Skip to content

#109 · New Security Test: Alert on High Volume of Exposed PII

We’ve introduced a new security test in the Escape scanner for GraphQL and REST APIs to identify excessive exposure of Personally Identifiable Information (PII) - a common sign of broken or missing access controls.

When multiple PII elements are returned in a single response, it often indicates that sensitive data is accessible without proper authentication or authorization, increasing the risk of:

  • Data breaches
  • Compliance violations (e.g., GDPR, CCPA)
  • Reputational and financial damage

By default, the test raises an alert when 4 or more PII fields are detected (pii_threshold: 4). This threshold can be customized to match your organization’s risk tolerance.

Learn more about how this test works and how to customize it in Escape’s documentation.