档案库 · 开发与企业工具 · 战略决策 · 2021–2026
Endor Labs 押注欧盟《网络弹性法案》让依赖安全成为必买品
Endor Labs 押注供应链攻击加上欧盟《网络弹性法案》会让依赖安全成为必买品;已融资 1.63 亿美元,到 2025 年 ARR 增长 30 倍。
Endor Labs
做的是什么生意
Endor Labs is an AI-native application security platform that maps open-source dependencies, surfaces reachable and exploitable vulnerabilities, generates SBOMs, and scans AI-generated code for flaws via plugins for Cursor and GitHub Copilot.
启动资金:$163M total raised through the April 2025 Series B (TechCrunch).
起因
Founded in 2021 by Varun Badhwar (RedLock, acquired by Palo Alto Networks) and Dimitri Stiliadis (Aporeto), who watched developers at Palo Alto struggle to know which open-source components were safe to update. The SolarWinds (2020) and Log4j (2021) breaches, plus the resulting policy push — US Executive Order 14028, the Securing Open Source Software Act, and later the EU Cyber Resilience Act — convinced them supply-chain security was becoming regulated, not optional.
经过
Endor emerged from stealth in October 2022 with $25M from Lightspeed, Dell Technologies Capital and others, and closed a $70M Series A (Lightspeed, Coatue) in August 2023. It then expanded from dependency security into AI-generated-code security with plugins for Cursor and GitHub Copilot. In April 2025 it closed a $93M Series B led by DFJ Growth with Salesforce Ventures, reporting 30x ARR growth, 5M+ applications protected and 1M+ weekly scans. The EU CRA entered into force on December 10, 2024, with reporting obligations from September 11, 2026 and main obligations from December 2027.
结果
Still scaling. The CRA obligations Endor markets against began taking effect in September 2026 (vulnerability reporting), with main product obligations in December 2027 — the regulatory bet is entering its payoff window as of September 2026.
背景
Endor Labs 创立于 2021 年,创始人是安全老兵 Varun Badhwar 和 Dimitri Stiliadis,售卖面向软件供应链的 AI 原生应用安全平台:绘制开源依赖关系,显示哪些易受攻击的包实际可达可利用,生成软件物料清单,并通过 Cursor 和 GitHub Copilot 插件扫描 AI 生成的代码。
创始赌注是供应链攻击——2020 年 SolarWinds、2021 年 Log4j——会变成监管,让依赖安全成为合规采购,而不是工程上的锦上添花。公司 2022 年 10 月走出隐身模式,拿到 2500 万美元,2023 年 8 月完成 7000 万美元 A 轮,随后扩展到 AI 代码安全领域。到 2025 年 4 月,报告 ARR 自 2023 年以来增长 30 倍,保护应用超过 500 万个,每周扫描超过 100 万次,客户包括 OpenAI、Rubrik、Peloton、Snowflake、Egnyte 和 Dropbox。
监管顺风如期而至:欧盟《网络弹性法案》2024 年 12 月 10 日生效,让制造商负责漏洞管理和强制性 SBOM,覆盖产品全生命周期,报告义务从 2026 年 9 月 11 日起适用,主要义务从 2027 年 12 月起。Endor 明确把平台定位成 CRA 就绪路径,强调对活跃利用的漏洞有 24 小时披露窗口,罚款可达数百万。
截至 2026 年 9 月,Endor Labs 仍在扩张,融资约 1.63 亿美元;它面向的 CRA 报告制度刚刚开始,监管赌注的回报窗口正在打开,而不是关闭。
这件事要成立,得有什么
- 赌注跟可见的政策趋势同步:SolarWinds 和 Log4j 之后,华盛顿和布鲁塞尔都从建议转向强制,比如 EO 14028 和 CRA。
- 产品直接针对合规证据问题——可达性分析和 SBOM 正是 CRA 审计要求的东西。
- 扩展到 AI 代码安全抓住了第二波:CRA 责任模型适用于第三方组件,AI 代码让组件数量激增。
- 融资节奏(2500 万、7000 万、9300 万)加上 30 倍 ARR 增长,说明投资者在给监管论点买单,不只是技术。
可借鉴之处
监管把事件驱动型品类变成采购订单,但前提是你要卖合规官需要的证据——SBOM、可达性、文档——而不只是更好的扫描器。
后续进展
截至 2026 年 9 月 2 日,Endor Labs 仍在扩张:通过 2025 年 4 月 B 轮融资 1.63 亿美元,保护应用 500 万个以上,每周扫描 100 万次以上,产品扩展到 AI 代码安全(Cursor 和 GitHub Copilot 插件)。欧盟 CRA 的漏洞报告义务从 2026 年 9 月 11 日起生效,主要产品义务从 2027 年 12 月 11 日起适用——Endor 的 CRA 材料瞄准这个合规窗口,包括强制 SBOM 和 24 小时披露活跃利用漏洞。所查资料中没有反映进一步融资或收购。
资料来源
- Cyber Resilience Act
- Endor Labs, which helps companies secure their open source packages, raises $70M
- Endor Labs, which builds tools to scan AI-generated code for vulnerabilities, lands $93M
- Why We Raised a $93M Series B (In This Market)
- The EU Cyber Resilience Act and the Software Supply Chain: Why Compliance Can't Wait
发现哪里写错了?告诉我们。
轮到你了
你刚读完一家。说说你在做什么,看看谁在赌同一件事。
免费账号 · 3 次免费提问 · 不用绑卡