API Protection Reviews and Ratings

What are API Protection?

API protection products protect APIs from exploits, abuse and access violations, and assist in remediating API exposures. These products perform API discovery and posture management and provide runtime protection. API protection products may be delivered as cloud-based or on-premises solutions.

API protection products serve to provide capabilities to organizations that need to protect their data assets primarily from attacks against the first-party APIs they expose publicly. They also need to provide coverage for the internal APIs and the third-party APIs that they may consume. API products deliver a catalog of inventoried APIs, a prioritized list of remediations of API exposures and alerts on suspicious or malicious activity on APIs.

Product Listings

Filter by

Products 1 - 20 of 42

Check Point Software Technologies Ltd. is a company that offers cyber security solutions to governmental and business entities around the world. The company's solutions are designed to safeguard against a variety of cyber threats including malware and ransomware. With Check Point's multilevel security architecture, dubbed 'Infinity Total Protection with Gen V advanced threat prevention', cloud, network, and mobile devices of businesses are protected. Additionally, Check Point provides a comprehensive and easy-to-manage control security management system.

Show More Details

Akamai powers and protects life online. Leading companies worldwide choose Akamai to build, deliver, and secure their digital experiences – helping billions of people live, work, and play every day. Akamai Connected Cloud, a massively distributed edge and cloud platform, puts apps and experiences closer to users and keeps threats farther away.

Show More Details

Imperva is a cybersecurity firm that assists organizations in safeguarding critical applications, APIs, and data across various scales and locations. It adopts a comprehensive approach that amalgamates edge, application security, and data security to offer protection to businesses at all levels of their digital journey. Imperva Threat Research and the worldwide intelligence community contribute to Imperva's knowledge of the evolving threat landscape. This understanding allows incorporation of the most recent security, privacy, and compliance expertise into the offered solutions.

Show More Details

Googlers is a company that creates products intended to create opportunities for an extensive audience, regardless of their location across the globe. The company values diverse perspectives, imaginations and non-conformity to predefined norms and impossibilities. The goal is to build products while incorporating uniqueness of each individual involved in this process, aiming to make their products accessible and useful to all.

Show More Details

Cequence Security specializes in API security and bot management, delivering Unified API Protection (UAP) uniting discovery, compliance, and protection across all internal and external APIs to defend against attacks, targeted abuse, and fraud. Requiring less than 15 minutes to onboard an API without requiring any instrumentation, SDK, or JavaScript integration, the flexible deployment model supports SaaS, on-premises, and hybrid installations. Cequence solutions scale to handle the most demanding Fortune and Global 2000 organizations, securing more than 8 billion daily API calls and protecting more than 3 billion user accounts.

Show More Details

Wallarm gives security teams the ability to detect and block API attacks. The Wallarm platform delivers a complete inventory of APIs, AI agents, and AI apps, providing risk assessment, patented AI/ML API abuse detection, real-time blocking on day zero, and an API SOC-as-a-service. Customers can deploy Wallarm to protect legacy and brand new cloud-native APIs. Wallarm’s multi-cloud platform delivers capabilities to secure businesses against existing and emerging API threats.

Show More Details

Salt Security is a provider of API security solutions. The company's API Protection Platform uses cloud-scale big data and ML/AI technologies to detect and block API attacks, offering security across all stages of the API lifecycle. Salt's platform offers real-time analysis and continuous insights for API discovery, attack prevention, and integrating security practices early in the development process. The unique API Context Engine (ACE) part of the system facilitates pre-production design analysis, API discovery, API attack mitigation, and remediation insights.

Show More Details

Traceable provides API Security to organizations, helping them to achieve API protection in a cloud-first, API-driven world. With an API Data Lake at the core of the platform, Traceable is the only intelligent and context-aware solution that powers complete API security – security posture management, threat protection and threat management across the entire Software Development Lifecycle – enabling organizations to minimize risk and maximize the value that APIs bring to their customers.

Show More Details

Akto is a platform designed to help application security and product security teams build an enterprise-grade API security program within their DevSecOps pipeline. Akto offers a suite of solutions including API discovery, API security posture management, sensitive data exposure, and API security testing. These solutions enable organizations to gain visibility into their API security posture and manage their security processes more effectively. Over 1,000 Application Security teams worldwide rely on Akto to address their API security needs.

Akto use cases:

API Discovery,

API Security Testing in CI/CD,

API Security Posture Management,

Authentication and Authorization Testing,

Sensitive Data Exposure,

and Shift Left in DevSecOps

Show More Details

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it; development and DevSecOps teams to automate testing within development pipelines without compromising velocity; and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Show More Details

The 42Crunch API security platform, is deployed by Fortune 500 firms and used by over 1.6 million developers globally. We help teams build better and more secure APIs, through good API security governance.

