Zafran Security

Zafran Security is an AI-native threat exposure management (CTEM) platform for security teams buried in vulnerabilities and manual remediation work. It brings vulnerability findings together across an organization's existing scanners and tools to create a unified view of exposure across the hybrid enterprise, then determines actual exploitability by analyzing runtime presence, internet reachability, and existing compensating controls. Zafran maps vulnerabilities to controls the team already owns to mitigate risk before patching, and its RemOps capability uses generative AI to consolidate overlapping CVEs into a clear get-well plan routed to the right owners through existing ticketing platforms. The platform is delivered as a SaaS product accessed at api.zafran.io behind Descope-based authentication with API-key access for integrations (Axonius, Palo Alto Cortex XSOAR); it does not publish a public developer portal or OpenAPI. Zafran is backed by Menlo Ventures.

Zafran Security is profiled on the APIs.io network. Tagged areas include Company, Security, Cybersecurity, Vulnerability Management, and Threat Exposure Management.

Zafran Security’s developer surface includes engineering blog, signup flow, and 11 more developer resources.

19.2/100 emerging ▬ flat Agent 0/100 human only Full breakdown ↓
scored 2026-07-27 · rubric v0.5
0 APIs
CompanySecurityCybersecurityVulnerability ManagementThreat Exposure ManagementCTEMRemediationArtificial Intelligence

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-27 · rubric v0.5
Composite quality — 19.2/100 · emerging
Contract Quality 0.0 / 25
Developer Ergonomics 0.4 / 20
Commercial Clarity 10.0 / 20
Operational Transparency 2.1 / 13
Governance 0.0 / 12
Discoverability 6.8 / 10
Agent readiness — 0/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 0 / 15
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 0 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/zafran-security: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Zafran Security Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Zafran Security Vulnerability Disclosure

contact published

SECURITY

Zafran Security Trust Center

SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 42001:2023, GDPR, TX-RAMP

SECURITY

Resources

Get Started 2

Portal, sign-up, and the first successful call

Build 1

SDKs, sample code, and the tooling you integrate with

Access & Security 5

Authentication, authorization, and security posture

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 1

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: zafran-security
name: Zafran Security
description: Zafran Security is an AI-native threat exposure management (CTEM) platform for security teams buried in vulnerabilities
  and manual remediation work. It brings vulnerability findings together across an organization's existing scanners and tools
  to create a unified view of exposure across the hybrid enterprise, then determines actual exploitability by analyzing runtime
  presence, internet reachability, and existing compensating controls. Zafran maps vulnerabilities to controls the team already
  owns to mitigate risk before patching, and its RemOps capability uses generative AI to consolidate overlapping CVEs into
  a clear get-well plan routed to the right owners through existing ticketing platforms. The platform is delivered as a SaaS
  product accessed at api.zafran.io behind Descope-based authentication with API-key access for integrations (Axonius, Palo
  Alto Cortex XSOAR); it does not publish a public developer portal or OpenAPI. Zafran is backed by Menlo Ventures.
url: https://raw.githubusercontent.com/api-evangelist/zafran-security/refs/heads/main/apis.yml
x-type: company
x-source: vc-portfolio
x-backed-by:
- menlo-ventures
x-tier: stub
x-tier-reason: portfolio-lead
accessModel:
  pricing: unknown
  onboarding: unknown
  trial: false
  try_now: false
  public: false
  label: Unknown
  confidence: low
  source: []
  generated: '2026-07-22'
  method: derived
specificationVersion: '0.20'
created: '2026-07-17'
modified: '2026-07-21'
image: https://cdn.prod.website-files.com/680f7748aeaac0c97e4b1a7b/683a2e0c6e76020e5ddb494b_zafran-og.png
tags:
- Company
- Security
- Cybersecurity
- Vulnerability Management
- Threat Exposure Management
- CTEM
- Remediation
- Artificial Intelligence
apis: []
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
- FN: APIs.json
  email: info@apis.io
common:
- type: Website
  url: https://zafran.io
- type: Platform
  url: https://www.zafran.io/platform
- type: Blog
  url: https://www.zafran.io/blog
- type: SignUp
  url: https://www.zafran.io/free-trial
- type: Demo
  url: https://www.zafran.io/get-a-demo
- type: TermsOfService
  url: https://www.zafran.io/legal/terms-of-use
- type: PrivacyPolicy
  url: https://www.zafran.io/legal/privacy-policy
- type: GitHubOrganization
  url: https://github.com/zafransecurity
- type: TrustCenter
  url: security/zafran-security-trust-center.yml
- type: Compliance
  url: https://trust.zafran.io/
- type: Security
  url: https://www.zafran.io/responsible-disclosure
- type: VulnerabilityDisclosure
  url: security/zafran-security-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/zafran-security-domain-security.yml
x-enrichment:
  date: '2026-07-21'
  status: enriched
  artifacts_added: 3
  pass: local-v1