What we deliver

Scope of work

Every engagement is scoped in writing before it starts. A typical engagement includes:

  • API discovery and an honest inventory of every endpoint, including shadow and zombie APIs
  • API security testing against the OWASP API Security Top 10
  • Behavioural baselining and detection of business-logic fraud, account takeover and data exfiltration
  • Runtime protection with Cyron API Security: eBPF sensor deployment with no SDK and no code change
  • Coverage for REST, GraphQL, gRPC, WebSocket, Server-Sent Events and Socket.IO
  • Signed, OCSF-aligned security events into your SIEM
  • Sensitive-data and PII exposure detection in API responses

What you get

Outcomes

  • Visibility of APIs you did not know you had
  • Attacks blocked at the source without touching application code
  • Evidence of what happened, not just an alert that something did

Track record

Experience behind it

  • Architect and builder of Cyron API Security, a production runtime API security platform
  • Kernel-level eBPF sensor with out-of-band traffic capture and around 2 ms average detection time
  • Detection for all ten OWASP API Security Top 10 risks plus 31 real-time detectors for streaming and RPC protocols
  • Secure-by-design API architecture for a regulated central-bank platform in Singapore

Technologies and frameworks

  • eBPF
  • Go
  • OWASP API Top 10
  • gRPC
  • GraphQL
  • WebSocket
  • OCSF
  • Kafka
  • PostgreSQL
  • Docker

FAQ

Common questions

Something else on your mind? Ask us directly.

Do we need to change our code to use runtime API protection?

No. Cyron API Security uses an eBPF sensor that copies traffic at the Linux kernel, out of band. There is no SDK, no code change and no proxy in the live request path.

Does API security replace our web application firewall?

No. A WAF filters known bad requests. API security looks at behaviour across requests, which is how BOLA, account takeover and business-logic abuse are caught. The two work together.

Can it run on our own infrastructure?

Yes. Cyron API Security is available as SaaS hosted in Germany or as a full on-premise deployment on your own servers.

Related services

Often combined with

Have a system to build, modernise or secure?

Tell us where things stand today. The first conversation is free, and you will leave it with an honest view of the work involved.