With 42Crunch, companies leverage the combined resources of their security and development teams to build more secure APIs, avoid the costly impact of API breaches by identifying and remediating vulnerabilities at design time and accelerate the time to market of API-driven services.

The 42 API security platform automates API security testing and runtime protection to enable companies fix API vulnerabilities at design time and block attacks at runtime. Risk assessment, risk scoring and security quality testing tools help developers build secure APIs and security teams retain governance and policy enforcement throughout the API lifecycle.

Show More Details
Show More Details

APIsec is a security testing platform primarily focused on identifying severe API vulnerabilities that could result in data breaches. Utilizing an automated system, APIsec creates and operates thousands of specific attack playbooks, tailored to each distinct API. This enables the detection of security weaknesses and data logic errors before they reach the production stage. The platform employs a zero-touch deployment model, eliminating the need for source code access, agents, or inline mechanisms. Functioning at the pace of DevOps, APIsec notifies security personnel and developers of new vulnerabilities in the Continuous Integration/Continuous Deployment (CI/CD) pipeline for ongoing validation of all API code.

Show More Details

Data Theorem focuses on preventing application security (AppSec) data breaches. The main areas of specialty include API Security, Web Security, Mobile Security, and Cloud Security. This is accomplished through the provision of static application security testing (SAST), dynamic application security testing (DAST), and runtime application self-protection (RASP). These services extend to various types of APIs, mobile applications, web applications, and cloud applications. The inventory, security testing, and active protection offered by Data Theorem across its range of products ensure robust defenses against data breaches. The headquarters of Data Theorem is located in Palo Alto, CA, with other offices spread across multiple cities internationally.

Show More Details

AppSentinels is a comprehensive full life-cycle API Security platform. We help build secure APIs and protect applications against business logic API attacks. The platform is deployed quickly, providing immediate API security and protection. The platform offers deep insights into application behavior, user journeys, and business logic workflows.

Show More Details

Indusface is an application security firm that secures Web, Mobile, and API applications of 5000+ global customers using its fully application security managed platform that integrates DAST scanner(Web & API), WAAP, DDoS & BOT Mitigation, CDN, and threat intelligence engine.

Show More Details

Levo.ai is an API Security Platform that automatically discovers, documents, tests, and monitors APIs, aligning with OWASP and compliance frameworks. Levo tackles the root cause of security incidents like insecure code by integrating visibility and security testing early in the SDLC.

1. Comprehensive API Discovery – Uncovers internal, third-party, zombie, open-source, and partner APIs without code or configuration changes.

2. Detailed API Documentation & Sensitive Data Classification – Provides in-depth API insights with identity context, mapping sensitive data flows across services.

3. Automated Security Testing & AuthN/AuthZ Validation – Identifies vulnerabilities (OWASP API Top 10, MITRE, authorization bypass, object-level misconfigurations) with zero manual effort.

4. Real-time Security Monitoring & Reporting – Tracks API traffic, flags deviations, and generates compliance-ready reports with custom policies.

Show More Details

Reblaze is a firm that specializes in providing cloud-based web application and API protection (WAAP) through a comprehensive security platform. The firm's multifaceted solution boasts a multitude of features including state-of-the-art WAF, DDoS protection, Bot Management, API security, Account Takeover (ATO) prevention, substantial rate limiting, biometric and behavioral threat detection, and Machine Learning among others. It also offers seamless integration with various environments, encompassing private/public clouds, single or multi-cloud, hybrid, on-premise, containers, service meshes, and serverless architectures. Its platform ensures thorough WAAP, improved visibility, and real-time control, all under a single category. The services of Reblaze are utilized by a diverse range of organizations worldwide.

Show More Details

Cloudflare, is a provider of WAAP, SASE, SSE, SD-WAN, CDN, and Edge Developer services. Cloudflare empowers organizations to make their employees, applications and networks faster and more secure everywhere, while reducing complexity and cost. Cloudflare delivers all services from a single intelligent global network platform, providing customers with a unified platform of cloud-native products and developer tools, so any organization can gain the control they need to work, develop, and accelerate their business.

Show More Details

At Secure Blink, we are dedicated to fortifying the digital landscape against ever-evolving cyber threats. Specializing in cutting-edge solutions for Web Application and API Security, we focus on innovation and excellence to protect your digital assets.

Our flagship SaaS product, Threatspy, is a developer-first, AI-powered AppSec management platform. Threatspy empowers developers and security teams to proactively identify and mitigate both known and unknown vulnerabilities in applications and APIs through automated detection, prioritization, and remediation processes. By leveraging Threatspy, businesses can enhance their security posture, reduce risk, and ensure the resilience of their digital infrastructure.

Threatspy supports both modern and legacy tech stacks, offering flexible deployment options across cloud-native and multi-cloud environments.

Show More Details