Skip to content

Platform

#22 · [Enterprise] SSO, Fine-grained Authentication & Identity Federation

We're thrilled to announce the enhancement of our authentication mechanisms. As part of our continuous efforts to bolster security and improve user experience, we have introduced Fine-grained Authentication, Identity Federation, SAML, and SSO capabilities into Escape.

⚙️ What's New:

  • 1. Fine-grained Authentication: Our advanced authentication system now offers detailed access controls, ensuring that users have appropriate permissions tailored to their roles and responsibilities.
  • 2. Identity Federation: Seamlessly integrate Escape with your organization's Identity Provider (IdP). This feature simplifies user management while maintaining the highest security standards.
  • 3. SAML (Security Assertion Markup Language) Support: Integrate Escape with any SAML 2.0 compliant Identity Provider. This ensures secure and streamlined single sign-on capabilities.
  • 4. Single Sign-On (SSO): A more seamless login experience. Users can now access Escape using a single set of credentials, reducing password fatigue and enhancing security.

Your data security and user experience are of paramount importance to us. This update epitomizes our dedication to ensuring you benefit from a seamless, secure, and efficient authentication process in Escape. We encourage you to check out our documentation for detailed information and setup guides.

In Conclusion:

With these enhancements, we aim to simplify your interaction with Escape while maintaining the highest security standards. As always, your feedback drives our progress, and we're eager to hear your thoughts on these updates.

#21 · Scan Internal APIs using Escape's Proxy

In our pursuit to enhance security and provide more accessibility, we've rolled out a feature allowing users to scan their internal APIs, which is especially beneficial for those who can't whitelist IPs. By leveraging a custom proxy, this process becomes a breeze.

⚙️ What's New:

  • Custom Proxy Deployment: If you're unable to whitelist IPs but can deploy a service and expose its IP, you now have the flexibility of a custom proxy. While you can choose any proxy, the Escape proxy is readily available for use. Ensure to allow incoming traffic to this proxy via your firewall settings.

  • Essential Setup Information: To get started, you'll need a few details:

    • User: The user permitted to connect to the proxy. If you're using the Escape proxy, this would be your organization ID.
    • Password: The password for the aforementioned user. For the Escape proxy users, this translates to your API key.
    • IP & Port: The IP address and port to connect to your proxy.
  • Configuration Guide: For a step-by-step guide on setting up the proxy and integrating it into your scan configuration, please refer to our detailed documentation.

With this update, we continue to simplify and fortify the security scanning process for our users. The ability to scan internal APIs using a proxy not only fills a pivotal gap in security testing but also caters to a broader range of user requirements. Your insights shape our journey, and we're eager for your feedback on this new addition.

#20 · Announcing Escape's Public Status Page

📢 Announcing Escape's Public Status Page

In our continued commitment to transparency and reliability, we're excited to introduce Escape's Public Status Page. This page serves as your go-to source for real-time insights into our platform's uptime and Service Level Agreement (SLA) adherence.

⚙️ What's New:

  • 1. Real-Time Uptime Monitoring: Keep track of our platform's operational status instantly. You'll now have visibility into our uptime performance, ensuring you're always in the know.
  • 2. SLA Insights: Transparency is key. With our public status page, you can gauge our adherence to the promised Service Level Agreement, ensuring we're upholding our commitment to you.
  • 3. Instant Notifications: No more guesswork. Should any interruptions occur, our status page provides immediate notifications using RSS Feed, keeping you informed every step of the way.

Your trust in Escape is paramount, and this update is a testament to our dedication to being open, accountable, and reliable. We invite you to visit our status page and stay updated on our platform's performance. Your continued feedback propels us forward, and we're excited to keep innovating for you. Here's to continuous transparency and improved reliability!

#19 · [Enterprise] Enhanced Stability and Scalability

With the surge in our user base and the subsequent unprecedented load on our systems, we recognized the paramount importance of both stability and scalability. Following our recent migration to AWS, we've not only refined the platform's stability but also fortified its capability to scale effortlessly. Our joint efforts with the AWS Engineering team have resulted in an infrastructure that is both robust and scalable.

