Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. API Security

API Security

Build an evaluation questionnaire →

How vendors compareSource labelsThe chip next to each vendor shows where the assessment came from and how independently it's been verified. A higher label is a more independent source — not a better product. See the full trust model at How trust works.

balanced · vendor-sourced

Neutral strengths and gaps for each vendor in this category, from vendors' own public materials — so the questionnaire favors no single vendor. Gaps reflect capabilities not emphasized in public materials, not rankings.

VendorStrengthsGaps / watch-outs
42Crunch AI baselineDeveloper-first API security: OpenAPI audit/conformance scanning and contract-anchored runtime protection (shift-left).Spec/contract-centric; broad runtime behavioral threat detection is less central than posture and testing.
Akamai AI baselineAPI security delivered on a global edge/CDN with integrated WAAP and large-scale traffic protection.Edge-platform context; deep API behavioral discovery/posture is one part of a broad portfolio.
Akto AI baselineAPI discovery and automated security testing (including agentic AI/MCP), developer-friendly and fast to deploy.Newer entrant; very-large-enterprise runtime-protection depth is still expanding versus incumbents.
Cequence Security AI baselineAPI protection at scale with bot/abuse defense and native inline mitigation across discovery, detection, and prevention.Bot/abuse-defense heritage; shift-left testing breadth is less central than runtime.
Escape AI baselineBusiness-logic-aware DAST and attack-surface discovery from code to cloud, with AI-driven remediation.Testing/DAST and ASM focus; inline runtime protection is less central.
Salt Security AI baselineAPI discovery plus runtime threat detection with behavioral/ML context across the full API lifecycle, and strong BOLA/abuse detection.Detection-and-discovery heritage; inline prevention/WAAP enforcement is less central than out-of-band detection.
Traceable AI baselineAPI security across discovery, posture, threat detection, and protection with distributed-tracing context and a data-exposure focus.Broad platform; depth varies by module, and tracing-based context can require instrumentation.
Wallarm AI baselineInline API security and WAAP that blocks OWASP threats across protocols, plus API testing and AI-workload protection.Inline/WAAP enforcement heritage; deep behavioral discovery and posture are less central than protection.

Analyst coverage

Public fact of coverage — not proprietary ratings
📊

No analyst coverage recorded yet

Integration ecosystemUI-25 — integration network graphEvery API Security vendor with a detected integration, plus the vendors they integrate with (any category) — integrations are mostly cross-category in practice, so this shows the real neighborhood, not just same-category edges. API Security vendors are highlighted; connected vendors from other categories are dimmer. Circle size = how many integrations that vendor has. Sourced from each vendor's own published integration/partner pages (see UI-12).

222 edges

Status alerts in API SecurityUI-182 — category status-page rollupVendors in this category whose own public status page most recently reported degraded performance or a major outage — sourced from each vendor's real status page, never inferred. Not a live feed: each row shows exactly when it was last checked (rechecked roughly every 30 days), so treat this as a recent signal to verify directly on the vendor's own status page, not a real-time monitor.

  • Impervadegradedstatus page ↗as of 8/14/2026
  • Akamaidegradedstatus page ↗as of 8/14/2026

CVE exposure in API SecurityUI-71 — vendor/CVE treemapEvery API Security vendor with at least one tracked CVE, sized by count — same data and coloring as the full-catalog version on the Browse page, scoped to just this category.

RSS ⇢

12 vendors with at least one tracked CVE, sized by how many. Color = relative volume.About CVE trackingSourced from the public NVD database, matched by vendor name (same data as each vendor's own CVE list). Tracking is capped at 100 CVEs per vendor as a scan guard — no vendor has hit that cap yet. Vendor-level only, not per-product/version — always check the linked NVD record before drawing conclusions about a specific product.

Cloudflare80 CVEsAkamai22 CVEsImperva18 CVEsEscape15 CVEsFastly10 CVEsAcunetix6 CVEsTraceable4 CVEsGhost Security2 CVEsSecureLayer72 CVEsData Theorem1 CVEMend1 CVEInvicti1 CVE

Security posture in API SecurityUI-108 — category security rollupA category-level rollup of the same per-vendor signals shown on each vendor's own page (UI-90/99/102): security-header checks against each vendor's own homepage, and keyword-matched compliance certifications. Coverage is partial — only vendors checked so far are counted, not the whole category — so this describes what's known, not a claim about every vendor in API Security.

13/16
checked vendors have a strong security-header posture (3+/5)
0
vendors with a disclosed certification
16/40
vendors in this category checked so far

Vendors (40)

⚖ Compare vendors side-by-side

Pick 2–4 vendors, then compare their products and neutral strengths/gaps.

