Secure and manage AI risks in the software supply chain

AI models and services are the new dependencies in your software supply chain. Continuously discover what's running in your code, assess each component for risk, and integrate governance into existing workflows — without slowing innovation.
Loved by security teams, painless for developers at:

How Endor Labs Governs AI in the Software Supply Chain

Detect AI models and services
Guides AI agents to write secure code from the start with real-time vulnerability intelligence.
Evaluate AI models for risk
Screen open source AI models from Hugging Face for security, licensing, and other operational risks.
Enforce guardrails
Set organization-wide policies governing the safe adoption and usage of AI models and third-party services.
My team is responsible for remediating vulnerabilities. Endor helps us do it quickly so we can deliver the most secure AI product possible.”
Travis McPeak
Security, Cursor (Anysphere)
Discover
Inventory your AI models and services
Keep a continuously updated inventory of third-party models and services that  keeps your SBOM audit-ready.
Discover AI models and services in your code
Build a comprehensive AI component inventory
Report the usage of AI models and services in your SBOM
Evaluate
Assess open source AI models for risks
Analyze AI models for licensing risks and malicious behavior. Get clear, actionable insights to keep your AI applications secure.
Help developers choose safe, high-quality AI models from sources like Hugging Face
Screen models on 50+ security, licensing, and quality signals
Flag models and services with risky practices
Enforce
Set policies to govern AI usage your AI models and services
Enforce your risk standards with a policy engine built on Open Policy Agent (OPA). Define rules once, apply them everywhere — from surfacing risks in development to blocking them in CI.
Use pre-built policies to flag risky AI models out of the box
Customize policies for security, legal, and operational needs
Warn developers or block builds on high-risk components
API-first platform that automates AI governance at scale
Flowchart showing integration paths from GitHub, GitLab, and PHP to Slack and Microsoft platforms, with a C# icon connected to Slack.

Your Tools, Your Languages
All Secured

Lean how Endor Labs fits into your ecosystem.
Flow diagram connecting software development tools and platforms including .NET, JetBrains, GitHub, Google, and Vercel.

FAQs

What is the Developer Edition?

Developer Edition is a free tier that gives individual developers access to the AURI MCP Server and CLI. It includes SAST, SCA, secrets detection, and malicious open source package detection — the core scanning capabilities you need to write secure code from day one.

What does the MCP Server actually do?

The MCP Server connects AURI's security intelligence to your AI coding assistant. When you or your AI writes code, the server scans for vulnerabilities, insecure patterns, hardcoded secrets, and risky dependencies in real time — then helps fix them inline, right where you're working.

Which editors and tools are supported?

The MCP server works with Cursor, VS Code, Windsurf, Claude Code, and any MCP-compatible client. It also integrates with asynchronous AI tools like GitHub Copilot and OpenAI Codex for agent-driven workflows.

Is Developer Edition really free?

Yes. Developer Edition requires no credit card and no paid subscription. You authenticate once via GitHub, GitLab, or Google and you're up and running. There's no trial period — it's free to use, forever.

What kinds of scans does it run?

Developer Edition includes four core scan types: static application security testing (SAST) for code-level issues, software composition analysis (SCA) for dependency vulnerabilities, secrets detection for exposed credentials, and malicious package detection to catch supply chain attacks before they reach your environment.

Does my code leave my machine?

No. All scans run locally. The MCP Server accesses AURI's vulnerability database for intelligence (read-only), but your source code stays on your machine and is never uploaded to Endor Labs' platform.

How is this different from other free security MCP servers?

Most free MCP servers focus on code scanning alone. The AURI Developer Edition is the only free offering that combines code scanning (SAST and secrets) with full supply chain security — including CVE detection and malicious open source package identification in your dependencies.

Do I need to install anything besides the MCP Server?

No. The MCP Server fetches everything it needs on demand, including the Endor Labs CLI. There's no separate installation step, no pre-configuration, and no dependency management required to get started.

Can I use Developer Edition with my team?

Developer Edition is designed for individual developers. If your team needs shared policies, centralized reporting, or platform-level visibility, Endor Labs offers team and enterprise tiers that build on the same scanning engine with collaboration and governance features.

What's the difference between Developer Edition and the full Endor Labs platform?

Developer Edition gives you the core scanning tools — MCP Server and CLI — with default security policies and local-only results. The full platform adds a web UI, custom policies, centralized reporting, team management, and integrations with SIEM and vulnerability management tools for organization-wide security programs.