Endor Labs has been named a Sample Vendor in the Gartner® Hype Cycle™ for Application Security, 2026 across three categories:
- Agentic Application Security Testing
- Software Supply Chain Security
- Reachability Analysis
We see recognition across all three as validation of a thesis we've held since founding the company: application security in the agentic era is one connected problem, not three separate product categories.
The code agents write, the open source they pull in, the way teams prioritize and fix what they find, and how you secure the systems producing code all depend on the same thing: a deep, continuously updated understanding of how your applications behave.
Agentic coding changed the problem
Software engineers now ship code with AI agents in the loop by default. Pull request volume is up 113%, yet our agent code security benchmark shows that 70% or more of AI-generated is insecure. Agents also make dependency decisions on their own, importing packages no human vetted, at a moment when attackers are poisoning open source ecosystems specifically to target agentic workflows.
This shift breaks the scan-after-build model. When agents plan, write, test, and open PRs with minimal human checkpoints, security has to work the way agents work: embedded in the development loop, evaluating code as it's produced, checking dependencies as they're chosen, and fixing issues before they merge. Securing agentic coding means securing the code agents produce and the software supply chain they draw from, together.
That is the story we read across our three recognitions in this year's Hype Cycle.
Securing the code agents produce
Traditional SAST pattern-matches against known signatures, which is why legacy tools miss business logic flaws and drown teams in false positives. Agentic application security testing takes a different approach, using LLMs and reasoning to analyze application logic the way a security researcher would.
We built AI SAST on the belief that reasoning alone isn't enough. Pure LLM approaches lack the deterministic grounding that mature security programs require, so AURI by Endor Labs combines LLM-based reasoning with program analysis trained on ground-truth vulnerability data. Every finding is anchored to our code context graph, a continuously updated model of application behavior across code, dependencies, secrets, and containers.
The results show up in our AI SAST benchmark against traditional scanners and frontier models across eight real projects. Endor Labs AI SAST found 192 real vulnerabilities, 2.6x more than Claude Code and 3.5x more than OpenAI Codex, and surfaced 63 vulnerabilities no other tool in the test caught. Those unique findings were concentrated exactly where agentic testing earns its keep: broken access control, authentication failures, and business-logic flaws that depend on how an application behaves rather than what a pattern matches.
Securing coding agents and the software factory itself
Most applications are mostly other people's code, and AI agents have made third-party consumption faster and less supervised. An agent that hallucinates a package name or picks an unmaintained dependency expands your attack surface in seconds.
This recognition adds to Gartner's view of Endor Labs in the category: we were also named a Visionary in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security, which we see as recognition of both where the market is heading and how we're building for it.
Endor Labs secures the supply chain at the point of consumption. Package Firewall scans newly published packages across npm, PyPI, and other ecosystems and flags emerging malware campaigns in under 10 minutes, blocking both developers and coding agents from pulling malicious packages into a local machine or CI runner. Coding Agent Governance extends that visibility to the agents themselves: which models, MCP servers, and tools are active in your development environment, and whether their behavior matches your policies. SBOM generation, artifact signing, and CI/CD posture management round out coverage from dependency selection through delivery.
Reachability analysis: fixing what matters
Finding more issues only helps if teams can act on them. Function-level reachability has been core to Endor Labs from day one: we analyze call graphs across first-party code, direct and transitive dependencies, and container layers to determine whether your application can actually invoke a vulnerable function. On average, that lets teams deprioritize 92% of vulnerability noise and focus engineering time on exploitable risk.
Reachability also powers remediation. Upgrade impact analysis shows exactly which breaking changes a patch will trigger before anyone touches a version number, and Endor Patches fix vulnerabilities in hard-to-upgrade libraries without forcing a major version bump. The result is 6x faster remediation, because fixes ship as predictable engineering tasks instead of blind upgrades.
One platform for agentic coding security
These three capabilities share a single foundation. The code context graph gives coding agents the context to write secure code by default, gives PR reviews the evidence to separate real risk from noise, and gives remediation the confidence to fix without breaking builds. Testing informs prioritization. Supply chain intelligence informs what agents are allowed to do. Reachability informs everything.
We think that connected architecture is what application security looks like when agents write most of the code, and we're glad to see the categories it spans recognized in this year's Hype Cycle.
Want to see how AURI secures agentic development end to end? Request a demo.
Disclaimer
Gartner, Hype Cycle for Application Security, 2026, Dionisio Zumerle, 21 July 2026.
Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and HYPE CYCLE is a registered trademark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved.
What's next?
When you're ready to take the next step in securing your software supply chain, here are 3 ways Endor Labs can help:
