Onam Security
API Security

Which of your APIs are exposed, unauthenticated, or unmonitored?

Every API gateway you forgot about is still accepting requests.

API Security discovers every API surface across your clouds — gateways, load-balanced endpoints, function URLs and ingress routes — and evaluates them against 241 application and API posture rules, then correlates them with runtime detection signals.

10,000+
security rules
7
cloud providers
< 5 min
to first finding
100%
agentless
Why this matters

APIs multiply faster than anything else in a cloud estate.

A team ships an API Gateway for a prototype, wires it to a Lambda, disables the authoriser 'just for testing', and moves on. Two years later it is still public, still unauthenticated, still has no WAF, still has no logging — and it is the single cheapest way into your account. Nobody removed it because nobody knew it existed.

The risk of not knowing

If it is not surfaced today, it is exposed today. Attackers do not wait for your quarterly review — and neither do auditors.

Real-time detection, not periodic audits
How does it actually work?

The mechanism, not the marketing

  1. 1

    Discovery enumerates API surfaces across AWS, Azure, GCP, OCI, Alibaba and Kubernetes — API Gateway, App Gateway, Apigee, function URLs, ALB/NLB listeners and ingress resources.

  2. 2

    Each endpoint is evaluated against 241 application and API security rules covering authentication, authorisation, throttling, WAF association, TLS policy and logging.

  3. 3

    Endpoints are cross-referenced with the network graph so an API that is technically protected but reachable through an open path is treated as exposed.

  4. 4

    A CDR enricher joins runtime signals onto each endpoint — so an unauthenticated API that is also seeing anomalous request volume is escalated rather than queued.

  5. 5

    Shadow and orphaned APIs — endpoints with no recent traffic or no owning tag — are flagged for decommissioning.

What do you actually get?

Specific outputs, measurable outcomes

Complete API inventory across every cloud and cluster
Unauthenticated and open-endpoint detection
WAF coverage gaps on internet-facing APIs
TLS and cipher policy validation per endpoint
Rate limiting and throttling configuration checks
API access logging and monitoring coverage
Shadow API detection
endpoints nobody owns
Runtime correlation
API posture joined to live CDR detection signals
See it live

API Security in the real console.

Not a mockup — the actual Onam console on a live demo account, showing exactly what your team sees.

Network Security
Export Topology
5
VPCs
47
Security Groups
7
Internet-Exposed
23
Open Ports
Loading live data…
Your network edge, mapped
5 VPCs, 47 security groups — 7 internet-exposed resources with exact fix actions
Clip length
10s
Data
Demo account
FAQ

Questions we get a lot

Not as part of posture scanning. API Security reads configuration through read-only cloud APIs. Active testing against running endpoints is handled separately by the DAST scanner in the Code Security engine, which you point at targets explicitly.
Ready to see it live

Ready to see API Security in your cloud?

Connect a read-only role in three minutes. Your first findings surface in under five.