# Endor Labs vs StackHawk

**Leader by Vioscale score:** Endor Labs

| Attribute | Endor Labs | StackHawk |
|---|---|---|
| **Vioscale score** | 65.2 (71% (medium)) | 50.5 (73% (medium)) |
| deployment.options | `{"cloud":true,"hybrid":true,"self_hosted":true}` | `{"cloud":true}` |
| description.long | An AI-powered application security platform combining static analysis, dependency scanning, and container image scanning with reachability-based prioritization to reduce false positives and enable automated vulnerability remediation across the development lifecycle. | A platform that enables AI coding agents (such as Claude, GitHub Copilot, Cursor) to automatically identify, analyze, and remediate security vulnerabilities in applications during development, eliminating context switching and manual handoffs to security teams. |
| features.capabilities | `{"sca":true,"dast":false,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":false,"iac_scanning":false,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":false}` | `{"dast":true,"hosting":"cloud","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":true}` |
| integrations.count | 10 | 11 |
| integrations.list | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"BitBucket"},{"name":"Azure DevOps"},{"name":"AWS Marketplace"},{"name":"Microsoft Azure"},{"name":"Google Cloud Marketplace"},{"name":"Wiz"},{"name":"Cursor AI"},{"name":"Microsoft Defender for Cloud"}]` | `[{"name":"Claude Code"},{"name":"Codex"},{"name":"Gemini CLI"},{"name":"GitHub Copilot"},{"name":"OpenCode"},{"name":"Cursor"},{"name":"Snyk"},{"name":"Auth0"},{"name":"GitHub Actions"},{"name":"GitLab"},{"name":"Jenkins"},{"name":"CircleCI"}]` |
| market.availability | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"subscription","plans":[{"free":true,"name":"Developer","summary":"Free for individual developers","features":["Local scanning","Read-only vulnerability data"],"description":"Free tier for individual developers with local scanning and read-only access to vulnerability data","contactSales":false},{"free":false,"name":"Core","description":"Team-oriented tier with reachability analysis, prioritization, and policies","contactSales":false},{"free":false,"name":"Pro","description":"Enterprise-scale tier with advanced detection, triage, and fix capabilities across application layers","contactSales":false}],"summary":"Seat-based subscription pricing with free Developer tier; specific pricing available on request","currency":"USD","freeTier":true,"sourceUrl":"https://www.endorlabs.com/pricing","retrievedAt":"2026-08-14T09:22:26.641Z","billingPeriods":["month","year"]}` | `{"type":"subscription","plans":[{"free":false,"name":"Wingman","summary":"$10/user/month","features":["Works inside Claude Code, Cursor, GitHub Copilot","Auto-configures and boots app","Runtime testing against running app","Finds and fixes vulnerabilities in same session","Auto-rescanning to verify fix","Pre-PR security attestation","Unlimited apps","50 scans/user/month"],"commitment":"monthly","components":[{"kind":"per_unit","unit":"user","amount":10,"period":"month","currency":"USD"}],"description":"For individuals and teams shipping with AI coding agents","contactSales":false,"includedLimits":{"apps":"unlimited","scans":"50/user/month"}},{"free":false,"name":"Scale","summary":"Custom pricing. Contact sales.","features":["Everything in Wingman","Attack surface discovery","Sensitive data detection","Deeper, broader scan coverage","Program reporting (coverage, fix rates by team)","Teams, roles, and enterprise support","Unlimited agentic scans"],"description":"For security teams needing attack surface discovery, coverage, and proof across every app","contactSales":true,"includedLimits":{"apps":"unlimited","scans":"unlimited"}}],"summary":"From $10/user/month (Wingman). 14-day free trial. Scale plan available via sales consultation.","currency":"USD","freeTier":true,"sourceUrl":"https://www.stackhawk.com","retrievedAt":"2026-08-03T22:45:21.019Z","freeTrialDays":14,"startingPrice":{"amount":10,"period":"month","currency":"USD"},"billingPeriods":["month"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | freemium |
| pricing.price_level | low | low |
| pricing.transparent | no | no |
| reliability.sla_pct | 99.9 | - |
| reliability.status_page | yes | yes |
| security.disclosure_policy | yes | yes |
| security.fedramp | yes | - |
| security.pci | yes | - |
| security.soc2 | yes | yes |

## Capabilities (DevSecOps Tools)

| Capability | Endor Labs | StackHawk |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | ✓ | - |
| DAST (dynamic analysis) | ✗ | ✓ |
| SCA / dependency scanning | ✓ | - |
| Secret scanning | ✓ | - |
| Container / image scanning | ✓ | - |
| IaC misconfiguration scanning | ✗ | - |
| **Governance** |  |  |
| OSS licence compliance | ✗ | - |
| SBOM generation (SPDX/CycloneDX) | ✓ | - |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | ✓ | ✓ |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | ✓ | - |
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Cloud only |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✓ | ✓ |
| **Licensing** |  |  |
| OSS engine available | ✗ | ✓ |

*Source: Vioscale. Generated 2026-09-01T16:39:04.221Z. "-" = undocumented, not absent.*
