Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
24 criteria
baselineHow does the platform discover all APIs — including shadow, zombie, and internal/east-west APIs — across environments, and how continuous is discovery?
baselineHow does the platform assess API posture (OpenAPI/spec conformance, authentication and authorization configuration) and detect sensitive-data exposure in API traffic?
baselineDescribe runtime detection of API attacks — BOLA/BFLA, abuse, account takeover, and business-logic attacks — the signals used, and accuracy. Quantify with customer references.
baselineWhat API security testing does the platform provide pre-production (spec scanning, fuzzing, DAST, CI/CD), and how does it integrate with developer pipelines?
baselineIs detection inline (proxy/agent) or out-of-band (mirrored traffic/logs), what is the latency and scale impact, and does API data leave the customer boundary?
baselineWhat response and prevention is available (blocking, rate-limiting, WAAP enforcement, ticketing), and is it native or integration-dependent?
baselineHow does the platform secure GenAI/LLM APIs and AI-agent/MCP traffic (prompt abuse, model endpoints, agent-to-API calls)?
baselineWhich gateways, CDNs, and CI/CD tools does the platform integrate with, and provide false-positive/accuracy figures with customer-validated evidence.
baselineWhat is the pricing model — per API endpoint, per request volume, or a flat enterprise tier — and given that API discovery inherently reveals more endpoints than initially estimated (shadow/zombie APIs), how does pricing respond to that discovery-driven growth?
baselineDoes the platform assess risk from third-party/partner APIs the organization CONSUMES (not just the APIs it exposes), including monitoring for a partner API's security posture or breach history affecting the customer's own risk?
baselineWhat compliance-specific reporting does the platform generate for API-relevant requirements (e.g., PCI DSS API security provisions), and is this a built-in exportable auditor-ready report or something the customer must assemble manually?
baselineDetail incident-forensics capability for a confirmed API breach — can the platform quickly reconstruct exactly which records/data were accessed via the compromised API and by whom, with a concrete turnaround-time example from a customer reference?
baselineDoes API security coverage extend meaningfully to mobile-app backend APIs specifically (distinct traffic patterns and auth models from browser-facing web APIs), or is coverage effectively web-API-centric?
baselineHow consistent is discovery and protection depth across multi-cloud/hybrid API deployments — is coverage equally deep across AWS, Azure, GCP, and on-prem gateways, or meaningfully shallower for one environment?
baselineDetail historical trend reporting on API attack-surface growth (new endpoints discovered, shadow-API count trend) over time, suitable for demonstrating program maturity to leadership, distinct from a real-time current-state dashboard.
baselineWhat is a customer-referenced onboarding timeline from contract signature to the platform producing a genuinely complete API inventory and useful detections, for an organization with a large, pre-existing, poorly-documented API footprint?
baselineTest web, mobile, and cloud applications for common vulnerabilities (e.g., injection, XSS, auth/session flaws, insecure APIs) (Application Security Testing).
baselinePerform Web Application testing including injection, broken authentication/session management, XSS, insecure direct object references, security misconfiguration, sensitive data exposure, missing function-level access control, CSRF, use of components with known vulnerabilities, unvalidated redirects/forwards, API/web services testing, session hijacking (MITM/sniffing/sidejacking), and malicious file upload.
baselineMust provide API support for seamless integration with other security tools (e.g., EDR, firewall management, IAM solutions), and should support integration with existing ticketing and incident management systems.
baselineSupport open APIs to enable bi-directional data flow or similar connection/integration with other systems or applications of the organization (e.g. SharePoint, Enterprise Data Warehouse).
baselineTest API endpoints (if applicable) for vulnerabilities such as broken authentication, excessive data exposure, and insufficient rate limiting.
baselineExternal Network Testing scope: Internet-facing infrastructure, web applications and APIs, email and DNS infrastructure, remote access solutions (VPN, RDP, etc.), and wireless infrastructure.
baselineApplication Security Testing (Pension Platform): web application penetration testing (OWASP Top 10), API security assessment, and authentication/authorization mechanisms.
baselineO365 Cloud Environment testing: identities and conditional access policies (MS Entra ID), API security assessment, and key data repositories (SharePoint, Teams).
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIHow does the platform discover all APIs — including shadow, zombie, and internal/east-west APIs — across environments, and how continuous is discovery?Answer key — what a strong answer shows
Strong answers cover shadow/zombie and internal APIs, name the discovery sources (live traffic, gateways, code, cloud), and confirm continuous (not point-in-time) inventory.
