Security is one of the API Evangelist areas on the APIs.io network — a focused corner of the API landscape. The full area lives at security.apievangelist.com.
30 providers on the network work in this area, including Pynt, Upwind, CyCognito, detectify, Imperva, Chaitin Tech, and 24 more — each links out to that provider’s APIs, schemas, and governance artifacts.
Related areas: Authentication, API Evangelist Search, Containers, and DNS. Browse every area at areas.apis.io.
About this area
An index and topic collection covering API security, identity, access management, secrets management, encryption, and threat protection. API security spans the full lifecycle of…
Related providers (867)
Top 30 of 867 network providers tagged for this area — search the full set on apis.io.
| Provider | Description | APIs | Rating |
|---|---|---|---|
| Pynt | Pynt is an API security testing platform that discovers and secures APIs, LLM endpoints and MCP servers. It wraps a team's existing functional tests — or proxies live traffic — ... | 2 | developing |
| Upwind | Upwind is a cloud and AI security platform (CNAPP) that secures cloud infrastructure, workloads, and applications in real time — spanning cloud security posture management (CSPM... | 2 | developing |
| CyCognito | CyCognito is a cybersecurity company providing an external attack surface management (EASM) and exposure management platform. Its cloud-native platform continuously discovers, m... | 1 | developing |
| detectify | Detectify is an External Attack Surface Management (EASM) and Dynamic Application Security Testing (DAST) platform that continuously discovers an organization's internet-facing ... | 1 | developing |
| Imperva | Imperva (a Thales company) is a cybersecurity company providing cloud-based and on-premises application security, data security, and network security solutions. Their developer ... | 2 | developing |
| Chaitin Tech | Chaitin Tech (长亭科技) is a Chinese cybersecurity company best known for SafeLine (雷池), a self-hosted, semantic-analysis Web Application Firewall and reverse proxy with 22k+ GitHub... | 6 | thin |
| Traceable | Traceable is an API security and observability platform that provides API discovery, threat detection, and protection across the full application lifecycle. It uses context-awar... | 1 | thin |
| PortSwigger | PortSwigger is the UK-based security research company behind Burp Suite, the industry-standard web and API security testing platform used by penetration testers and enterprise A... | 5 | thin |
| Akto | Akto is a proactive API security platform that discovers, tests, and protects APIs and AI systems across an organization's infrastructure. Its open-source core (MIT, Java) deliv... | 0 | thin |
| 42Crunch | 42Crunch is a leading API security company that specializes in protecting and securing APIs. They provide innovative solutions that help organizations safeguard their sensitive ... | 6 | thin |
| Impart Security | Impart Security is a runtime security platform that unifies WAF, API security, and AI/LLM/agent/MCP protection on one inline enforcement engine. It analyzes the full request/res... | 1 | emerging |
| Vorlon | Vorlon is an agentic ecosystem security platform that helps enterprises deploy AI agents and SaaS applications safely by protecting sensitive data in real time. The platform map... | 0 | emerging |
| Invicti | Invicti is an enterprise web application security solution providing automated vulnerability scanning, DAST, and API security testing. The Invicti platform includes API Discover... | 1 | emerging |
| Operant | Operant AI is a San Francisco-based runtime security company (founded 2021, backed by Felicis) that protects cloud and AI applications with real-time, Kubernetes-native "3D Runt... | 0 | emerging |
| Salt Security | Salt Security provides an AI-powered API security platform that discovers all APIs, stops API attacks in real-time, and provides remediation insights. The platform delivers full... | 2 | emerging |
| Crosslayer Labs | Crosslayer Labs is a network and web-infrastructure security company spun out of a Princeton University security research lab. Its founding team invented Multi-Perspective Issua... | 0 | emerging |
