APIs multiply faster than anything else in a cloud estate.
A team ships an API Gateway for a prototype, wires it to a Lambda, disables the authoriser 'just for testing', and moves on. Two years later it is still public, still unauthenticated, still has no WAF, still has no logging — and it is the single cheapest way into your account. Nobody removed it because nobody knew it existed.
The risk of not knowing
If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.
The mechanism, not the marketing
- 1
Discovery enumerates API surfaces across AWS, Azure, GCP, OCI, Alibaba and Kubernetes — API Gateway, App Gateway, Apigee, function URLs, ALB/NLB listeners and ingress resources.
- 2
Each endpoint is evaluated against 241 application and API security rules covering authentication, authorisation, throttling, WAF association, TLS policy and logging.
- 3
Endpoints are cross-referenced with the network graph so an API that is technically protected but reachable through an open path is treated as exposed.
- 4
A CDR enricher joins runtime signals onto each endpoint — so an unauthenticated API that is also seeing anomalous request volume is escalated rather than queued.
- 5
Shadow and orphaned APIs — endpoints with no recent traffic or no owning tag — are flagged for decommissioning.
Specific outputs, measurable outcomes
API Security in the real console.
Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.
Questions we get a lot
Ready to see API Security in your cloud?
Connect a read-only role in three minutes. Your first findings surface in under five.