Skip to content

Introduction to Escape

Escape helps security teams discover web applications and APIs, test them, and review findings.

Platform Overview

The platform is provided as a SaaS solution and centers around three key capabilities:

  • Attack Surface Management: Discovers, classifies, and tracks internal and external Assets, then runs surface security tests on monitored Assets.
  • Modern Security Testing in CI/CD (Business Logic Aware Dynamic Application Security Testing): Runs business logic security tests on APIs and Web Applications (including SPAs) and provides remediations directly in the CI/CD pipeline, starting at the development phase.
  • AI Pentesting: Uses AI agents to discover, analyze, and exploit security vulnerabilities through adaptive testing.

Choose Your Product

Escape offers three complementary security testing products. See Choose Your Product for a detailed comparison and decision guide.

Key Concepts

Attack Surface Management

The ASM is the result of Escape's Discovery feature. The ASM includes all identified and classified Assets (for example, Hosts, APIs, SPAs) within a specified scope, typically defined by a DNS or set of domains.

Business Logic Aware DAST

Business Logic Aware DAST refers to Business Logic Security Testing, performed by Escape's Business Logic Aware DAST Proprietary Engine against a Service. It simulates realistic attack scenarios beyond signature-based checks to uncover potential vulnerabilities in an application's logic and workflows.

AI Pentesting

AI Pentesting leverages advanced AI agents to autonomously discover, analyze, and exploit security vulnerabilities. Agents understand application context, reason about attack vectors, and adapt their testing strategies to discover complex, multi-step vulnerabilities that require understanding of business logic and application state.

Domain

A Domain name used as input for the ASM process. Escape initiates its discovery by enumerating and analyzing subdomains and Assets associated with this domain.

Asset

An Asset in Escape represents a Host, API Service, Web Application, or Repository. The list of supported Assets is defined in the ASM documentation.

Endpoint

An Endpoint is an actionable entry point within an API Service. For REST APIs, an Endpoint is defined by a path (URL) and method (for example, GET or POST). For GraphQL, an Endpoint corresponds to a specific query or mutation.

Schema

A Schema, sometimes referred to as Documentation or Specification, is a document that defines the interface and structure of an API Service's endpoints. Common examples include OpenAPI Specifications (formerly known as Swagger), GraphQL Introspection documents, and Postman Collections. Schemas help standardize how Services are described, ensuring that Business Logic Aware DAST can accurately target available endpoints.

Profile

A Profile is a configuration for the Business Logic Aware DAST scanning feature that includes various parameters (such as authentication details), environment settings, a schema, and the entire scan history for that Profile. This ensures consistency in repeated scans and helps track changes or improvements over time.

Location

A Location is a proxy environment through which Escape sends requests for both ASM and Business Logic Aware DAST:

  • Public Location: Hosted by Escape with a static IP, suitable for most external testing scenarios.
  • Private Location: Deployed by the user within their own infrastructure to securely test internal or firewall-protected assets.

Issue

An Issue can be a Vulnerability or Sensitive Data Leak from ASM, AI Pentesting, or Business Logic Aware DAST, clustered together for easier triage and management. A single Issue can represent multiple similar alerts (for example, the same vulnerability found on different endpoints of the same Service). See Issue Management for more details.

Sensitive Data

Sensitive Data represent data leaks uncovered through either the ASM or Business Logic Aware DAST processes. Examples include secrets, PII (personally identifiable information), API keys, or any other sensitive information potentially exposed to unauthorized parties. Sensitive Data are a subset of the Data Types (or Scalars).

Getting Started