SAST and Secret Scanning

Automate code security so you can get on with your day

Whether human—or AI—generated, we protect your applications by discovering risks including CWEs, architectural changes, and secrets.
Loved by security teams, painless for developers at:

How it works

Reduce code risks
Scan your first party code for CWEs and provide developers with critical context, all within their existing workflows.
Discover architectural changes
Use AI to automatically find material changes to your security architecture that warrant human review.
Stop secret leaks
Help developers identify and remove sensitive information before it can be exploited.
Protect
Scalable SAST, no expertise required
Endor Labs is a modern SAST that’s easy to use, has fewer false positives, and enables preventing risk before code ships.
Reduce MTTR: Developers see just the findings that are relevant to their application, and each finding includes the snippet where a CWE was found and the rule used to identify it. They’ll know what to fix and why, all without any intervention from the security team.
Save time: Simplified rule writing means you don't need a dedicated resource to write rules or time to upskill the team around a niche language.
Integrated experience: From creating policies to viewing findings, use the same UI and CLI for all your AppSec scanners.
Prioritize 
Never miss a critical security change
Engineering teams make numerous code changes every day, and security-impacting changes are easy to miss in the noise. Endor Labs uses AI to automatically review pull requests with the context and care of a real team:
Cut through the noise: Automatically surface material changes to your security architecture, such as modifications to authentication methods, database schema, or cryptography, and flags pull requests that warrant human review 
Get context fast: Understand what changed and why, without reading every line or knowing the codebase inside-out.
Take action: Loop in the right code owners to follow up on changes and guide next steps where it matters most.
Prevent
Consolidate secret scanning with SAST and SCA
No matter which SCM you’re using, help developers identify and remove sensitive information before it can be exploited.
Stop leaks at the source: Continually scan during pre-commit checks, at the time of commit, and in your production code.
Reduce false positives: Save developer time by identifying active, potentially exploitable, and hard-coded secrets.
Customizable rules: Configure rules to check and validate custom secrets.
Flowchart showing integration paths from GitHub, GitLab, and PHP to Slack and Microsoft platforms, with a C# icon connected to Slack.

Your Tools, Your Languages
All Secured

Lean how Endor Labs fits into your ecosystem.
Flow diagram connecting software development tools and platforms including .NET, JetBrains, GitHub, Google, and Vercel.

FAQs

What is the Developer Edition?

Developer Edition is a free tier that gives individual developers access to the AURI MCP Server and CLI. It includes SAST, SCA, secrets detection, and malicious open source package detection — the core scanning capabilities you need to write secure code from day one.

What does the MCP Server actually do?

The MCP Server connects AURI's security intelligence to your AI coding assistant. When you or your AI writes code, the server scans for vulnerabilities, insecure patterns, hardcoded secrets, and risky dependencies in real time — then helps fix them inline, right where you're working.

Which editors and tools are supported?

The MCP server works with Cursor, VS Code, Windsurf, Claude Code, and any MCP-compatible client. It also integrates with asynchronous AI tools like GitHub Copilot and OpenAI Codex for agent-driven workflows.

Is Developer Edition really free?

Yes. Developer Edition requires no credit card and no paid subscription. You authenticate once via GitHub, GitLab, or Google and you're up and running. There's no trial period — it's free to use, forever.

What kinds of scans does it run?

Developer Edition includes four core scan types: static application security testing (SAST) for code-level issues, software composition analysis (SCA) for dependency vulnerabilities, secrets detection for exposed credentials, and malicious package detection to catch supply chain attacks before they reach your environment.

Does my code leave my machine?

No. All scans run locally. The MCP Server accesses AURI's vulnerability database for intelligence (read-only), but your source code stays on your machine and is never uploaded to Endor Labs' platform.

How is this different from other free security MCP servers?

Most free MCP servers focus on code scanning alone. The AURI Developer Edition is the only free offering that combines code scanning (SAST and secrets) with full supply chain security — including CVE detection and malicious open source package identification in your dependencies.

Do I need to install anything besides the MCP Server?

No. The MCP Server fetches everything it needs on demand, including the Endor Labs CLI. There's no separate installation step, no pre-configuration, and no dependency management required to get started.

Can I use Developer Edition with my team?

Developer Edition is designed for individual developers. If your team needs shared policies, centralized reporting, or platform-level visibility, Endor Labs offers team and enterprise tiers that build on the same scanning engine with collaboration and governance features.

What's the difference between Developer Edition and the full Endor Labs platform?

Developer Edition gives you the core scanning tools — MCP Server and CLI — with default security policies and local-only results. The full platform adds a web UI, custom policies, centralized reporting, team management, and integrations with SIEM and vulnerability management tools for organization-wide security programs.