SAFE Security

SAFE Security (SAFE, formerly Lucideus) is a Palo Alto based cyber risk management company whose SAFE One platform quantifies cyber risk in financial terms on the FAIR standard, unifying Cyber Risk Quantification (CRQ), Third-Party Risk Management (TPRM), Continuous Threat Exposure Management (CTEM) and AI Security Posture Management (AI-SPM). The platform is API-first: a versioned REST API at /api/v3 on a per-tenant safeone.ai host lets customers pull users, assets, findings, risk scenarios, reports and audit logs, and drive the 50+ product integrations programmatically, while an open-source Signal specification (MIT, github.com/Safe-Security/signal) defines the JSON contract for pushing CA, VA, EDR and UBA security signals into SAFE from any tool. SAFE acquired RiskLens in 2023 and Balbix in 2025.

SAFE Security publishes 2 APIs on the APIs.io network. Tagged areas include Company, Security, Cyber Risk Quantification, Third-Party Risk Management, and Continuous Threat Exposure Management.

SAFE Security’s developer surface includes documentation, API reference, getting-started guide, support, engineering blog, signup flow, changelog, and 24 more developer resources.

38.3/100 thin ▬ flat Agent 10/100 agent aware saas Full breakdown ↓
scored 2026-09-01 · rubric v0.17.2
2 APIs 1 MCP Servers
CompanySecurityCyber Risk QuantificationThird-Party Risk ManagementContinuous Threat Exposure ManagementAI Security Posture ManagementRisk ManagementGovernance Risk and ComplianceFAIRVulnerability Management

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-01 · rubric v0.17.2
Composite quality — 38.3/100 · thin
Contract Quality 1.7 / 25
Developer Ergonomics 11.0 / 20
Access Clarity 7.4 / 20
Operational Transparency 8.6 / 13
Contract Governance 2.2 / 12
Discoverability 7.6 / 10
Agent readiness — 10/100 · agent aware
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 10
Documented Reversibility 0 / 6
MCP Server 12 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Delegated User Identity 0 / 6
Protected Resource Metadata 0 / 5
Registration Without a Human 0 / 6
Agentic Commerce Surface 0 / 5
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/safe-security: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 2

Individual APIs this provider publishes, each with its own machine-readable definition.

SAFE REST API

The SAFE REST API (v3) gives customers and partners programmatic access to the SAFE One platform: users, assets/technology, findings, risk scenarios, reports, audit-log export, ...

Balbix REST API

The Balbix REST API (v1) gives programmatic read access to the asset, vulnerability, misconfiguration, software-inventory and application inventory Balbix discovers - the Contin...

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Safe Security Rate Limits

1 limits

RATE LIMITS

Examples 7

Example request and response payloads for these APIs.

Scroll for all 7

Security Posture 4

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Safe Security Authentication

