# Defakto Security

**Canonical:** https://apis.io/providers/defakto-security/  
**Website:** https://www.defakto.security/  
**APIs profiled:** 2

Defakto (formerly SPIRL) is a non-human identity (NHI) security company that issues short-lived, cryptographically attested identities to workloads, services, CI/CD pipelines and AI agents in place of static secrets, API keys and long-lived service accounts. The platform is built on SPIFFE and ships two products: Mint, which runs Trust Domain Servers and Agents that mint X.509-SVIDs, JWT-SVIDs and proof-of-possession WIT-SVIDs for Kubernetes, Linux, Docker and serverless workloads under a dozen attestation methods; and Ledger, which discovers, risk-scores and eradicates static secrets across AWS, Azure, GCP, Kubernetes, Anthropic, OpenAI, Bedrock AgentCore and Gemini. The control plane is driven by a gRPC management API and the spirlctl CLI, with a Go SDK, an OpenTofu/Terraform provider, workload identity federation into AWS/Azure/GCP, and OCSF 1.8.0 audit logging.

## Kin Score — 49.6 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 49.6).

| Facet | Score |
|---|---|
| Discoverability | 75.9 |
| Contract Quality | 51.6 |
| Governance | 12.5 |
| Operational Transparency | 39.5 |
| Developer Ergonomics | 78.3 |
| Commercial Clarity | 34.2 |

## Agent readiness — 41.9 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | yes |
| Agent Skills | yes |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (2)

- **Defakto Management API** — The Defakto control-plane API. A gRPC service surface of sixteen versioned services covering trust domains, clusters, realms, workloads, access policy, service accounts and sess...
- **SPIRL Management API (legacy)** — The pre-rebrand SPIRL control-plane endpoint, still documented and still serving the legacy app.spirl.com console and the spirlctl CLI alongside the current api.defakto.security...

## Security (3)

- **Defakto Security Authentication** — 5 schemes
- **Defakto Security Domain Security** — TLSv1.3 · DNSSEC · DMARC
- **Defakto Security Vulnerability Disclosure** — Hackerone · contact published

## Plans (1)

- **Defakto Security Plans Pricing**

## Tags

Security, Identity, Non-Human Identity, Workload Identity, SPIFFE, Authentication, Zero Trust, Secrets Management, Kubernetes, CI/CD, Cloud Security, gRPC, Machine Identity, Agentic AI

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/defakto-security/). Scores are computed from the provider's own public artifacts under a published rubric.
