Product · API Security

API security that ties code to runtime

Inventory every endpoint, score the risk on one A-F curve, surface toxic combinations, and diff your declared contract against what is actually running.

Capabilities

What API Security does

Inventory + risk score

Every endpoint inventoried under one hero A-F risk score on the same posture curve - not a wall of KPIs.

Toxic combinations

Public + sensitive + not-provably-authenticated collapses into one prioritised 'Risky' verdict, not three separate facts.

Code-to-runtime

Each endpoint labelled Code + Runtime, From source or Runtime-only - the SAST+DAST differentiator.

Contract-as-truth

Attach your OpenAPI spec and diff declared vs running: documented, shadow, declared-untested, auth-drift.

How it works

apPosture treats API security as posture, not a WAF in the request path: it inventories every endpoint, scores the risk on the same A-F curve as your org posture, and correlates the code that defines an endpoint with the traffic that actually hits it.

01

Inventory

Discover endpoints from SAST attack-maps, the DAST crawl, an attached OpenAPI spec and external subdomain probing.

02

Score + prioritise

One hero risk score; toxic-combination 'Risky' endpoints and typed PII/PCI/PHI data classes float to the top.

03

Correlate

Diff the declared contract and ingested runtime access logs against the scanned posture - shadow, drift and runtime-only endpoints surface.

ENDPOINT IN CODE (SAST) AT RUNTIME (DAST) PROVENANCE POST /api/orders Code + Runtime GET /api/legacy-export - From source GET /internal/debug - Runtime-only · shadow
Code-to-runtime provenance - the code that declares an endpoint correlated with the traffic that actually hits it. Endpoints seen only at runtime are shadow APIs.

What you get

  • Hero API risk score and A-F grade on the posture curve
  • Toxic-combination prioritisation: public + sensitive + unauthenticated
  • Code-to-runtime provenance per endpoint (Code + Runtime / From source / Runtime-only)
  • Contract-as-truth: declared vs running OpenAPI diff
  • Out-of-band runtime correlation from your existing access logs - not inline
  • CI score-gate plus SARIF export and API-scoped compliance across 7 frameworks
Part of one platform

API Security feeds your unified posture

Every API Security finding deduplicates into one risk-weighted posture, correlates into attack-chains, and can block the build at the CI gate.

DAST SAST SCA Container IaC Kubernetes Posture Secrets AI Pentest Threat Modeling ASPM CI/CD Gate

See API Security on your own app

From discovery to a proven attack chain. A PoC in your own environment.