⚙️ What's New:

  • 1. Redesigned Architecture & Data Pipeline: Our move to AWS ushered in comprehensive changes in our infrastructure. This revamped architecture is tailored to facilitate streamlined processes and provide an optimized user experience.
  • 2. Progressive Rollout: To ensure a smooth transition and heightened user experience, we are progressively introducing our newly developed pipeline to our customers.
  • 3. Intensified Focus on Stability: Addressing the inconsistencies experienced over recent weeks, we've intensified our efforts to enhance stability. Our collaboration with AWS ensures an unwavering and reliable platform.
  • 4. Embracing Scalability: In the face of unprecedented system loads, our platform is now equipped to scale seamlessly, ensuring uninterrupted service even during peak usage times.

Your unwavering trust and continued partnership motivate us to elevate our platform's standards. This update epitomizes our dedication to ensuring you benefit from a seamless, stable, and scalable Escape. Your feedback drives our progress, and we're eager to hear your thoughts on these enhancements. Here's to a scalable, stable, and superior platform!

#18 · [Enterprise] Migration to North-American Servers

To better serve our valued customers and optimize performance, we're excited to announce our server migration. We have transitioned from European servers to North American Servers, bringing you a swifter and more responsive experience.

🚀 Key benefits:

  • 1. Closer Proximity to Our Primary Customer Base: The shift to North-American servers ensures that our primary customer base benefits from reduced latency and enhanced data accessibility.
  • 2. Faster Scans: Experience significant improvements in scan speeds, making your security checks and validations quicker than ever before.
  • 3. Optimized Performance: Leveraging the robust infrastructure of AWS in North America, users can anticipate a smoother, faster, and more reliable platform experience.

This strategic migration underscores our commitment to delivering unparalleled performance and value to our customers. We understand the importance of speed and reliability in today's digital landscape, and with this move, we aim to exceed your expectations. As always, your feedback is paramount. Together, let's redefine excellence!

#17 · [Enterprise] Audit Logs

In our continuous effort to enhance the security, transparency, and manageability of our platform, we're thrilled to unveil the much-anticipated Audit Logs feature. With Audit Logs, enterprises can now have a holistic view of user activity, ensuring better compliance and oversight.

📋 What's New:

  • Centralized User Activity Stream: A unified stream capturing all user activity, enabling organizations to monitor and control access to information for enhanced security and compliance.
  • Comprehensive Event Logging: Capture application-specific user activities, security events, administrative changes, and more.

🔒 Enhanced Security Features:

  • Immutability: Ensure data remains unaltered. Deleted objects retain a separate action record.
  • Admin Accessibility: Built-in audit log viewer in the application for easy access by enterprise account admins.
  • Search: Efficiently search into events and fields like Actor, Date, Action, and Description.

We believe that adding Audit Logs will significantly enhance the accountability and transparency of our platform. Your feedback and experience are vital to us. Together, let's create a safer and more efficient digital environment. Looking forward to more updates and improvements!

#16 · [Private Beta] Announcing Escape for REST APIs

After diligently focusing on GraphQL security, we are elated to venture into the realm of REST API Security Testing. Our commitment to enhancing API security is unwavering, and our latest offering showcases our dedication to this mission.

🔥 Key features

  • Expansion to REST: Building on our stellar track record with GraphQL, we've expanded our horizons to encompass REST API Security Testing. This beta support aims to broaden our security umbrella.
  • Feedback-Driven API Exploration Technology: This unique technology, initially crafted for GraphQL, has now been molded to cater to REST APIs, fortifying our ability to detect intricate business logic-aware security issues.
  • Comprehensive Security Testing: Our REST Security testing includes a suite of checks:
    • API Security Best Practices
    • Compliance with OWASP API Top 10 2023 (and more to come)
    • Detection of Advanced Business Logic issues, such as Sensitive Data Leaks

⏭️ Upcoming Features: Our roadmap for enhancing our REST offerings includes:

  • Specification-less REST API Scanning: Recognizing the limitations of tools that solely rely on OpenAPI/Swagger documentation or Postman collections, we're pioneering a new wave of specification-less REST API security testing.
  • Tailor-made remediation for various languages and frameworks such as Java Springboot, Express.js, and Django.
  • API Catalog: Automated REST API discovery for an exhaustive security audit.

