing SCA stack could not produce, without expanding headcount.

- Accelerated our FedRAMP authorization program and DoD Moderate Equivalency under DFARS 252.204-7012
- 91% noise reduction
- 1.67x improvement in security engineering efficiency
- Scaled through shift-left and automation
Security teams don't scale linearly with engineering. If your operating model requires a security engineer in the loop on every finding, you've already lost the velocity argument before the conversation starts. Our job is to put evidence directly in front of the developer with enough fidelity that they can act on it without our involvement. Reachability analysis is the piece that made that credible at our scale.”

Security is part of Egnyte's DNA. As a content collaboration platform, customers expect their data to be protected to the highest standard, and meeting that bar is a competitive advantage. Egnyte already complies with SOC 2, ISO 27001, HIPAA, and other frameworks, and in 2024 the company committed to pursuing FedRAMP authorization to expand its federal footprint.
The security organization evaluated how its programs and processes would need to evolve to meet the strict standards FedRAMP is known for. One of the greatest challenges — and one that could become a blocker to our FedRAMP authorization timeline and ROI on that investment — was the volume of false positives produced by existing software composition analysis tools.
“To meet the rigorous FedRAMP requirements while maintaining engineering velocity, we needed to evolve our existing workflows. Endor Labs provided the specialized reachability analysis we needed to scale our patch management without expanding the team.”
– Maciej Markiewicz, Senior Security Engineering Manager @ Egnyte
The top challenges came from the volume of false positives produced by SCA tooling. This volume would be difficult to satisfy in a FedRAMP assessment process and would not scale alongside existing engineering workflows without a significant increase in headcount.
- Reachability as the next layer: The team had already built sophisticated custom tooling for prioritization using EPSS and CISA KEV. The next leap — required for FedRAMP cadence and developer trust — was function-level reachability evidence, which sits outside what traditional SCA was designed to produce.
- Developer friction: Egnyte wanted to provide the most precise information possible, directly where developers work every day: Jira and GitLab. This was done to reduce developer friction resulting from several factors, including learning a new SCA tool, dealing with a high volume of tickets, spending time on prioritization, and synchronizing issue status between tickets when some issues were resolved through a grouped fix, but individual tickets remained open.
- More flexibility: Egnyte had already built its own abstraction layer between FedRAMP ConMon requirements and the developer workflow. The team needed a partner willing to integrate into that model — not a vendor that would force Egnyte to bend its workflows to a generic compliance template — and a tool flexible enough to bridge agile engineering against non-agile regulatory cadences.
The team knew they could not rely on a high volume of findings and manual workarounds as evidence of false positives. Egnyte could have dedicated more resources to upgrading libraries that likely contained false positives, potentially spending more in engineering hours than the expected FedRAMP revenue justified, but instead looked for a new security partner that was more flexible, experienced, and aligned with their expectations.
Ultimately, these compounding challenges led Egnyte to conclude that they needed an AppSec platform capable of supporting the new maturity targets. Requirements for a new platform included:
- Developer-friendly: The platform had to be optimized to provide the least disruptive experience possible for developers. This included the ability to consolidate findings by library to reduce the volume of Jira tickets. The solution could not interrupt developers in their work or require a "revolution" in their working culture. It needed to deliver data directly to developers through easy integration with existing workflows and tools, including Jira and Gitlab.
- High-fidelity findings: Findings needed to contain evidence indicating whether vulnerable functions were reachable in production-relevant code paths, so the team could reliably identify and prioritize these findings compared to findings without clear proof of reachability.
- FedRAMP compliance experience: Egnyte needed a vendor that understood FedRAMP continuous monitoring challenges and had experience providing evidence that could support 3PAO review.
Why Endor Labs Won
Egnyte chose Endor Labs as their AppSec platform because of three primary factors:
- Reachability analysis: Endor Labs could show whether vulnerable functions were reachable through a call graph, giving Egnyte a much more precise way to separate actionable findings from noise.
- Deep FedRAMP positioning: Endor Labs cited prior 3PAO evaluations of their reachability analysis as supporting evidence for adjusted severity disposition in ConMon — a claim we weighted heavily in evaluation.
- Strong, responsive partnership: When it became evident that a traditional pipeline integration wouldn’t work for Egnyte, Endor Labs built managed scanning for GitLab that enabled the team to apply consistent policies across all repositories.
