Off the Bit
Tools: Endor Labs
Category: Security and secrets
Site: endorlabs.com
Endor Labs
Application security aimed at reachability: whether a vulnerable function is actually called, not only present.
Answers whether the vulnerability is reachable.
What it is sold for
Cutting dependency findings down to the ones that matter.
Same shelf
The rest of security and secrets, alphabetically. Sharing a category is a filing decision, not a relationship.
- Fine-grained authorization as a service, so permission checks stop being scattered if-statements.
- Hosted identity: login, federation, multi-factor and the standards work nobody wants to implement twice.
- Amazon's managed identity for consumer applications, priced and scaled for very large user pools.
- Static analysis for security and privacy risk, focused on where sensitive data flows. Acquired by Cycode.
- The open-source scanner behind Bearer. Finds and ranks security and privacy risk in source, and still runs on its own.
- Open-source SAML and OIDC single sign-on, so enterprise login is not a rewrite. The address now serves Ory.
- Enterprise application security, combining several scan types and consolidating findings into one risk view.
- Authentication with the interface components included, built for React and Next.js first.
ImranTools[Endor Labs]