Endor Labs Secures $70 Million Series A Funding

Endor Labs Secures $70 Million Series A Funding

The News: Endor Labs raised $70 million in an oversubscribed Series A funding round that included backing from Lightspeed Venture Partners (LSVP), Coatue, Dell Technologies Capital, and Section 32, as well as more than 30 CEOs, CISOs, and CTOs. The vendor will invest the funding in research and development to further its Code and Pipeline Governance Platform, as well as in expanding its go-to-market reach in the channel and in EMEA. Additional information is available on the Endor Labs blog.

Endor Labs Secures $70 Million Series A Funding

Analyst Take: The market dynamics surrounding CI/CD and open-source pipeline security are rapidly evolving as businesses prioritize efficient and secure software development practices. Continuous Integration and Continuous Deployment (CI/CD) methodologies have gained immense popularity due to their ability to accelerate the development process and improve software delivery. However, with the increasing reliance on open-source components in pipelines, there is a growing need for robust security solutions to address potential vulnerabilities and ensure the integrity of the entire software supply chain. As a result, the demand for comprehensive and automated security tools in the CI/CD space continues to rise, presenting significant opportunities for innovative security providers.

Fresh from its launch 10 months ago, Endor Labs has secured $70 million in a Series A funding round. The investment capital will be applied in two key areas. The first is furthering research and development (R&D) initiatives to advancing development of the company’s Code and Pipeline Governance Platform, which was designed to streamline DevSecOps processes as they pertain to open-source software development. The second is facilitating go-to-market initiatives focused on expanding the company’s reach in the channel and in EMEA.

As The Futurum Group learned in conversation with Endor CEO Varun Badhwar, who was previously at Palo Alto Networks and built its cloud-native security business from scratch to over $300 million annual recurring revenue (ARR) in 3 years, with the vendor’s Code and Pipeline Governance Platform, Endor Labs aims to enable DevSecOps teams to meet security and compliance requirements, including creating a software bill of materials (SBOM) and addressing critical vulnerabilities, without impacting their productivity. Effectively, the objective is to bake security in as a default component of the CI/CD pipeline and to allow security policies to be enforced consistently, without hampering developer productivity.

Today’s developers use a host of open-source components and libraries as they script applications; in fact, according to Endor Labs, 90% of code in modern applications is open source. While speeding development operations by avoiding the need for developers to create everything from scratch, the tradeoff inherent in this approach is the creation of a plethora of dependencies that developers themselves might not even be privy to. As a result, as vulnerabilities arise, IT Operations and security teams might not be aware that an application is impacted, or they might end up spending extensive time prioritizing addressing a vulnerability that does not materially impact source code. According to Endor, only approximately 12% of open-source code that is brought in by developers ends up finding its way into source code. In other words, prioritizing risk mitigation initiatives has become practically impossible. With the criticality of agile development to business success, and the ongoing onslaught of cyber-attacks that capitalize on software vulnerabilities, this is a significant issue that Endor’s product tackles.

Among Endor’s differentiators are its focus on “dependency life cycle management,” that is, cataloging and tracking applications’ various dependencies, and applying a metrics-based risk score that can be used to prioritize and apply security policies. The concept is that comprehensively inventorying potential paths to vulnerabilities allows them to be prioritized and subsequently addressed.

Though only 2 years since its founding and 10 months since its launch, Endor is one of four finalists in Black Hat USA’s 2023 startup competition, occurring on August 9. The company has attracted a spate of large customers, including Five9, as well as an R&D staff, one-third of which is educated at the doctoral level. Fueled with the investment funding, Endor is well-poised to continue innovating around the pressing issue of managing application security vulnerabilities in a DevSecOps environment.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other Insights from The Futurum Group:

What Is Comprehensive Cyber-Resiliency? — Infrastructure Matters, Episode 4

Searching for That Good Restore Point

Cybersecurity is Everyone’s Job

Author Information

Krista Case brings over 15 years of experience providing research and advisory services and creating thought leadership content. Her vantage point spans technology and vendor portfolio developments; customer buying behavior trends; and vendor ecosystems, go-to-market positioning, and business models. Her work has appeared in major publications including eWeek, TechTarget and The Register.

Steven engages with the world’s largest technology brands to explore new operating models and how they drive innovation and competitive edge.

Related Insights
Salesforce's $1.6B Win Signals a New Era in Veteran Care Technology
July 27, 2026

Salesforce’s $1.6B Win Signals a New Era in Veteran Care Technology

Keith Kirkpatrick, Vice President & Research Director, Enterprise Software & Di at Futurum, Salesforce's $1.6B VA contract signals a pivotal shift toward AI-enhanced veteran care and modernized public sector service...
IBM Q2 FY 2026: Software Growth Continues as Mainframe Purchases Slow
July 27, 2026

IBM Q2 FY 2026: Software Growth Continues as Mainframe Purchases Slow

Futurum Research analyzes IBM’s Q2 FY 2026 earnings, focusing on software mix, mainframe timing, AI demand, and revised FY 2026 guidance....
So This Is How AIs Attack- Observations From the OpenAI & Hugging Face Incident
July 24, 2026

So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident

Fernando Montenegro and Mitch Ashley, VPs at Futurum, read the OpenAI and Hugging Face agentic incident as a live test of enterprise readiness to detect and contain AI agents that...
ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth
July 23, 2026

ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth

Futurum Research analyzes ServiceNow Q2 FY 2026 earnings, focusing on AI Control Tower adoption, security expansion, and workflow demand....
Alphabet Q2 FY 2026: Google Cloud Leads Growth Amid Rising AI Investment
July 23, 2026

Alphabet Q2 FY 2026: Google Cloud Leads Growth Amid Rising AI Investment

Futurum Research analyzes Alphabet’s Q2 FY 2026 earnings, focusing on cloud AI demand, Gemini adoption, Search monetization, and rising AI infrastructure spending....
Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?
July 23, 2026

Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?

Mend.io's security team identified 199 malicious RubyGems and achieved complete takedown within hours, intercepting a cryptomining campaign before execution and demonstrating the critical importance of continuous open-source monitoring....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.