“Reachability analysis at our scale is a hard problem. It's the reason most platforms can't deliver it credibly for an organization our size. Endor Labs is the first platform we evaluated that met our scale and fidelity requirements without cutting corners.”
– Pawel Malita, Staff Product Security Engineer @ Egnyte
Egnyte's use of Endor Labs has resulted in significant business outcomes, including support for our FedRAMP authorization program. The impact has primarily come from streamlining complex compliance processes, preserving (and in some areas accelerating) developer velocity, and drastically reducing time spent on manual security triage and governance.
Operating ConMon under FedRAMP
Egnyte utilized Endor Labs to build sophisticated automation workflows that streamline its entire vulnerability management process. This automation integrates data via API to standardize security tickets and govern remediation across the organization. It helps the team proactively monitor FedRAMP SLA adherence for every ticket. The system generates monthly FedRAMP ConMon reports, with human review focused on exception cases and final attestation before submission.
“ConMon at FedRAMP scale does not work if every finding requires manual security judgment. Human judgment is too expensive a resource to spend on findings automation can dispose of. Endor Labs added the reachability evidence layer on top of the EPSS, KEV, and internal exploitability signals we already operate.”
– Dawid Balut, VP of Security @ Egnyte
91% noise reduction and improved developer trust
Today, only 9% of Egnyte’s findings are reachable at the function level, and Egnyte can group findings by library and drive the number of developer-facing tickets even lower. This reduction has several cascading effects.
First, developers have more confidence in Endor Labs findings because they can review the call graph and see how a vulnerable function may be called. Next, because the reachable subset is much smaller and developers do not have to spend as much time debating findings, they can move more quickly to remediation.
With a more efficient process, the mean time to remediation (MTTR) decreased by 70% and continues to improve. Automated workflows detect when an upgrade is complete, allowing the system to automatically close the corresponding Jira ticket. Together, these factors help Egnyte consistently remediate vulnerabilities within FedRAMP’s aggressive SLAs.
“Security teams don't scale linearly with engineering. If your operating model requires a security engineer in the loop on every finding, you've already lost the velocity argument before the conversation starts. Our job is to put evidence directly in front of the developer with enough fidelity that they can act on it without our involvement. Reachability analysis is the piece that made that credible at our scale.”
– Dawid Balut, VP of Security @ Egnyte
1.67x more efficient security engineering
Security engineering teams are frequently stretched to the limit, and Egnyte is no exception. By automating the typical overhead that comes with FedRAMP ConMon, Endor Labs acted as a force multiplier for Egnyte. This new engine allowed the team to reallocate approximately 40% of their security engineering resources from manual triage to high-impact strategic initiatives like the Security Champions program.
“By automating manual tasks, we can focus more on mid- and long-term goals and projects. We now focus on high-leverage projects like our Security Champions or further expanding platform security capabilities. Focusing on such projects helps us achieve better efficiency in implementing Secure SDLC standards, as well as driving a more effective shift-left.”
– Maciej Markiewicz, Senior Security Engineering Manager @ Egnyte
Scaling through shift-left, automation, and the champions program
The deployment of Endor Labs and the automation surrounding it allowed Egnyte to pivot from reactive manual work to high-leverage, long-term goals: building a robust automated security platform and driving a true shift-left culture.
By creating an abstraction layer that translates FedRAMP ConMon requirements into standardized Jira tickets, the security team moved security into the development pipeline where engineers already work. This automated platform does not just identify reachable vulnerabilities; it proactively monitors remediation and verifies remediation in the build pipeline before updating ticket state, supporting consistent FedRAMP SLA tracking.
To scale these high standards, Egnyte utilizes its Security Champions program as a force multiplier, expanding the team's capacity to detect vulnerabilities early in the lifecycle and maintain practical standardization across more than 350 engineers. The Champions program also extends Endor Labs' value beyond CVE triage into broader supply-chain hygiene decisions.
“A Champion recently flagged a dependency that scored poorly on Endor Labs' package-quality signals; no CVE involved. They reviewed the alternatives Endor Labs surfaced and replaced the package before it became a security problem. Engineering owning supply-chain hygiene with evidence they don't have to escalate to us is the operating model we've been building toward.”
– Pawel Malita, Staff Product Security Engineer @ Egnyte



.avif)
