Case Study: Grip Security cuts SCA noise by 99% after replacing its incumbent tool with Endor Labs
Key results
The challenge
Grip Security's previous SCA tool marked many findings as reachable when they were actually unreachable in the application's context. Developers spent time manually evaluating findings to confirm reachability, and had to choose between upgrading packages at the risk of dependency issues or waiting on DevOps investigation.
The solution
Grip replaced its incumbent SCA tool with Endor Labs, which prioritizes findings using call-path analysis to distinguish reachable from unreachable vulnerabilities. The change surfaced the smaller set of findings that were actually exploitable in Grip's code.
“Endor Labs delivered on its promise to make SCA way more efficient and bubble up what actually matters much quicker.”
IFIdan FastCo-Founder & CTO, Grip Security
The results, in context
Grip Security reported a 99% noise reduction with Endor Labs. Its previous tool had claimed roughly 100 times more reachable vulnerabilities than Endor Labs surfaced on its first scan, and developers gained faster, more accurate prioritization.