🔭 A Glimpse into the Future:

Our vision goes beyond REST and GraphQL. We're prepping the foundation to embrace other API technologies like gRPC, tRPC, and even SOAP. The ultimate aim? Assisting developers and security teams in identifying and rectifying security lapses in application business logic.

To achieve this, we've conceptualized a meta-model of API that zeroes in on the core business logic, transcending mere implementation specifics. This strategy has already proven its mettle with REST and GraphQL, and we're poised to extend its prowess to other standards.

📣 Wrapping Up:

We're thrilled to launch our private beta support for REST API testing within Escape. This monumental step aligns perfectly with our ambition of simplifying security for developers and AppSec teams. Join us in this exciting phase by registering for the REST beta directly from the Escape Platform! We value your partnership and can't wait for you to experience the enhanced Escape.

Your journey with Escape has been remarkable, and with the introduction of REST API testing, we are taking another giant leap towards a more secure digital landscape. We're eager to hear your feedback, and together, we'll continue redefining API security standards. Cheers to a more secure, adaptable, and forward-thinking platform!

#14 · GitHub Single Sign-On (SSO) Integration

We are excited to announce that Escape now supports logging in with GitHub SSO and the existing Google SSO. This update aims to provide our users more flexibility and convenience while accessing our platform.

Key Highlights:

  • Users can now log in using their GitHub credentials, streamlining the authentication process.
  • This new SSO integration complements the existing Google SSO, providing users with multiple secure and seamless access options.
  • As always, Escape allows organizations to enforce SSO at the organizational level to ensure higher security and compliance.

How to Get Started:

To start using the GitHub SSO with Escape, click on the "Sign in with GitHub" button on the login page. As an organization administrator, you can enforce SSO by navigating to the organization settings and selecting the preferred SSO provider.

We hope this new feature will improve your overall experience with Escape. Should you have any questions or need assistance, please do not hesitate to reach out to our support team on Discord (https://discord.escape.tech) or via email (support@escape.tech)

#13 · OWASP Top Ten API 2023 Compliance

We are excited to announce that Escape supports the new OWASP Top 10 API 2023 RC. This significant update ensures that your applications built using Escape adhere to the latest security best practices, minimizing the risk of your GraphQL applications.

  • API01: Broken Object Level Authorization (BOLA)
  • API02: Broken Authentication
  • API03: Broken Object Property Level Authorization (BOPLA)
  • API04: Unrestricted Resource Consumption
  • API05: Broken Function Level Authorization (BFLA)
  • API06: Server Side Request Forgery (SSRF)
  • API07: Security Misconfiguration
  • API08: Lack of Protection from Automated Threats
  • API09: Improper Inventory Management
  • API10: Unsafe Consumption of APIs

We are committed to providing a secure environment for you and your users. If you have any questions or need assistance with implementing the OWASP Top 10 API 2023 guidelines, please get in touch with us on Discord or email support@escape.tech

Thank you for your continued support, and stay secure!

The Escape Team

#12 · Security Reporting in now available in Public Beta

We are excited to announce the launch of Escape's Reporting Feature in public beta. This powerful new addition aims to provide development and security teams with easy, comprehensive, and granular visibility into risk across their GraphQL applications. We aim to facilitate data-driven conversations that drive shared responsibility, accountability, and effective remediation across your organization.

Key Features

  1. Comprehensive Visibility: With reporting capabilities, both development and security teams can now gain the visibility needed to identify and address potential risks in their applications, providing you with accurate and timely insights.
  2. Identify and Prioritize Risks: Get insights into the most significant risks and set priorities for remediation.
  3. Vulnerability Analysis: Understand the type, volume, and criticality of vulnerabilities detected and applications impacted.
  4. Remediation Tracking: Monitor the pace and progress of remediation efforts.
  5. Long-term Metrics and Trends: Access high-level, long-term metrics to inform strategic decision-making.
  6. Easy to Use: The intuitive user interface and streamlined navigation make it simple for teams to access and understand critical data.

We hope the new reporting feature delivers valuable insights and helps your organization make informed decisions about application security. As always, feel free to contact our team va Discord or email (support@escape.tech) if you have any questions or need assistance.

Thank you for your continued support!

The Escape Team