Holm Security's API Security is a vulnerability assessment solution designed to evaluate Application Programming Interfaces for security flaws. The system assesses multiple API architectures, including REST/OpenAPI, GraphQL, and SOAP, and can import API definitions from formats such as Postman, Fiddler, Burp Suite, and HAR. It is built to identify security weaknesses in both authenticated and unauthenticated APIs, covering internal and externally facing applications. The scanning process targets threats outlined in the OWASP API Top 10, such as Broken Object Level Authorization (BOLA), broken authentication, injection attacks, and security misconfigurations.
The solution provides automated and continuous capabilities, integrating with attack surface management to automatically discover and monitor an organization's API assets. It performs automated vulnerability assessments to generate detailed reports on the overall security posture. A central Security Center offers a unified interface for the discovery, prioritization, remediation, and reporting of identified API vulnerabilities, enabling the ongoing management of an organization's API security.