Endor Labs: Interview With CEO Varun Badhwar About AI-Native Application Security

Endor Labs provides an AI-native application security platform designed to help organizations understand software supply chain risk, prioritize vulnerabilities based on reachability, and secure increasingly AI-generated software without slowing development. The company is expanding across software composition analysis, AI SAST, security code review, and full-stack container reachability. Pulse 2.0 interviewed Endor Labs CEO Varun Badhwar to learn more.

Varun Badhwar’s Background

When asked about his background and the experiences that led him to found Endor Labs, Badhwar shared:

I’ve spent most of my career working at the intersection of software development and security. Before founding Endor Labs, I helped build and scale large-scale cloud security programs, including Prisma Cloud at Palo Alto Networks, during a period when cloud-native architectures were rapidly becoming mainstream.

What became clear during that time is that modern software development had fundamentally changed. Applications are no longer built from scratch. They are assembled from thousands of open-source components, transitive dependencies, and increasingly AI-generated code. That shift created a level of complexity and velocity that traditional security approaches were never designed to handle.

That experience led me to start Endor Labs with a mission to help developers move fast without introducing unnecessary risk into the software supply chain. Our focus is on helping teams understand what code is actually doing, which risks matter, and how to remediate issues without slowing innovation.

Appointing The First CRO

When asked what strategic priorities led Endor Labs to appoint Zack Sikora as its first CRO at this stage of growth, Badhwar explained:

We’ve reached a point where founder-led go-to-market doesn’t scale anymore. Our GTM organization has tripled in the last 12 months, and that level of growth demands someone who can orchestrate across sales, customer success, and partnerships.

But there’s also a shift happening with how customers engage with us. They start with our reachability-based SCA work, then expand across the broader platform: AI SAST, security code review, full-stack container reachability. That platform motion requires someone who understands how to deepen customer relationships over time, not just close deals.

And we’re committing fully to a channel-first model. That’s a structural change that touches everything: how we hire, how we build partnerships, how we go to market. It needs someone with real operating experience at scale.

Zack’s built enterprise sales teams; he understands long-term team development, and he knows how to drive discipline across complex organizations.

225% Revenue Growth

When asked what has driven Endor Labs’ 225% year-over-year revenue growth and how sustainable that trajectory is, Badhwar said:

Our growth has been driven by a combination of market transformation and product expansion.

First, AI is fundamentally compressing the software development lifecycle. Code is being generated faster than ever before, often by AI systems, which dramatically increases both the volume and complexity of software being introduced into organizations.

Second, we are seeing a structural shift in the threat landscape. Our research shows a sharp increase in malware activity across open source ecosystems alongside growing supply chain attacks. At the same time, many organizations still lack basic preventative controls, creating a widening gap between attacker speed and defensive maturity.

Third, our platform approach is resonating. Customers typically start with reachability-based SCA and then expand across our broader AI-native application security platform over time. That expansion across use cases has been a key driver of growth.

We believe this trajectory is sustainable because it is rooted in long-term structural changes in how software is built and how it is being targeted.

Autonomous Plane Acquisition

When asked how the acquisition of Autonomous Plane enhances Endor Labs’ AI-native application security platform, Badhwar detailed:

The acquisition of Autonomous Plane strengthens Endor Labs’ ability to secure software in the era of AI-generated development by extending visibility beyond code into how applications actually run in production environments.

As AI becomes embedded in software engineering workflows, applications are increasingly assembled from AI-generated code, open source dependencies, and containerized components. This creates blind spots for traditional security tools that rely on static, point-in-time scanning.

With Autonomous Plane, Endor Labs expands into full-stack reachability, connecting application code, dependencies, and container images into a unified view of risk. This allows teams to understand not just what vulnerabilities exist, but which are actually reachable and meaningful in a running environment.

A key impact is signal clarity. By correlating code and runtime behavior, the platform can eliminate up to 90% of false positives, helping teams focus only on exploitable, real-world risk.

For customers, this means faster development enabled by AI, paired with stronger confidence that security is focused on what truly matters in production.

Full-Stack Container Reachability

When asked what full-stack container reachability means in practice and why it matters for modern security teams, Badhwar explained:

Full-stack container reachability connects application code, dependencies, container images, and runtime behavior into a single view of how software actually executes in production.

Traditional container security tools primarily scan images and surface all known vulnerabilities, regardless of whether they are used by the running application. This creates significant noise and makes it difficult for teams to prioritize what truly matters.

By tracing how application logic flows through dependencies into containerized runtime environments, full-stack reachability identifies which vulnerabilities are actually reachable, and therefore exploitable, in production.

This enables a shift from volume-based vulnerability management to risk-based prioritization. Instead of remediating thousands of theoretical issues, teams can focus on the small subset that represents real exposure.

As organizations adopt more AI-generated code and increasingly rely on open source and containerized infrastructure, this level of precision becomes critical for maintaining security without slowing development velocity.

The Next Phase Of Application Security

When asked what the next phase of application security looks like as AI continues to transform software development, Badhwar concluded:

The next phase of application security will be defined by agentic, AI-driven development, where code is generated at speeds the industry has never seen before.

We’re already seeing a gap between functional correctness and security. AI-generated code may work, but it is not consistently secure, and as frontier models like Mythos demonstrate deep understanding of open source code, that gap will only accelerate.

Mythos-style models are trained on essentially all of open source, giving them near-native context across kernels, libraries, and dependencies. That means vulnerabilities are not just being detected faster; they are being discovered at a scale that will overwhelm traditional security workflows.

Three shifts are already clear:

  1. CVE volume will explode across open source, including code that has been stable for decades.
  2. Attackers will target shared dependencies, not proprietary systems, such as libraries like axios, litellm, and trivy.
  3. Exploit windows are collapsing, from weeks or months to hours with LLM-assisted tooling.

The reality is that we are effectively shipping “Formula One cars without brakes.” AI is accelerating development faster than security controls, governance, and validation can keep up.

The next phase is not about slowing AI down. It is about adding the “brakes and guardrails” for AI-native development: continuous visibility into code behavior, real security validation, and understanding actual exploitable risk in production.

At Endor Labs, we believe security has to become more evidence-based and contextual. The key question is no longer “is there a vulnerability?” but “is it reachable, and how fast can we fix it?”