# Zafran Security

**Canonical:** https://apis.io/providers/zafran-security/  
**Website:** https://zafran.io  
**APIs profiled:** 0

Zafran Security is an AI-native threat exposure management (CTEM) platform for security teams buried in vulnerabilities and manual remediation work. It brings vulnerability findings together across an organization's existing scanners and tools to create a unified view of exposure across the hybrid enterprise, then determines actual exploitability by analyzing runtime presence, internet reachability, and existing compensating controls. Zafran maps vulnerabilities to controls the team already owns to mitigate risk before patching, and its RemOps capability uses generative AI to consolidate overlapping CVEs into a clear get-well plan routed to the right owners through existing ticketing platforms. The platform is delivered as a SaaS product accessed at api.zafran.io behind Descope-based authentication with API-key access for integrations (Axonius, Palo Alto Cortex XSOAR); it does not publish a public developer portal or OpenAPI. Zafran is backed by Menlo Ventures.

## Kin Score — 17.2 / 100 (emerging)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 17.2).

| Facet | Score |
|---|---|
| Discoverability | 50.0 |
| Contract Quality | 0.0 |
| Governance | 0.0 |
| Contract Governance | 0.0 |
| Operational Transparency | 13.2 |
| Developer Ergonomics | 2.4 |
| Commercial Clarity | 50.0 |
| Access Clarity | 50.0 |

## Agent readiness — 0.0 (human-only)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Unknown — onboarding: unknown, pricing: unknown, trial: no (confidence: low).

## Security (3)

- **Zafran Security Domain Security** — TLSv1.3 · HSTS · DMARC
- **Zafran Security Vulnerability Disclosure** — contact published
- **Zafran Security Trust Center** — SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 42001:2023, GDPR, TX-RAMP

## Tags

Company, Security, Cybersecurity, Vulnerability Management, Threat Exposure Management, CTEM, Remediation, Artificial Intelligence

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/zafran-security/). Scores are computed from the provider's own public artifacts under a published rubric.
