perch vs Endor Labs

Side-by-side comparison of features, pricing, and ratings

Analysis reviewed Live tool data as of 2026-09-26
Cross-checked through our multi-step verification ·
Saved

At a glance

DimensionperchEndor Labs
PricingFreeFreemium — self-serve Developer tier (local scanning, no account); paid enterprise tiers quote-only
Core jobEnforce your team's own semantic rules on a source treeVerify and prioritize real, reachable vulnerabilities across code, containers, and AI agent actions
Rules authored asYour own perch.yaml rules written in plain-language --ensure guaranteesVendor-maintained policy engine + policy-as-code enforcement (allow/block/ask a human)
Agent-related scopeReviews/gates code produced by Claude Code, Codex, CursorGoverns agents themselves: inventories agents, models, MCP servers, skills; audit trail
Hosting / opsCLI, findings stored locally in .perch; source sent to a third-party service for analysisPlatform deployed where your infrastructure runs; nothing installed in your cluster (container scanning)
CI gatingExit code 3 fails CI jobs on breaking findingsPolicy-as-code enforcement at the moment of action, with audit trail
perch
perch

Perch is a semantic code linter that turns your team's review rules into committed, executable policy checks powered by Jev.

Visit Website
Endor Labs
Endor Labs

AI-native application security that governs coding agents and verifies real, reachable vulnerabilities.

Visit Website
Pricing
Free
Freemium
Plans
Free (MIT license); per-scan Jev analysis billed separately
$0/mo
Contact sales
Contact sales
Popularity
1 views
6.6k views
Skill Level
Intermediate
Intermediate
API Available
Platforms
CLI
WebAPICLIPlugin
Categories
🔎 Code Review & Quality🔐 Application & Code Security
🔐 Application & Code Security🛡️ AI Governance & Guardrails
Features
Run semantic scans across a source tree with `perch scan` for defects and security issues
Author custom lints in perch.yaml with plain-language guarantees via `--ensure`
Scope rules by unit with `--each method` or `--each file`
Limit rules to path globs with `--where "src/**/*.ts"`
Report each finding with rule ID, file:line, severity, confidence percentage, and method name
Filter a scan to one rule with `perch scan --filter rule=<name>`
Test a rule against a specific symbol with `perch check <file>::<method> --rules <name>`
Detect off-by-one loop errors, weak cryptography (MD5-hashed tokens), and unhandled nulls
Score findings probabilistically (e.g. 91%, 93%, 72%) rather than pass/fail
Scan only changed files with surrounding context using `perch scan --since origin/main`
Fail CI jobs on breaking findings with exit code 3
Store findings locally in the .perch directory
Apply rules to non-code files such as Markdown documentation with `--each file`
Install the Perch skill for Claude Code, Codex, or Cursor so agents check their own fixes
Report scan summaries with finding count, methods touched, and estimated cost
AI SAST with data flow analysis to cut up to 95-97% of false positives
C language support for AI SAST (added August 2026)
Reachability-based software composition analysis (SCA)
Secrets detection before commit, one policy from laptop to pipeline
AI security review in pull requests (auth gaps, removed OAuth state params, new PII collection)
Container image scanning with code-to-image reachability, nothing to install in your cluster
Package Firewall that blocks malicious packages at install
Agentic remediation that applies fixes while preserving logic
AI coding agent governance: inventories agents, models, MCP servers, and skills
Policy-as-code enforcement at the moment of action (allow, block, or ask a human) with audit trail
MCP server and rich CLI for Cursor, Claude Code, Codex, VS Code/Copilot, Antigravity
Free Developer tier with local scanning and no account required
SBOM Hub for first- and third-party SBOMs with compliance reporting (CRA, FedRAMP, ISO 42001, PCI DSS, SOC 2)
CI/CD security and artifact signing
Patches as drop-in replacements for vulnerable open source libraries
Integrations
GitHub Actions
Claude Code
Codex
Cursor
GitHub App
CircleCI
Microsoft Defender for Cloud
Bazel
OpenAI Codex
VS Code
Copilot
Antigravity
MCP servers
AWS Marketplace
Azure Marketplace
Google Cloud Marketplace

What real users say: perch vs Endor Labs

Not marketing copy and not our opinion — a structured sweep of public discussion (reviews, forums, communities and video comments), showing what people praise and what they complain about for each tool.

perch

70 mentions across 6 sources · 14% positive — critical (weighted across 6 sources)

Reddit, Hacker News, YouTube, Product Hunt, GitHub, Lemmy

What users praise

  • • Free and globally installed via npm as @lakeday/perch — zero cost to try.
  • • Natural-language rules in perch.yaml let you encode team conventions as reviewable code.
  • • Findings include rule ID, file:line, severity, confidence percentage, and enclosing method.
  • • Per-finding confidence scoring avoids binary pass/fail and reduces false-positive fatigue.

What frustrates them

  • • Almost no independent user reviews or testimonials exist for the actual linter.
  • • Open language-filtering bug means shipped scans may flag irrelevant vulnerability classes.
  • • No listed integrations with CI/CD, editors, or Slack — everything is manual CLI wiring.
  • • Name collision with Google Perch and a board game makes community support hard to find.