RFIHow does the platform assess API posture (OpenAPI/spec conformance, authentication and authorization configuration) and detect sensitive-data exposure in API traffic?Answer key — what a strong answer shows
Look for spec/contract conformance checks, auth/authz posture analysis, and detection of sensitive data (PII/secrets) flowing through APIs — not just a vulnerability scan.
RFPDescribe runtime detection of API attacks — BOLA/BFLA, abuse, account takeover, and business-logic attacks — the signals used, and accuracy. Quantify with customer references.Answer key — what a strong answer shows
Evidence-backed answers map to the OWASP API Top 10 (especially BOLA), describe business-logic abuse detection, give false-positive/accuracy figures, and cite customer outcomes.
Neutral strengths and gaps for each vendor in this category, drawn from vendors' own public materials — included so the questions above favor no single vendor. Gaps reflect capabilities not emphasized in public materials, not rankings.
Vendor
Strengths
Gaps / watch-outs
42CrunchAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Developer-first API security: OpenAPI audit/conformance scanning and contract-anchored runtime protection (shift-left).
Spec/contract-centric; broad runtime behavioral threat detection is less central than posture and testing.
AkamaiAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
RFIWhat API security testing does the platform provide pre-production (spec scanning, fuzzing, DAST, CI/CD), and how does it integrate with developer pipelines?Answer key — what a strong answer shows
Strong answers include shift-left testing (spec scan, DAST/fuzzing), CI/CD integration, and developer-friendly remediation guidance, distinguishing testing from runtime protection.
RFIIs detection inline (proxy/agent) or out-of-band (mirrored traffic/logs), what is the latency and scale impact, and does API data leave the customer boundary?Answer key — what a strong answer shows
Look for a clear statement of inline vs out-of-band architecture, latency/scale impact, and whether traffic/data (vs metadata) leaves the boundary — a common deployment constraint.
RFIWhat response and prevention is available (blocking, rate-limiting, WAAP enforcement, ticketing), and is it native or integration-dependent?Answer key — what a strong answer shows
Distinguish native inline prevention/WAAP from detection that hands off to a gateway/WAF or ticketing; look for rate-limiting and automated response.
RFIHow does the platform secure GenAI/LLM APIs and AI-agent/MCP traffic (prompt abuse, model endpoints, agent-to-API calls)?Answer key — what a strong answer shows
Look for protection of LLM/AI API endpoints and AI-agent/MCP traffic, with honest scope given how new this is. Treat broad 'AI-ready' claims skeptically without specifics.
RFPWhich gateways, CDNs, and CI/CD tools does the platform integrate with, and provide false-positive/accuracy figures with customer-validated evidence.Answer key — what a strong answer shows
Prefer broad, GA (not roadmap) integrations with API gateways/CDNs/CI tools, plus real false-positive/accuracy numbers backed by customer references over vendor benchmarks.
RFIWhat is the pricing model — per API endpoint, per request volume, or a flat enterprise tier — and given that API discovery inherently reveals more endpoints than initially estimated (shadow/zombie APIs), how does pricing respond to that discovery-driven growth?Answer key — what a strong answer shows
Same tension as other discovery-driven categories: successful shadow-API discovery inherently increases the counted endpoint population — ask explicitly how pricing handles a large post-onboarding jump.
RFPDoes the platform assess risk from third-party/partner APIs the organization CONSUMES (not just the APIs it exposes), including monitoring for a partner API's security posture or breach history affecting the customer's own risk?Answer key — what a strong answer shows
API risk isn't just about what you expose — a vendor addressing consumed third-party API risk (a real and often-overlooked attack surface) shows more complete scope than one focused solely on inbound/exposed APIs.
RFIWhat compliance-specific reporting does the platform generate for API-relevant requirements (e.g., PCI DSS API security provisions), and is this a built-in exportable auditor-ready report or something the customer must assemble manually?Answer key — what a strong answer shows
Native compliance-evidence generation is materially more valuable than raw findings requiring manual compilation for every audit cycle.
RFPDetail incident-forensics capability for a confirmed API breach — can the platform quickly reconstruct exactly which records/data were accessed via the compromised API and by whom, with a concrete turnaround-time example from a customer reference?Answer key — what a strong answer shows
Strong answers describe a fast, specific forensic reconstruction capability with a real turnaround-time figure — this is the highest-stakes use case (a confirmed breach), not just preventive monitoring.
