Skip to content

Release Notes

#19 · [Enterprise] Enhanced Stability and Scalability

With the surge in our user base and the subsequent unprecedented load on our systems, we recognized the paramount importance of both stability and scalability. Following our recent migration to AWS, we've not only refined the platform's stability but also fortified its capability to scale effortlessly. Our joint efforts with the AWS Engineering team have resulted in an infrastructure that is both robust and scalable.

⚙️ What's New:

  • 1. Redesigned Architecture & Data Pipeline: Our move to AWS ushered in comprehensive changes in our infrastructure. This revamped architecture is tailored to facilitate streamlined processes and provide an optimized user experience.
  • 2. Progressive Rollout: To ensure a smooth transition and heightened user experience, we are progressively introducing our newly developed pipeline to our customers.
  • 3. Intensified Focus on Stability: Addressing the inconsistencies experienced over recent weeks, we've intensified our efforts to enhance stability. Our collaboration with AWS ensures an unwavering and reliable platform.
  • 4. Embracing Scalability: In the face of unprecedented system loads, our platform is now equipped to scale seamlessly, ensuring uninterrupted service even during peak usage times.

Your unwavering trust and continued partnership motivate us to elevate our platform's standards. This update epitomizes our dedication to ensuring you benefit from a seamless, stable, and scalable Escape. Your feedback drives our progress, and we're eager to hear your thoughts on these enhancements. Here's to a scalable, stable, and superior platform!

#18 · [Enterprise] Migration to North-American Servers

To better serve our valued customers and optimize performance, we're excited to announce our server migration. We have transitioned from European servers to North American Servers, bringing you a swifter and more responsive experience.

🚀 Key benefits:

  • 1. Closer Proximity to Our Primary Customer Base: The shift to North-American servers ensures that our primary customer base benefits from reduced latency and enhanced data accessibility.
  • 2. Faster Scans: Experience significant improvements in scan speeds, making your security checks and validations quicker than ever before.
  • 3. Optimized Performance: Leveraging the robust infrastructure of AWS in North America, users can anticipate a smoother, faster, and more reliable platform experience.

This strategic migration underscores our commitment to delivering unparalleled performance and value to our customers. We understand the importance of speed and reliability in today's digital landscape, and with this move, we aim to exceed your expectations. As always, your feedback is paramount. Together, let's redefine excellence!

#17 · [Enterprise] Audit Logs

In our continuous effort to enhance the security, transparency, and manageability of our platform, we're thrilled to unveil the much-anticipated Audit Logs feature. With Audit Logs, enterprises can now have a holistic view of user activity, ensuring better compliance and oversight.

📋 What's New:

  • Centralized User Activity Stream: A unified stream capturing all user activity, enabling organizations to monitor and control access to information for enhanced security and compliance.
  • Comprehensive Event Logging: Capture application-specific user activities, security events, administrative changes, and more.

🔒 Enhanced Security Features:

  • Immutability: Ensure data remains unaltered. Deleted objects retain a separate action record.
  • Admin Accessibility: Built-in audit log viewer in the application for easy access by enterprise account admins.
  • Search: Efficiently search into events and fields like Actor, Date, Action, and Description.

We believe that adding Audit Logs will significantly enhance the accountability and transparency of our platform. Your feedback and experience are vital to us. Together, let's create a safer and more efficient digital environment. Looking forward to more updates and improvements!

#16 · [Private Beta] Announcing Escape for REST APIs

After diligently focusing on GraphQL security, we are elated to venture into the realm of REST API Security Testing. Our commitment to enhancing API security is unwavering, and our latest offering showcases our dedication to this mission.

🔥 Key features

  • Expansion to REST: Building on our stellar track record with GraphQL, we've expanded our horizons to encompass REST API Security Testing. This beta support aims to broaden our security umbrella.
  • Feedback-Driven API Exploration Technology: This unique technology, initially crafted for GraphQL, has now been molded to cater to REST APIs, fortifying our ability to detect intricate business logic-aware security issues.
  • Comprehensive Security Testing: Our REST Security testing includes a suite of checks:
    • API Security Best Practices
    • Compliance with OWASP API Top 10 2023 (and more to come)
    • Detection of Advanced Business Logic issues, such as Sensitive Data Leaks

⏭️ Upcoming Features: Our roadmap for enhancing our REST offerings includes:

  • Specification-less REST API Scanning: Recognizing the limitations of tools that solely rely on OpenAPI/Swagger documentation or Postman collections, we're pioneering a new wave of specification-less REST API security testing.
  • Tailor-made remediation for various languages and frameworks such as Java Springboot, Express.js, and Django.
  • API Catalog: Automated REST API discovery for an exhaustive security audit.

🔭 A Glimpse into the Future:

Our vision goes beyond REST and GraphQL. We're prepping the foundation to embrace other API technologies like gRPC, tRPC, and even SOAP. The ultimate aim? Assisting developers and security teams in identifying and rectifying security lapses in application business logic.

To achieve this, we've conceptualized a meta-model of API that zeroes in on the core business logic, transcending mere implementation specifics. This strategy has already proven its mettle with REST and GraphQL, and we're poised to extend its prowess to other standards.

📣 Wrapping Up:

We're thrilled to launch our private beta support for REST API testing within Escape. This monumental step aligns perfectly with our ambition of simplifying security for developers and AppSec teams. Join us in this exciting phase by registering for the REST beta directly from the Escape Platform! We value your partnership and can't wait for you to experience the enhanced Escape.

Your journey with Escape has been remarkable, and with the introduction of REST API testing, we are taking another giant leap towards a more secure digital landscape. We're eager to hear your feedback, and together, we'll continue redefining API security standards. Cheers to a more secure, adaptable, and forward-thinking platform!