| Signal Sciences | Signal Sciences is a web application and API protection (WAAP) company whose Next-Gen Web Application Firewall (WAF) and Runtime Application Self-Protection (RASP) defend web ap... | 1 | minimal |
| Raspire | Raspire (RASPIRE) provides runtime security for mobile applications, positioning itself as the first line of defense for Android and iOS apps against AI-powered fraud attacks, A... | 0 | minimal |
| Hex Security | Hex Security is a Y Combinator (W26) security startup building autonomous AI agents that perform continuous penetration testing against web applications, APIs, and infrastructur... | 0 | minimal |
| Tinfoil Security | Tinfoil Security was a web application and API security scanning company that provided automated dynamic (DAST) vulnerability testing for web apps and REST APIs. It was acquired... | 0 | minimal |
| Tcell Io | Tcell Io (tCell.io) was surfaced as a portfolio company of Menlo Ventures and added to the API Evangelist network as a lead for enrichment. As of this enrichment pass the compan... | 0 | |
| Elastic Stack | The Elastic Stack (formerly known as the ELK Stack) is the collection of open-source products from Elastic — Elasticsearch, Logstash, Kibana, and Beats/Elastic Agent — designed ... | 11 | exemplar |
| Snyk | Snyk is a developer-first security platform covering code, open-source dependencies, container images, and infrastructure-as-code. The Snyk REST API and V1 API expose groups, or... | 3 | exemplar |
| Amazon VPN | AWS VPN solutions establish secure connections between on-premises networks, remote offices, client devices, and the AWS global network. AWS offers two types of private connecti... | 1 | exemplar |
| OneTrust | OneTrust is an enterprise trust, privacy, and AI-governance platform. Its developer portal publishes 37 downloadable OpenAPI definitions covering roughly 631 operations across U... | 37 | exemplar |
| Aembit | Aembit is a Workload Identity and Access Management (Workload IAM) platform for non-human identities — AI agents, applications, microservices, CI/CD pipelines, scripts and servi... | 2 | exemplar |
| Clerk | Clerk is a complete user management and authentication infrastructure platform offering embeddable UI components, flexible APIs, and admin dashboards. It provides full-stack aut... | 7 | exemplar |
| Cloudflare | Cloudflare is a global network designed to make everything you connect to the Internet secure, private, fast, and reliable. | 24 | exemplar |
| Drata | Drata is a continuous security and compliance automation platform supporting SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and more, with policies, evidence, and trust center. Drata e... | 3 | exemplar |
| Auth0 | Auth0 (now part of Okta) is a leading identity-as-a-service platform providing authentication and authorization for applications, APIs, and AI agents. It implements OpenID Conne... | 3 | exemplar |
Related areas
Cohort brief
Auto-generatedThe 28 providers in the APIs.io catalog working in Security, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.
| Facet | This cohort | Catalog | Difference | Scored |
|---|---|---|---|---|
| Operational Transparency | 35.5 | 13.6 | +21.9 | 28 |
| Access Clarity | 47.6 | 26.4 | +21.2 | 28 |
| Developer Ergonomics | 41.9 | 23.1 | +18.8 | 28 |
| Contract Quality | 33.8 | 17.6 | +16.2 | 28 |
| Discoverability | 65.1 | 58.2 | +6.9 | 28 |
| Contract Governance | 12.5 | 6.3 | +6.2 | 28 |
A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.
| Artifact | This cohort | Catalog | Difference |
|---|---|---|---|
| MCP server (any) | 45% | 15% | +30 |
| MCP server (first-party) | 38% | 12% | +26 |
| Agent Skills | 0% | 0% | 0 |
| OAuth scopes | 17% | 11% | +6 |
| Security | 97% | 98% | -1 |
| Arazzo workflows | 7% | 2% | +5 |
| Governance rules | 28% | 13% | +15 |
mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.
- 1 Elastic Stack 78.5
- 2 Snyk 74.8
- 3 Amazon VPN 74.6
- 4 OneTrust 73.2
- 5 Aembit 72.6
- 6 Clerk 71.9
- 7 Cloudflare 71.9
- 8 Drata 70.7
- 9 Auth0 70.5
- 10 Pynt 52.7
- 1 Cloudflare 65.5
- 2 OneTrust 55.9
- 3 Aembit 54.6
- 4 Drata 48.6
- 5 Elastic Stack 46.4
- 6 Clerk 45.9
- 7 Snyk 43.7
- 8 Upwind 41.5
- 9 CyCognito 38.7
- 10 Auth0 37.2
Work with this as data
Every area here is available over the APIs.io API and to AI agents over MCP.