Endor Labs, which helps businesses select, secure, monitor, and maintain their open-source software dependencies at scale, emerges from stealth with a $25M seed
Context & Ripple Effects
Endor Labs is entering a category that ShiftLeft helped define years earlier with its pre-runtime code security approach — but aimed one layer up, at the open-source dependencies that make up most of a modern application rather than first-party code alone. The $25M seed is unusually large for a stealth-stage company, signaling investor conviction that dependency management is a budget line of its own.
The arc since then validates the bet: within a year Endor Labs raised a $70M Series A led by Lightspeed, and by 2025 it had reached a $93M Series B and $163M total funding, pivoting its scanning technology toward AI-generated code. This seed round is the origin point of that trajectory.
First-order effects
- Enterprises gain a dedicated vendor for selecting, securing, and maintaining open-source dependencies at scale — work previously handled by ad hoc tooling or general-purpose scanners like ShiftLeft's.
Second-order effects
- A $25M seed forces incumbents in code security to treat dependency governance as a distinct product line rather than a feature, and encourages adjacent security startups — such as Reco in data-sharing monitoring — to pitch buyers on a broader software-supply-chain stack.
Third-order effects
- If funding cadence holds, software supply chain security consolidates into platform vendors spanning dependencies, pipelines, and eventually AI-generated code — the direction Endor Labs' own Series B took.
The trend: Security spending is shifting from scanning first-party code at runtime to governing the entire software supply chain — dependencies, pipelines, and machine-written code — as a single managed layer.