API discovery: do you know where your APIs are?
This is the most fundamental question in API Security. Salt automatically and continuously discovers all APIs, capturing granular details about them including where sensitive data resides, to help you eliminate blind spots, assess risk, and manage API sprawl with our industry-leading posture governance engine.
It all starts with API discovery
It’s eye opening to know how many APIs you deal with, and more importantly, how many have serious security flaws. Many organizations know about only a fraction of their APIs. Salt helps you start your API Security journey with extensive and continuous API discovery.
Learn more01 Advanced API discovery
Eliminate blind spots by automatically and continuously discovering all internal, external and third-party APIs.
- API details exposed. Granular details such as parameters, usage patterns, risk scores and sensitive data exposure that help you understand your attack surface and assess risk.
- Context-rich insights. Salt delivers the most detailed, context-rich filtering and querying available, enabling organizations to gain custom insights into their APIs.
- Discovery insights that drive governance. Use insights to derive and customize posture governance policies with Salt's industry-first API Posture Governance engine.
- No documentation? No problem. APIs not in your gateway or documented in an OpenAPI Specification (aka Swagger)? No problem. Salt will still find them and add them to your library.
02 Find shadow and zombie APIs
Deprecated, unknown and shadow APIs represent a significant risk to organizations.
- Gain visibility. Shadow and zombie APIs typically represent anywhere from 40% to 800% of the total APIs organizations thought they had or what is noted in their documentation.
- Protect sensitive data. PII and other sensitive data can be exposed inadvertently through APIs not on your radar and increase risk dramatically.
- Keep documentation current. By continuously discovering your APIs, you can compare with your current documentation to ensure it's always accurate.
03 Identify and minimize API risk
Continuously monitor API traffic and behavior to detect anomalies and potential threats
- Risk assessment. Evaluate the potential risks associated with each API, such as vulnerabilities, misconfigurations and sensitive data exposure.
- Compliance. Ensure that APIs comply with relevant regulations and industry standards, such as GDPR, HIPAA and PCI DSS.
- Policy enforcement. Implementing and enforcing policies that define acceptable API behavior and access controls.
What our customers are saying
“Salt has been a game-changer for our API security. We now have the visibility and control to protect our data, stay compliant, and build trust with our customers.”
—Peter Rios, Infrastructure and Information Security Manager, CISM, Kingston
Want to see the Salt platform in action?
Learn how Salt Security's leading API security platform can provide complete Posture Governance and API Behavioral Threat Protection.

















