Inventory every endpoint, score the risk on one A-F curve, surface toxic combinations, and diff your declared contract against what is actually running.
Every endpoint inventoried under one hero A-F risk score on the same posture curve - not a wall of KPIs.
Public + sensitive + not-provably-authenticated collapses into one prioritised 'Risky' verdict, not three separate facts.
Each endpoint labelled Code + Runtime, From source or Runtime-only - the SAST+DAST differentiator.
Attach your OpenAPI spec and diff declared vs running: documented, shadow, declared-untested, auth-drift.
apPosture treats API security as posture, not a WAF in the request path: it inventories every endpoint, scores the risk on the same A-F curve as your org posture, and correlates the code that defines an endpoint with the traffic that actually hits it.
Discover endpoints from SAST attack-maps, the DAST crawl, an attached OpenAPI spec and external subdomain probing.
One hero risk score; toxic-combination 'Risky' endpoints and typed PII/PCI/PHI data classes float to the top.
Diff the declared contract and ingested runtime access logs against the scanned posture - shadow, drift and runtime-only endpoints surface.
Every API Security finding deduplicates into one risk-weighted posture, correlates into attack-chains, and can block the build at the CI gate.
From discovery to a proven attack chain. A PoC in your own environment.