RFIDoes API security coverage extend meaningfully to mobile-app backend APIs specifically (distinct traffic patterns and auth models from browser-facing web APIs), or is coverage effectively web-API-centric?Answer key — what a strong answer shows
Mobile-app backend APIs have distinct traffic and authentication patterns from browser-facing APIs — a vendor should clarify this scope explicitly rather than implying uniform coverage.
RFIHow consistent is discovery and protection depth across multi-cloud/hybrid API deployments — is coverage equally deep across AWS, Azure, GCP, and on-prem gateways, or meaningfully shallower for one environment?Answer key — what a strong answer shows
Ask for an honest per-environment coverage breakdown; uneven coverage across cloud providers is a common real gap a vendor should disclose rather than obscure.
RFPDetail historical trend reporting on API attack-surface growth (new endpoints discovered, shadow-API count trend) over time, suitable for demonstrating program maturity to leadership, distinct from a real-time current-state dashboard.Answer key — what a strong answer shows
Trend-over-time reporting is a distinct capability from a real-time technical dashboard — confirm this exists as a maintained, exportable report.
RFIWhat is a customer-referenced onboarding timeline from contract signature to the platform producing a genuinely complete API inventory and useful detections, for an organization with a large, pre-existing, poorly-documented API footprint?Answer key — what a strong answer shows
Strong answers give a concrete, customer-validated timeline for a realistic worst-case scenario (large undocumented API sprawl), not just a greenfield/small-footprint example.
RFPTest web, mobile, and cloud applications for common vulnerabilities (e.g., injection, XSS, auth/session flaws, insecure APIs) (Application Security Testing).
RFPPerform Web Application testing including injection, broken authentication/session management, XSS, insecure direct object references, security misconfiguration, sensitive data exposure, missing function-level access control, CSRF, use of components with known vulnerabilities, unvalidated redirects/forwards, API/web services testing, session hijacking (MITM/sniffing/sidejacking), and malicious file upload.
RFPMust provide API support for seamless integration with other security tools (e.g., EDR, firewall management, IAM solutions), and should support integration with existing ticketing and incident management systems.
RFPSupport open APIs to enable bi-directional data flow or similar connection/integration with other systems or applications of the organization (e.g. SharePoint, Enterprise Data Warehouse).
RFPTest API endpoints (if applicable) for vulnerabilities such as broken authentication, excessive data exposure, and insufficient rate limiting.
RFPExternal Network Testing scope: Internet-facing infrastructure, web applications and APIs, email and DNS infrastructure, remote access solutions (VPN, RDP, etc.), and wireless infrastructure.
RFPApplication Security Testing (Pension Platform): web application penetration testing (OWASP Top 10), API security assessment, and authentication/authorization mechanisms.
RFPO365 Cloud Environment testing: identities and conditional access policies (MS Entra ID), API security assessment, and key data repositories (SharePoint, Teams).
Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.
API security delivered on a global edge/CDN with integrated WAAP and large-scale traffic protection.
Edge-platform context; deep API behavioral discovery/posture is one part of a broad portfolio.
AktoAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
API discovery and automated security testing (including agentic AI/MCP), developer-friendly and fast to deploy.
Newer entrant; very-large-enterprise runtime-protection depth is still expanding versus incumbents.
Cequence SecurityAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
API protection at scale with bot/abuse defense and native inline mitigation across discovery, detection, and prevention.
Bot/abuse-defense heritage; shift-left testing breadth is less central than runtime.
EscapeAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Business-logic-aware DAST and attack-surface discovery from code to cloud, with AI-driven remediation.
Testing/DAST and ASM focus; inline runtime protection is less central.
Salt SecurityAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
API discovery plus runtime threat detection with behavioral/ML context across the full API lifecycle, and strong BOLA/abuse detection.
Detection-and-discovery heritage; inline prevention/WAAP enforcement is less central than out-of-band detection.
TraceableAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
API security across discovery, posture, threat detection, and protection with distributed-tracing context and a data-exposure focus.
Broad platform; depth varies by module, and tracing-based context can require instrumentation.
WallarmAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Inline API security and WAAP that blocks OWASP threats across protocols, plus API testing and AI-workload protection.
Inline/WAAP enforcement heritage; deep behavioral discovery and posture are less central than protection.