Skip to content

2023

#14 · GitHub Single Sign-On (SSO) Integration

We are excited to announce that Escape now supports logging in with GitHub SSO and the existing Google SSO. This update aims to provide our users more flexibility and convenience while accessing our platform.

Key Highlights:

  • Users can now log in using their GitHub credentials, streamlining the authentication process.
  • This new SSO integration complements the existing Google SSO, providing users with multiple secure and seamless access options.
  • As always, Escape allows organizations to enforce SSO at the organizational level to ensure higher security and compliance.

How to Get Started:

To start using the GitHub SSO with Escape, click on the "Sign in with GitHub" button on the login page. As an organization administrator, you can enforce SSO by navigating to the organization settings and selecting the preferred SSO provider.

We hope this new feature will improve your overall experience with Escape. Should you have any questions or need assistance, please do not hesitate to reach out to our support team on Discord (https://discord.escape.tech) or via email (support@escape.tech)

#13 · OWASP Top Ten API 2023 Compliance

We are excited to announce that Escape supports the new OWASP Top 10 API 2023 RC. This significant update ensures that your applications built using Escape adhere to the latest security best practices, minimizing the risk of your GraphQL applications.

  • API01: Broken Object Level Authorization (BOLA)
  • API02: Broken Authentication
  • API03: Broken Object Property Level Authorization (BOPLA)
  • API04: Unrestricted Resource Consumption
  • API05: Broken Function Level Authorization (BFLA)
  • API06: Server Side Request Forgery (SSRF)
  • API07: Security Misconfiguration
  • API08: Lack of Protection from Automated Threats
  • API09: Improper Inventory Management
  • API10: Unsafe Consumption of APIs

We are committed to providing a secure environment for you and your users. If you have any questions or need assistance with implementing the OWASP Top 10 API 2023 guidelines, please get in touch with us on Discord or email support@escape.tech

Thank you for your continued support, and stay secure!

The Escape Team

#12 · Security Reporting in now available in Public Beta

We are excited to announce the launch of Escape's Reporting Feature in public beta. This powerful new addition aims to provide development and security teams with easy, comprehensive, and granular visibility into risk across their GraphQL applications. We aim to facilitate data-driven conversations that drive shared responsibility, accountability, and effective remediation across your organization.

Key Features

  1. Comprehensive Visibility: With reporting capabilities, both development and security teams can now gain the visibility needed to identify and address potential risks in their applications, providing you with accurate and timely insights.
  2. Identify and Prioritize Risks: Get insights into the most significant risks and set priorities for remediation.
  3. Vulnerability Analysis: Understand the type, volume, and criticality of vulnerabilities detected and applications impacted.
  4. Remediation Tracking: Monitor the pace and progress of remediation efforts.
  5. Long-term Metrics and Trends: Access high-level, long-term metrics to inform strategic decision-making.
  6. Easy to Use: The intuitive user interface and streamlined navigation make it simple for teams to access and understand critical data.

We hope the new reporting feature delivers valuable insights and helps your organization make informed decisions about application security. As always, feel free to contact our team va Discord or email (support@escape.tech) if you have any questions or need assistance.

Thank you for your continued support!

The Escape Team

#11 · [Enterprise] Introducing Permission-Based Access Control

We're excited to announce customizable Permission Based Access Control (RBAC) on the Escape platform. This enhancement allows you to invite all team members in your organization and assign specific permissions to them, ensuring a secure and efficient collaboration experience.

Key Features

  1. Flexible Permission Management: Define permissions such as read-only or read and write on any specific application, manage integrations, manage organization and billings, etc.
  2. Streamlined Team Collaboration: Bring everyone on board by inviting team members with the appropriate role assigned. This ensures they have the right access and privileges to perform their tasks efficiently.
  3. Improved Security: By assigning roles to team members, you can control access to sensitive information and prevent unauthorized users from changing your GraphQL apps.
  4. Easy to Manage: Escape's user-friendly interface allows you to easily manage your team's permissions, making it simple to add, modify, or revoke access as needed.

We hope the new PBAC feature is valuable in enhancing your team's collaboration and security. As always, we appreciate your feedback and support. Feel free to contact our support team (https://discord.escape.tech or support@escape.tech) with any questions or suggestions.

Happy collaborating!

The Escape Team

#10 · Posture Management

The Escape Team is excited to announce the release of its latest feature, API Security Posture Management for GraphQL. This feature proposes a single API Catalog view to explore the security, integrity, and performance of all GraphQL operations in one place.

Escape's API Posture Management works out-of-the-box with all GraphQL engines, including Apollo, Yoga, Hasura, and AWS AppSync, and seamlessly integrates into CI/CD.

The feature is currently in Beta. We can't wait for your feedback!

#9 · Public API improvements

Escape's public HTTP API is getting better!

It is now possible to progrmmatically fetch your scans and applications from the public api. The documentation has also been improved in order to clearly show the API's base URL, and to present the new routes.

We also added the organization's id on the organization display of the platform. This way, you can now easily retrieve it to start using the API.

See the organization page

Check the documentation for our public HTTP API

#8 · Application-wise integrations

Hello everyone ! This week sees the release of a feature that has been heavily asked to us: You can now declare Slack, Discord and email notifications per applications.

If you had previous integrations setup, nothing changes, you will still be notified for every applications your organization has on Escape.

However, when creating a new Discord/Slack/email-based integration, you will be offered to select one or more applications of your organization. Only these applications will trigger the notification to be sent.

#7 · New PDF reports with Compliance and Detailed remediations

We are excited to announce the latest addition to our Escape security platform: the ability to generate a PDF report for auditors and customers:

• Quickly provide the documentation required for vendor assessments, accelerating sales with customers who prioritize security.

• Enables swift compliance with SOC 2 or ISO 27001, generating a PDF report with evidence in seconds.

• Share vulnerability details with auditors or developers for efficient resolution. Each failed test case by Escape results in a finding, including technical details for easy remediation and enhanced web app security.

We understand the importance of security and compliance and are dedicated to providing our customers with the tools they need to ensure they are meeting the necessary standards.

If you have any questions about the Escape security platform or this new feature, please don’t hesitate to contact our team. We are always happy to help and provide additional information.

#6 · Static IP and Proxy

Hey everyone! We’re excited to announce a new feature to our Escape security platform: static IP and proxy!

This advanced configuration option allows you to run the Escape scanner through the proxy of your choice.

Many of you wanted another way than headers to identify the requests from the Escape scanner. At Escape, we now provide a static IP option. Please get in touch with us if you wish to whitelist our IPs.

See more about Proxy and Static IP in the Advanced Configuration section of our developer documentation.

If you have any questions or feedback, don't hesitate to reach out - we're here to help. Thanks for being part of the Escape Community!

#5 · Coverage assessment

Welcome to the latest update on our Escape Security Platform! We’re excited to announce the latest feature to help keep your API secure and up-to-date. Today, we’re introducing a new testing coverage assessment to help you test your API's entirety.

With this testing coverage feature, you can effortlessly visualize the proportion of your API you want to test and obtain immediate actions on improving your scan configuration to benefit from the full potential of Escape.

With the testing coverage feature, you can be assured that your API security scan is properly configured and functioning as expected.

See our Developer documentation to understand how to improve your coverage :)

We’re excited to bring you this latest feature and hope it helps you improve how you configure and secure your API. Try out the testing coverage feature today and see how it can help you!