2 schemes

SECURITY

Safe Security Domain Security

TLSv1.3 · HSTS · DNSSEC · DMARC

SECURITY

Safe Security Vulnerability Disclosure

Hackerone · security.txt

SECURITY

Safe Security Trust Center

SOC 2 Type 2, SOC 3, ISO 27001:2013, ISO 9001:2015, TX-RAMP

SECURITY

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 2

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 6

Authentication, authorization, and security posture

Operate 4

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: safe-security
name: SAFE Security
description: 'SAFE Security (SAFE, formerly Lucideus) is a Palo Alto based cyber risk management company whose SAFE One platform
  quantifies cyber risk in financial terms on the FAIR standard, unifying Cyber Risk Quantification (CRQ), Third-Party Risk
  Management (TPRM), Continuous Threat Exposure Management (CTEM) and AI Security Posture Management (AI-SPM). The platform
  is API-first: a versioned REST API at /api/v3 on a per-tenant safeone.ai host lets customers pull users, assets, findings,
  risk scenarios, reports and audit logs, and drive the 50+ product integrations programmatically, while an open-source Signal
  specification (MIT, github.com/Safe-Security/signal) defines the JSON contract for pushing CA, VA, EDR and UBA security
  signals into SAFE from any tool. SAFE acquired RiskLens in 2023 and Balbix in 2025.'
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: false
  label: Hosted service · you call their endpoint
  confidence: medium
  source:
  - pricing
  generated: '2026-08-28'
  method: derived
image: https://safe.security/wp-content/uploads/safe-social.jpg
url: https://raw.githubusercontent.com/api-evangelist/safe-security/refs/heads/main/apis.yml
x-type: company
x-source: harvest:secondary-market
specificationVersion: '0.20'
created: '2026-08-26'
modified: '2026-08-26'
tags:
- Company
- Security
- Cyber Risk Quantification
- Third-Party Risk Management
- Continuous Threat Exposure Management
- AI Security Posture Management
- Risk Management
- Governance Risk and Compliance
- FAIR
- Vulnerability Management
apis:
- name: SAFE REST API
  description: 'The SAFE REST API (v3) gives customers and partners programmatic access to the SAFE One platform: users, assets/technology,
    findings, risk scenarios, reports, audit-log export, and full lifecycle management of the platform''s product integrations.
    Authentication is a two-step exchange - HTTP Basic with an API username/password generated in Settings > API Credentials,
    then POST /api/v3/auth to mint a one-hour bearer access token. The API is served from the customer''s own regional tenant
    host on safeone.ai; the Swagger reference is published inside the authenticated application (User Profile > Help > SAFE
    API) and is not reachable anonymously.'
  humanURL: https://docs.safe.security/docs/accessing-safe-apis
  baseURL: https://us.safeone.ai/api/v3
  tags:
  - Security
  - Risk Management
  - Cyber Risk Quantification
  properties:
  - type: Documentation
    url: https://docs.safe.security/docs/accessing-safe-apis
  - type: APIReference
    url: https://docs.safe.security/docs/accessing-safe-apis
  - type: Authentication
    url: authentication/safe-security-authentication.yml
  - type: RateLimits
    url: rate-limits/safe-security-rate-limits.yml
  - type: Conventions
    url: conventions/safe-security-conventions.yml
  - type: ErrorCatalog
    url: errors/safe-security-problem-types.yml
  - type: DataModel
    url: data-model/safe-security-data-model.yml
  - type: MCPServer
    url: mcp/safe-security-mcp.yml
  - type: Examples
    url: examples/_index.yml
  - type: Lifecycle
    url: lifecycle/safe-security-lifecycle.yml
- name: Balbix REST API
  description: The Balbix REST API (v1) gives programmatic read access to the asset, vulnerability, misconfiguration, software-inventory
    and application inventory Balbix discovers - the Continuous Threat Exposure Management half of SAFE's platform since the
    2025 acquisition. Assets are addressed by an integer Device ID resolved through /asset_list from any combination of hostname,
    IP and MAC; applications by an App ID. Responses carry CVSS scores, CVE and CWE identifiers, CPE strings, MITRE ATT&CK
    tactic/technique pairs and a Balbix exposure score. Authentication is HTTP Basic plus a customer key against /apis/v1/gen_token,
    which mints a 30-minute session token sent bare in Authorization alongside a Client-API-Key tenant header - a different
    calling convention from the SAFE One API. The API is explicitly read-only, is served from a per-tenant *.balbix.net host
    issued by Balbix, and credentials can currently only be created by Balbix engineering or customer success rather than
    self-service.
  humanURL: https://docs.safe.security/balbixhelp/docs/balbix-rest-api-guide-v20
  baseURL: https://{tenant}.balbix.net/apis/v1
  tags:
  - Security
  - Continuous Threat Exposure Management
  - Vulnerability Management
  - Attack Surface Management
  properties:
  - type: Documentation
    url: https://docs.safe.security/balbixhelp/docs/balbix-rest-api-guide-v20
  - type: APIReference
    url: https://docs.safe.security/balbixhelp/docs/balbix-rest-api-guide-v20
  - type: Authentication
    url: authentication/safe-security-authentication.yml
  - type: Conventions
    url: conventions/safe-security-conventions.yml
  - type: ErrorCatalog
    url: errors/safe-security-problem-types.yml
  - type: DataModel
    url: data-model/safe-security-data-model.yml
  - type: ChangeLog
    url: changelog/safe-security-changelog.yml
  - type: RateLimits
    url: rate-limits/safe-security-rate-limits.yml
common:
- type: Website
  url: https://safe.security/
- type: Documentation
  url: https://docs.safe.security/
- type: APIReference
  url: https://docs.safe.security/docs/accessing-safe-apis
- type: GettingStarted
  url: https://github.com/Safe-Security/signal/blob/main/developer-guide.md
- type: Support
  url: https://docs.safe.security/docs/support-and-maintenance
- type: Blog
  url: https://safe.security/resources/blog/
- type: BlogRSS
  url: https://safe.security/feed/
- type: GitHubOrganization
  url: https://github.com/Safe-Security
- type: SignUp
  url: https://us.safeone.ai/
- type: TermsOfService
  url: https://safe.security/terms-of-service/
- type: PrivacyPolicy
  url: https://safe.security/privacy-policy/
- type: Security
  url: https://safe.security/security/
- type: TrustCenter
  url: security/safe-security-trust-center.yml
- type: Compliance
  url: conformance/safe-security-conformance.yml
- type: Conformance
  url: conformance/safe-security-conformance.yml
- type: VulnerabilityDisclosure
  url: security/safe-security-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/safe-security-domain-security.yml
- type: LLMsTxt
  url: llms/safe-security-llms.txt
- type: Packages
  url: packages/safe-security-packages.yml
- type: SDKs
  url: packages/safe-security-packages.yml
- type: Lifecycle
  url: lifecycle/safe-security-lifecycle.yml
- type: StatusPage
  url: lifecycle/safe-security-lifecycle.yml
- type: ChangeLog
  url: changelog/safe-security-changelog.yml
- type: Plans
  url: plans/safe-security-plans-pricing.yml
- type: Examples
  url: examples/_index.yml
- type: Conventions
  url: conventions/safe-security-conventions.yml
- type: ErrorCatalog
  url: errors/safe-security-problem-types.yml
- type: DataModel
  url: data-model/safe-security-data-model.yml
- type: MCPServer
  url: mcp/safe-security-mcp.yml
- type: Authentication
  url: authentication/safe-security-authentication.yml
- type: RateLimits
  url: rate-limits/safe-security-rate-limits.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
x-enrichment:
  date: '2026-08-26'
  status: enriched
  artifacts_added: 19
  pass: local-v1

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/safe-security"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/safe-security/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/safe-security/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.