#15 · Attack Surface Management with API Inventory

Escape is proud to announce the beginning of its brand new: API Inventory. Just input your company's domain, and Escape will detect exposed GraphQL endpoints and give you an overview of your Attack Surface, leveraging state-of-the-art scanning techniques.

🎊 Key highlights:

  • Endpoint discovery: Automatically identify every GraphQL endpoint exposed on your domains and subdomains.
  • Surface checks: Instantly identify open Introspections, leaking Schemas through Field Suggestions and public endpoints.

🛡 Benefits:

  • Comprehensive Security View: Security Engineers are equipped with an enhanced dashboard. This provides a 360° view of all exposed GraphQL applications, ensuring proactive management and mitigation of potential security threats.
  • Automated Refresh: Reduce manual oversight and error. Automated refresh ensures regular scanning of your attack surface.

🔜 Upcoming Enhancements:

  • We're always innovating! Our current methodology employs subdomain enumeration for the external attack surface. We're excited about expanding our capabilities. Expect richer features and broader scanning abilities in the forthcoming releases. Your security, our priority.

#14 · GitHub Single Sign-On (SSO) Integration

We are excited to announce that Escape now supports logging in with GitHub SSO and the existing Google SSO. This update aims to provide our users more flexibility and convenience while accessing our platform.

Key Highlights:

  • Users can now log in using their GitHub credentials, streamlining the authentication process.
  • This new SSO integration complements the existing Google SSO, providing users with multiple secure and seamless access options.
  • As always, Escape allows organizations to enforce SSO at the organizational level to ensure higher security and compliance.

How to Get Started:

To start using the GitHub SSO with Escape, click on the "Sign in with GitHub" button on the login page. As an organization administrator, you can enforce SSO by navigating to the organization settings and selecting the preferred SSO provider.

We hope this new feature will improve your overall experience with Escape. Should you have any questions or need assistance, please do not hesitate to reach out to our support team on Discord (https://discord.escape.tech) or via email (support@escape.tech)

#13 · OWASP Top Ten API 2023 Compliance

We are excited to announce that Escape supports the new OWASP Top 10 API 2023 RC. This significant update ensures that your applications built using Escape adhere to the latest security best practices, minimizing the risk of your GraphQL applications.

  • API01: Broken Object Level Authorization (BOLA)
  • API02: Broken Authentication
  • API03: Broken Object Property Level Authorization (BOPLA)
  • API04: Unrestricted Resource Consumption
  • API05: Broken Function Level Authorization (BFLA)
  • API06: Server Side Request Forgery (SSRF)
  • API07: Security Misconfiguration
  • API08: Lack of Protection from Automated Threats
  • API09: Improper Inventory Management
  • API10: Unsafe Consumption of APIs

We are committed to providing a secure environment for you and your users. If you have any questions or need assistance with implementing the OWASP Top 10 API 2023 guidelines, please get in touch with us on Discord or email support@escape.tech

Thank you for your continued support, and stay secure!

The Escape Team

#12 · Security Reporting in now available in Public Beta

We are excited to announce the launch of Escape's Reporting Feature in public beta. This powerful new addition aims to provide development and security teams with easy, comprehensive, and granular visibility into risk across their GraphQL applications. We aim to facilitate data-driven conversations that drive shared responsibility, accountability, and effective remediation across your organization.

Key Features

  1. Comprehensive Visibility: With reporting capabilities, both development and security teams can now gain the visibility needed to identify and address potential risks in their applications, providing you with accurate and timely insights.
  2. Identify and Prioritize Risks: Get insights into the most significant risks and set priorities for remediation.
  3. Vulnerability Analysis: Understand the type, volume, and criticality of vulnerabilities detected and applications impacted.
  4. Remediation Tracking: Monitor the pace and progress of remediation efforts.
  5. Long-term Metrics and Trends: Access high-level, long-term metrics to inform strategic decision-making.
  6. Easy to Use: The intuitive user interface and streamlined navigation make it simple for teams to access and understand critical data.

We hope the new reporting feature delivers valuable insights and helps your organization make informed decisions about application security. As always, feel free to contact our team va Discord or email (support@escape.tech) if you have any questions or need assistance.

Thank you for your continued support!

The Escape Team

#11 · [Enterprise] Introducing Permission-Based Access Control

We're excited to announce customizable Permission Based Access Control (RBAC) on the Escape platform. This enhancement allows you to invite all team members in your organization and assign specific permissions to them, ensuring a secure and efficient collaboration experience.

Key Features

  1. Flexible Permission Management: Define permissions such as read-only or read and write on any specific application, manage integrations, manage organization and billings, etc.
  2. Streamlined Team Collaboration: Bring everyone on board by inviting team members with the appropriate role assigned. This ensures they have the right access and privileges to perform their tasks efficiently.
  3. Improved Security: By assigning roles to team members, you can control access to sensitive information and prevent unauthorized users from changing your GraphQL apps.
  4. Easy to Manage: Escape's user-friendly interface allows you to easily manage your team's permissions, making it simple to add, modify, or revoke access as needed.

We hope the new PBAC feature is valuable in enhancing your team's collaboration and security. As always, we appreciate your feedback and support. Feel free to contact our support team (https://discord.escape.tech or support@escape.tech) with any questions or suggestions.

Happy collaborating!

The Escape Team

#10 · Posture Management

The Escape Team is excited to announce the release of its latest feature, API Security Posture Management for GraphQL. This feature proposes a single API Catalog view to explore the security, integrity, and performance of all GraphQL operations in one place.

Escape's API Posture Management works out-of-the-box with all GraphQL engines, including Apollo, Yoga, Hasura, and AWS AppSync, and seamlessly integrates into CI/CD.

The feature is currently in Beta. We can't wait for your feedback!