0/4 selected
  • 42Crunch9 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security testing and protection.
    42Crunch API Audit42Crunch API Protection42Crunch API Scan42Crunch API Security Platform42Crunch API Security Testing42Crunch API Discovery42Crunch API Runtime Threat Protection42Crunch API Protection (Micro-firewall)42Crunch Secure MCP Server
  • Acunetix2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API vulnerability scanning and testing for REST, SOAP, and GraphQL APIs
    Acunetix API Security Testing
  • Akamai17 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Edge security, WAF/DDoS, and API security.
    Noname Security PlatformAkamai API Security
  • Akto7 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API and agentic-AI security: discovery of APIs/MCPs/AI agents, automated red teaming, posture management, guardrails, and runtime protection.
    Akto Agentic AI DiscoveryAkto Automated Agentic Red TeamingAkto Agentic Security Posture ManagementAkto MCP and AI Agents GuardrailsAkto Agentic Runtime Protection
  • Ammune.ai1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security platform with discovery, WAF, bot protection, and DDoS defense
    Ammune API Discovery
  • APIsec1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered API security testing platform with continuous attack simulation
    APIsec API Security
  • Cequence Security5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security and bot defense.
    Cequence API SecurityCequence Bot ManagementCequence CQAI
  • Cloudflare11 productsUnclaimed
    Cloudflare API Shield
  • CloudMatos10 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Runtime security gateway for multi-agent AI systems with policy enforcement
    CloudMatos MatosSphere API Security
  • Corsha6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Machine identity provider for operational systems: dynamic machine identities, connection discovery, and identity-based microsegmentation.
    Corsha Automated Machine Trust
  • Data Theorem6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security platform for discovery, testing, and runtime protection
    Data Theorem API Security
  • Edgescan6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API discovery, vulnerability scanning, and penetration testing platform
    Edgescan API Security Testing
  • Equixly1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered API security testing platform for continuous vulnerability scanning
    Equixly The Agentic AI Hacker
  • Escape8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security from code to cloud: attack surface management, business-logic-aware DAST, AI pentesting, and AI-powered remediation.
    Escape Attack Surface ManagementEscape Business-Logic-Aware DASTEscape AI PentestingEscape AI-Powered RemediationEscape API Security
  • eXate5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Data classification, privacy & sovereignty platform with ABAC controls.
    eXate APIgator
  • Fastly9 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Edge cloud platform with WAF/DDoS.
    API SecurityFastly API Security
  • Forum Systems3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    IAM platform unifying auth, federation, and SSO with no per-user fees.
    Forum Systems Forum SentryForum Systems Sentry
  • Ghost Security1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-driven code analysis tool for API discovery and vulnerability detection
    Ghost Security Exorcist
  • Hypernative5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Onchain firewall that blocks malicious blockchain transactions in real-time
    Hypernative Guardian
  • Impart Security5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Agent-based runtime firewall for web apps and APIs with AI-driven rules
    Impart AIImpart Precision LogGenImpart WAF
  • Imperva14 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application and data security (WAF/DDoS).
    API SecurityImperva API Security
  • Indusface6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Managed DDoS protection service for websites and APIs with 24x7 SOC monitoring
    Indusface AppTrana - API Protection
  • Invicti4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security testing platform with discovery, scanning, and remediation
    Invicti API Security
  • Levo1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Runtime application security platform for API and AI stack protection
    Levo Runtime Application Security
  • Mend6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Application security (SCA/SAST), formerly WhiteSource.
    Mend API Security
  • Operant AI9 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Runtime defense for AI and APIs: discovery, detection, and real-time response across agents, MCP, and Kubernetes-native infrastructure.
    Operant AI API Threat Protection
  • Orca Security15 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Agentless cloud security and posture management.
    Orca API Security
  • Prancer Enterprise5 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-driven autonomous pentesting platform for continuous vulnerability discovery
    Prancer Autonomous API Security
  • Prophaze Technologies Pvt.Ltd.2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered API security platform with threat detection and discovery
    Prophaze API Security
  • Pynt3 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security testing platform with LLM-powered context awareness and attack simulation
    Pynt API Security TestingPynt Detect Sensitive Data and Excessive Data Exposure
  • Salt Security8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security platform.
    Salt Surface MapSalt ConnectSalt CollectSalt ProtectSalt Agentic Security PlatformSalt Security IlluminateSalt Security Salt CollectSalt Security Salt Connect
  • SecureLayer71 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security scanner for automated vulnerability detection in CI/CD pipelines
    SecureLayer7 BugDazz API Security Scanner
  • Spherical Defense1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    AI-powered API security platform using unsupervised deep learning
    Spherical Defense Autonomous Protection
  • StackHawk4 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API discovery tool that maps application attack surface from source code
    StackHawk API Discovery
  • Syhunt1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security testing tool for detecting vulnerabilities in web APIs
    Syhunt SyhuntAPI
  • TeejLab1 productAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API discovery, security, governance & lifecycle mgmt platform for enterprises
    TeejLab API Discovery Manager
  • ThreatX2 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Behavioral analytics platform for API and application threat detection
    ThreatX Attacker-Centric Behavioral Analytics
  • Traceable6 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security and observability.
    Traceable API Posture ManagementTraceable API Security TestingTraceable API ProtectionTraceable Attack Detection & Threat HuntingTraceable API Security Data LakeTraceable AppSec
  • Upstream Security12 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    Cloud security for connected vehicles and mobility.
    Upstream Runtime AI and API SecurityUpstream Fusion API Security
  • Wallarm8 productsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Unclaimed
    API security and WAAP with AI-workload protection: inline API protection, WAAP, API security testing, and runtime enforcement for AI agents.
    Wallarm API SecurityWallarm WAAPWallarm API Security TestingWallarm AI HypervisorWallarm Infrastructure Discovery