Softprom Becomes Official Partner of Endor Labs to Deliver Software Supply Chain Security in Azerbaijan
News | 18.08.2026
The partnership gives engineering and security teams in Azerbaijan local access to a platform that shows which vulnerabilities are actually exploitable — instead of flooding them with alerts.
BAKU, Azerbaijan — August 20, 2026 — Softprom, a value-added IT distributor operating since 1999, today announced the signing of a partnership agreement with Endor Labs, an application security company named a Visionary in the inaugural 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security. Under the agreement, Softprom becomes an official partner of Endor Labs, supplying the platform to companies in Azerbaijan and providing demos, trials, and pre-sales support through its certified engineers.
The partnership addresses a challenge familiar to nearly every development organization. A modern application consists largely of code the team did not write: open source libraries, their dependencies, and, increasingly, code produced by AI coding agents. Traditional security scanners flag every vulnerable package they detect — including those the application never calls — leaving engineers to triage hundreds of theoretical findings. At the same time, genuinely exploitable ones wait in the queue.
Endor Labs takes a different approach. The platform evaluates every open source package against 150+ risk factors and applies function-level reachability analysis to determine whether the application actually invokes vulnerable code. The result is an 80–92% reduction in false positives compared to traditional SCA tools: security teams receive a short, evidence-backed list of what requires action rather than thousands of raw alerts.
The same analysis extends across the software lifecycle. Endor Labs scans container images and automatically removes unreachable packages from the remediation queue, detects malicious open source packages before they enter the build, and secures AI-generated code. For organizations facing regulatory or contractual requirements, the platform produces audit-ready SBOMs, VEX documents, and provenance attestations, with compliance mapping for frameworks such as FedRAMP and PCI DSS 4.0 — turning what is often a weeks-long manual exercise into an automated report.
«Every AppSec engineer knows the feeling when the scanner report is longer than the codebase, and somewhere in it are the three findings that actually matter. Endor Labs starts from the engineer's question — what do I fix first? — and answers it with evidence. We are ready to run demos and pilots so that teams in Azerbaijan can see the difference on their own code, not on slides.»
Endor Labs holds SOC 2 Type II certification; its customers include Cursor, Dropbox, and Atlassian. The platform integrates natively with GitHub Actions, GitLab CI, and other CI/CD pipelines, allowing security checks to run where developers already work.
Demos, trials, and pre-sales consultations are available through Softprom at softprom.com/vendor/endor-labs.
About Endor Labs
Endor Labs is the agentic application security platform for teams that refuse to compromise between speed and security. Endor Labs helps teams identify, prioritize, and fix vulnerabilities across code, open-source dependencies, and container images. With agentic reasoning, deep program analysis, automated remediation, and unmatched coverage, Endor Labs empowers modern engineering and security teams to move fast without compromise. Learn more at endorlabs.com.