#16 · [Private Beta] Announcing Escape for REST APIs
After diligently focusing on GraphQL security, we are elated to venture into the realm of REST API Security Testing. Our commitment to enhancing API security is unwavering, and our latest offering showcases our dedication to this mission.
🔥 Key features¶
- Expansion to REST: Building on our stellar track record with GraphQL, we've expanded our horizons to encompass REST API Security Testing. This beta support aims to broaden our security umbrella.
- Feedback-Driven API Exploration Technology: This unique technology, initially crafted for GraphQL, has now been molded to cater to REST APIs, fortifying our ability to detect intricate business logic-aware security issues.
- Comprehensive Security Testing: Our REST Security testing includes a suite of checks:
- API Security Best Practices
- Compliance with OWASP API Top 10 2023 (and more to come)
- Detection of Advanced Business Logic issues, such as Sensitive Data Leaks
⏭️ Upcoming Features: Our roadmap for enhancing our REST offerings includes:¶
- Specification-less REST API Scanning: Recognizing the limitations of tools that solely rely on OpenAPI/Swagger documentation or Postman collections, we're pioneering a new wave of specification-less REST API security testing.
- Tailor-made remediation for various languages and frameworks such as Java Springboot, Express.js, and Django.
- API Catalog: Automated REST API discovery for an exhaustive security audit.
🔭 A Glimpse into the Future:¶
Our vision goes beyond REST and GraphQL. We're prepping the foundation to embrace other API technologies like gRPC, tRPC, and even SOAP. The ultimate aim? Assisting developers and security teams in identifying and rectifying security lapses in application business logic.
To achieve this, we've conceptualized a meta-model of API that zeroes in on the core business logic, transcending mere implementation specifics. This strategy has already proven its mettle with REST and GraphQL, and we're poised to extend its prowess to other standards.
📣 Wrapping Up:¶
We're thrilled to launch our private beta support for REST API testing within Escape. This monumental step aligns perfectly with our ambition of simplifying security for developers and AppSec teams. Join us in this exciting phase by registering for the REST beta directly from the Escape Platform! We value your partnership and can't wait for you to experience the enhanced Escape.
Your journey with Escape has been remarkable, and with the introduction of REST API testing, we are taking another giant leap towards a more secure digital landscape. We're eager to hear your feedback, and together, we'll continue redefining API security standards. Cheers to a more secure, adaptable, and forward-thinking platform!