Researched Sep 26, 2026

Endor Labs

30 mentions across 3 sources · 58% positive — mixed (averaged across 3 sources)

Hacker News, YouTube, Lemmy

What users praise

  • • Reachability-driven prioritization cuts through scanner noise effectively.
  • • Discovered real zero-days, including CVE-2026-55407 in Anthropic's buffa.
  • • Provides verifiable evidence with data flow and call paths.
  • • Contextual fixes preserve code logic, reducing manual effort.

What frustrates them

  • • Sparse community feedback makes independent validation difficult.
  • • Pricing for Core/Pro tiers lacks transparency in public discussions.
  • • Full platform complexity may require dedicated security expertise.
  • • Concern about support quality after Microsoft integration.

Researched Jul 31, 2026

Feature-by-feature

The two tools differ in kind, not degree. Endor Labs is a verification engine: its AURI engine mixes deterministic program analysis with data flow tracing to cut what the vendor claims is 95-97% of traditional SAST/SCA false positives, then prioritizes by reachability (including code-to-image reachability for containers). Its AI SAST extends to C as of August 2026 and covers first-party and business-logic scanning; secrets detection runs before commit; Package Firewall blocks malicious packages at install. Its distinguishing layer is agent governance: it inventories every AI coding agent, model, MCP server, and skill, learns your architecture from AGENTS.md and CLAUDE.md context files, and enforces policy at the moment of action — allow, block, or ask a human — with an audit trail. Perch has none of that. It is a CLI that runs perch scan over a source tree and returns findings with rule ID, file:line, severity, a confidence percentage, and enclosing method. Its differentiator is authoring: you define rules in perch.yaml with perch rules add, scope them with --each method, --each file, or --where "src/**/*.ts", and state them as plain-language --ensure guarantees. It filters to one rule, checks a single symbol, scans only changed files with --since origin/main, and exits 3 to fail CI. Perch detects off-by-one loops, weak crypto, and unhandled nulls; Endor Labs detects the same broad class of issues but as one input into a governed enterprise workflow.

Pricing compared

Endor Labs is freemium in the least generous sense: the only self-serve option is the Developer tier, which does local scanning with no account required, and everything else is a quote-based enterprise purchase. Its own 'not for' list says it plainly — buyers who need instant self-serve paid plans. Budget for a sales cycle, a deployment inside infrastructure you control, and onboarding alongside a security or DevSecOps function; several capabilities assume CI/CD pipelines exist. Perch costs nothing. You install it with npm install -g @lakeday/perch and run it. The hidden cost isn't licensing, it's labor: Perch ships no vendor rule pack worth speaking of, so the return depends entirely on the perch.yaml rules your team writes and maintains. Filtering with perch scan --filter rule=<name> and gating with perch scan --since origin/main keeps CI minutes near zero, and findings stay in the local .perch directory rather than a hosted dashboard you'd pay for. So the cost comparison is enterprise contract plus implementation effort versus zero dollars plus rule-authoring effort — not two tiers of the same product.

Who should pick which

  • Security team at a FedRAMP-bound enterprise
    Pick: Endor Labs

    FedRAMP 2026 rules make reachability analysis a requirement for vulnerability management; Endor Labs positions AURI's reachability engine as aligned.

  • DevSecOps engineer drowning in SCA/SAST false positives
    Pick: Endor Labs

    Data flow analysis plus reachability prioritization is the whole pitch — cut noise, then prove which findings are actually reachable.

  • Platform team rolling out Cursor, Claude Code, and Codex internally
    Pick: Endor Labs

    Inventory of agents, models, MCP servers, and skills with allow/block/ask enforcement and an audit trail is governance you can't build from a linter.

  • Two-person TypeScript startup with project-specific review rules
    Pick: perch

    Free, repo-committed perch.yaml rules scoped with --where "src/**/*.ts" and gated in GitHub Actions with exit code 3 — no vendor contract needed.

  • Solo developer reviewing AI-generated Python
    Pick: perch

    `perch scan --since origin/main` plus confidence-scored findings gives a cheap check on agent output without a hosted platform.

Frequently Asked Questions

Can I start using Endor Labs today without talking to sales?

Only the Developer tier, which does local scanning with no account required. Anything beyond that goes through a quote — its own 'not for' list flags buyers who need instant self-serve paid plans.

Does Perch need my source code to leave my machine?

Yes, analysis is done by a third-party service, which Perch lists as a disqualifier for codebases that can't send relevant source out. Findings themselves are stored locally in the .perch directory.

Can Perch replace Endor Labs' SCA or container scanning?

No. Perch scans a source tree for defects and security issues through rules you write. It has no software composition analysis, container image scanning, or reachability prioritization.

Do I have to write rules to get value from Perch?

Largely yes — Perch explicitly says it is not zero-config drop-in linting and that value depends on writing your own perch.yaml rules. Out of the box you get detection of things like off-by-one loops, MD5-hashed tokens, and unhandled nulls.

What happens to Endor Labs findings when a coding agent proposes a fix?

Its agentic remediation applies fixes while preserving logic, and policy-as-code can allow, block, or ask a human at the moment of action, with the decision recorded in an audit trail.

Can both run in the same pipeline?

Technically yes — Endor Labs integrates with GitHub Actions and CircleCI, and Perch fails CI jobs via exit code 3. But you'd be buying two different things: governed enterprise verification versus local custom-rule enforcement.

More perch or Endor Labs comparisons

Explore each tool further

Browse these categories

Still deciding? Get the weekly AI tools brief

One email a week — new tools, honest comparisons, no spam.

Last reviewed: September 26, 2026