We're thrilled to announce Endor Labs has been recognized as a Visionary in the 2026 Gartner Magic Quadrant for Software Supply Chain Security. This is the first Magic Quadrant Gartner has published for the category. For us, the work started well before the category had a name.
In early 2024, Endor Labs researchers led the creation of the OWASP Top 10 for Open Source Software Risks, the first community standard for what open source risk actually looks like, two years before this Magic Quadrant existed. A dedicated Magic Quadrant now confirms what we've believed since Endor Labs was founded in 2021: most of the code your developers ship won't be written by them, and securing where that code comes from is its own discipline. We're proud to have helped define the category, and to keep pushing it forward.
Gartner places Visionaries based on completeness of vision: a view of where the market is going and a roadmap to match. We built Endor Labs for the world that's arriving, not the one of the last decade. As AI introduces new dependencies into the software supply chain, from coding agents and models to MCP servers and skills, we've built the controls to govern them. And as attackers adopt AI to generate exploits, we’re helping defenders stay ahead. Every leap in frontier model capability, Mythos included, raises the same question from boards and security teams: what happens when attackers get this leverage?
They already have it. Exploits that took months now take hours, and malware campaigns increasingly target the packages and workflows AI agents depend on. If that makes you nervous, you're paying attention. Our answer is to give defenders the same leverage, grounded in evidence rather than fear.
From SCA to security for AI coding
When we launched in 2022, we started with a contrarian bet: software composition analysis was broken not because it found too little, but because it found too much. Legacy SCA flags every CVE in your dependency graph whether or not your application can ever invoke the vulnerable code. The result is backlogs of 10,000+ findings that engineering struggles to act on.
Since then we've expanded across the supply chain: a package firewall that evaluates over 150 risk signals and blocks malicious packages at install time, AI model governance covering 50 risk metrics on every Hugging Face model, SCA for C/C++, compliance guidance for PCI DSS 4.0 and the EU Cyber Resilience Act, the first 3PAO-endorsed approach for using function-level reachability to reduce FedRAMP ConMon costs, and Endor Outpost for organizations with strict sovereignty requirements. The same controls apply whether a package is installed by a developer or by an AI coding agent. That last part is no longer a nice-to-have. It's the new front line.
Pioneering full-stack reachability
Reachability is the idea we're most associated with, and for good reason. Function-level reachability analysis traces whether your application can actually invoke vulnerable code, across first-party code, open source dependencies, and container images, in more than 40 languages. For our customers, that cuts SCA noise by an average of 92%.
As Travis McPeak at Cursor put it: "Over 97% of vulnerabilities flagged by our previous tool weren't reachable in our application. Endor Labs shows the few impactful vulnerabilities, so we can patch quickly, focusing on what matters."
Every finding ships with evidence: the call path, the data flow, and the reachability proof. No black-box verdicts. That evidence model is also what makes our findings consumable by AI agents, which need deterministic context to act on security decisions, not a severity score and a shrug.
Patching and upgrade impact analysis
Finding real risk is half the problem. The other half is fixing it without breaking production. Upgrade impact analysis shows exactly what will break before you open the PR, turning guess-and-test remediation into an informed decision. And when an upgrade is too risky or impossible, Endor Patches delivers drop-in, security-only patches for hard-to-upgrade libraries and end-of-life software.
Gartner specifically recognized Endor Patches as a strength in its assessment, noting that it "helps customers to reduce the risk of introducing breaking changes into an application." Together, these capabilities are why customers see 6x faster CVE remediation.
The future of software development
Magic Quadrants evaluate what vendors have already shipped. Our eyes are on what's next.
Software development is being rebuilt around semi-autonomous agentic pipelines that write and deploy code with minimal human checkpoints. In that world, the "scan after build" model collapses. Security has to become intelligence embedded where code gets written: helping agents pick safe dependencies, blocking poisoned packages aimed at agentic workflows), and giving agents the deterministic context to fix what matters fast.
That's what we're building with AURI, the security harness for agentic development, on top of the same code context graph that powers our function-level reachability and supply chain intelligence. As engineering changes, the supply chain changes with it. So do we.
We're honored by the recognition, and more grateful for the customers and community who push us to be better every day. If you want to see what a supply chain security program built for the AI era looks like, book a demo and we'll show you.
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.
What's next?
When you're ready to take the next step in securing your software supply chain, here are 3 ways Endor Labs can help:









