About company

Endor Labs — an application security and software supply chain security (SSCS) platform that secures open source dependencies, CI/CD pipelines, container images, and AI-generated code. Softprom is an official partner of Endor Labs and supplies the platform to companies in Azerbaijan, providing demos, trials, and pre-sales support.

Built by the team that created Prisma Cloud at Palo Alto Networks, Endor Labs evaluates every open source package against 150+ risk factors and applies function-level reachability analysis — reducing false positives by 80–92% compared to traditional SCA tools. The platform holds SOC 2 Type II certification and is used by OpenAI, Dropbox, Citi, and Atlassian.

Core Capabilities of Endor Labs

Reachability-Based SCA

Function-level analysis shows whether vulnerable code is actually called — 80–92% fewer false positives than traditional SCA.

CI/CD & Pipeline Security

Native integrations with GitHub Actions, GitLab CI, and other pipelines; build integrity verification of artifacts.

Container Image Scanning

Reachability-based scanning of container images: unreachable packages are moved out of the remediation queue automatically.

AI Code & Malware Protection

Protection for AI-generated code and detection of malicious open source packages before they enter your supply chain.

What the Platform Delivers

Automated Remediation

Endor Patches and upgrade impact analysis show exactly what breaks before you update — remediation without a patching treadmill.

SBOM, VEX & Compliance

Audit-ready SBOMs, VEX documents, and provenance attestations with compliance mapping for FedRAMP and PCI DSS 4.0.

Repository Security Posture

RSPM detects misconfigurations in source repositories, while dashboards track risk posture with evidence for every finding.

Analyst Recognition Gartner MQ Visionary 2026

Endor Labs was named a Visionary in the inaugural 2026 Gartner Magic Quadrant for Software Supply Chain Security and was previously recognized as a Gartner Cool Vendor in Platform Engineering (2023). The company's research team — with experience from Amazon, Cisco, Meta, GitHub, and Microsoft — publishes at ICSE, ASE, and IEEE TSE, and that research ships directly in the product.

Endor Labs — FAQ

Endor Labs is a software supply chain security platform that secures open source dependencies, CI/CD pipelines, containers, and AI-generated code, with function-level reachability analysis at its core.

Traditional SCA flags every vulnerable package. Endor Labs checks whether the vulnerable function is actually reachable from your application, cutting false positives by 80–92% and leaving only findings that require action.

Yes. The platform generates audit-ready SBOMs, VEX documents, and provenance attestations, with compliance mapping and reporting for frameworks such as FedRAMP and PCI DSS 4.0.

Endor Labs integrates with GitHub Actions, GitLab CI, and other CI/CD pipelines, and connects to ecosystems including Google Cloud Marketplace and Microsoft Defender for Cloud.

Softprom, an official partner of Endor Labs, supplies the platform in Azerbaijan. Request a demo, trial, or pre-sales consultation through the buttons on this page — Softprom's certified engineers will guide the evaluation.
Countries

Softprom is the official distributor of this vendor in the territory of