# Phosphorus

**Canonical:** https://apis.io/providers/phosphorus/  
**Website:** https://phosphorus.io/  
**APIs profiled:** 2

Phosphorus Cybersecurity is a Nashville, Tennessee cyber-physical systems (CPS) security company founded in 2017 by Chris Rouland, Earle Ady and Rebecca Rouland, and acquired by Dragos on 1 June 2026. Its agentless xIoT platform discovers, assesses, hardens and remediates IoT, OT, IIoT and IoMT devices across enterprise and critical infrastructure networks, automating credential rotation, firmware updates, certificate management, and vulnerability assessment at scale without additional hardware or endpoint agents. The platform exposes a customer-facing REST API (v2 and v3) described by an OpenAPI 3.0.0 contract that Phosphorus serves from each tenant instance at /api/swagger/public/swagger.json, covering devices, alerts, firmware, certificates, credentials, sites, search, dynamic scans, integration providers, and the Phosphorus Vault, authenticated with an X-API-KEY request header.

## Kin Score — 31.7 / 100 (thin)

Scored 2026-09-01 under rubric 0.17.2. Trend: flat (+0.0 from 31.7).

| Facet | Score |
|---|---|
| Discoverability | 68.5 |
| Contract Quality | 46.3 |
| Governance | 4.5 |
| Contract Governance | 4.5 |
| Operational Transparency | 13.2 |
| Developer Ergonomics | 20.8 |
| Commercial Clarity | 34.2 |
| Access Clarity | 34.2 |

## Agent readiness — 24.6 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | yes |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (8)

- **Phosphorus Alerts API** — The Alerts API from Phosphorus — 1 operation(s) for alerts.
- **Phosphorus Device API** — The Device API from Phosphorus — 8 operation(s) for device.
- **Phosphorus Devices API** — The Devices API from Phosphorus — 1 operation(s) for devices.
- **Phosphorus Dynamic Scans API** — The Dynamic Scans API from Phosphorus — 5 operation(s) for dynamic scans.
- **Phosphorus Providers API** — The Providers API from Phosphorus — 5 operation(s) for providers.
- **Phosphorus Search API** — The Search API from Phosphorus — 1 operation(s) for search.
- **Phosphorus Sites API** — The Sites API from Phosphorus — 1 operation(s) for sites.
- **Phosphorus Vault API** — The Vault API from Phosphorus — 2 operation(s) for vault.

## Security (3)

- **Phosphorus Authentication** — apiKey · 1 scheme
- **Phosphorus Domain Security** — TLSv1.3 · HSTS · DMARC
- **Phosphorus Vulnerability Disclosure** — Hackerone · contact published

## Plans (1)

- **Phosphorus Plans Pricing**

## Tags

Cybersecurity, xIoT Security, IoT Security, OT Security, IoMT, Asset Discovery, Vulnerability Management, Firmware Management, Certificate Management, Credential Management, Critical Infrastructure, Device Management

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/phosphorus/). Scores are computed from the provider's own public artifacts under a published rubric.
