# Method Security

**Canonical:** https://apis.io/providers/method-security/  
**Website:** https://method.security  
**APIs profiled:** 10

Method Security is a cybersecurity company delivering cyber resilience to the U.S. Government and critical enterprises through an AI-native, full-spectrum security platform. The Method Platform blends offensive and defensive operations across cloud, on-premise, and internet-denied environments, and ships two flagship products: Bastion (digital-twin driven exposure and attack-surface management that maps, validates, and controls resources and attack paths) and Reaper/Operations (software-defined offensive operations and red-team execution). The platform is built around an Ontology object model, AI Agents governed by granular Policies, Jackal C2 agents, Overwatch terminal session recording, and an Explorer/Automator workspace. Method exposes a public REST API (OpenAPI 3.1) through the method-api-gateway, a published Python SDK (methodsdk), a docs MCP server, and OAuth 2.0 client-credentials authentication backed by Keycloak. Backed by OpenAI, Palantir, Andreessen Horowitz, General Catalyst, and Blackstone.

## Kin Score — 54.0 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 54.0).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 57.3 |
| Governance | 20.8 |
| Operational Transparency | 39.5 |
| Developer Ergonomics | 71.2 |
| Commercial Clarity | 36.8 |

Regulatory layer — **Government & Public Sector**: 66.7 (matched via tags).

## Agent readiness — 52.0 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | yes |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (10)

- **Method Security audit API** — The audit API from Method Security — 1 operation(s) for audit.
- **Method Security auth API** — The auth API from Method Security — 1 operation(s) for auth.
- **Method Security blueprints API** — The blueprints API from Method Security — 2 operation(s) for blueprints.
- **Method Security environments API** — The environments API from Method Security — 2 operation(s) for environments.
- **Method Security issues API** — The issues API from Method Security — 2 operation(s) for issues.
- **Method Security reports API** — The reports API from Method Security — 1 operation(s) for reports.
- **Method Security signals API** — The signals API from Method Security — 1 operation(s) for signals.
- **Method Security skills API** — The skills API from Method Security — 3 operation(s) for skills.
- **Method Security system API** — The system API from Method Security — 1 operation(s) for system.
- **Method Security targets API** — The targets API from Method Security — 3 operation(s) for targets.

## MCP servers (1)

- **method-security-mcp.yml**

## Agentic access (1)

- **Method Security Agentic Access** — 18 operations · 10 acting · 3 human-in-the-loop

## Security (4)

- **Method Security Authentication** — http · 1 scheme
- **Method Security Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Method Security Vulnerability Disclosure** — contact published
- **Method Security Trust Center** — SOC 2

## Tags

Company, Security, Cybersecurity, Offensive Security, Exposure Management, Attack Surface Management, Vulnerability Management, Red Team, AI Agents, Government

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/method-security/). Scores are computed from the provider's own public artifacts under a published rubric.
