# AttackIQ

**Canonical:** https://apis.io/providers/attackiq/  
**Website:** https://www.attackiq.com  
**APIs profiled:** 1

AttackIQ is a cybersecurity company that pioneered Breach and Attack Simulation (BAS) and now delivers a Continuous Threat Exposure Management (CTEM) platform. Its Security Optimization Platform continuously and safely emulates real adversary tactics, techniques, and procedures aligned to the MITRE ATT&CK framework, validating that security controls detect and prevent attacks and measuring control effectiveness over time. The platform exposes a REST/JSON Platform API (firedrill.attackiq.com/v1) for managing assessments, assets, scenarios, tests, and results, authenticated with per-user API tokens, plus an official Python SDK and `aiq` command-line interface. AttackIQ is a portfolio company of Index Ventures.

## Kin Score — 22.8 / 100 (emerging)

Scored 2026-08-30 under rubric 0.17.2. Trend: flat (+0.0 from 22.8).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 0.0 |
| Governance | 4.5 |
| Contract Governance | 4.5 |
| Operational Transparency | 18.4 |
| Developer Ergonomics | 40.5 |
| Commercial Clarity | 21.1 |
| Access Clarity | 21.1 |

## Agent readiness — 2.5 (human-only)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (1)

- **AttackIQ Platform API** — REST/JSON API for the AttackIQ Security Optimization Platform. Manage assessments, tests, scenarios, and assets and retrieve execution results. Authenticated with a per-user API...

## MCP servers (1)

- **AttackIQ MCP Server**

## Security (3)

- **Attackiq Authentication** — apiKey · 1 scheme
- **Attackiq Domain Security** — TLSv1.2 · HSTS · DNSSEC · DMARC
- **Attackiq Trust Center** — trust center published

## Tags

Company, Security, Cybersecurity, Breach and Attack Simulation, Continuous Threat Exposure Management, Security Validation, MITRE ATT&CK, Threat Exposure Management

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/attackiq/). Scores are computed from the provider's own public artifacts under a published rubric.
