🇫🇷 🇪🇺 Sovereign API Security: Automated Vulnerability Discovery for French & EU Infrastructure · NIS 2, DORA & RGPD Compliant.
Continuous API Authorization & BOLA Vulnerability Discovery

Find the API vulnerabilities behind the French data breaches before attackers exploit them.

Discover unauthorized data exposure paths before attackers do. API Angel passively captures live traffic, decodes complex GraphQL ASTs, SOAP XML, and Base64 identifiers, providing undeniable HTTP evidence dossiers and automated retesting to verify fixes.

ENGINEERED FOR STRICT REGULATORY & INSTITUTIONAL COMPLIANCE
NIS 2 (ANSSI) Art. 21
DORA (EU Banking/Fintech)
RGPD / CNIL Compliance
OWASP API #1 (BOLA) & #2 (Auth)
100% On-Prem / Air-Gapped

Why Traditional WAFs and Gateways Failed Against Healthcare, Telecom & Public Sector Data Leaks

In the recent wave of French data breaches, attackers did not bypass firewalls or use zero-day SQL injections. They exploited Broken Object Level Authorization (BOLA / IDOR) on legitimate endpoints using valid authentication tokens.

The BOLA Blindspot: Why Perimeter Security is Insufficient

Traditional Web Application Firewalls (WAFs) and API Gateways inspect HTTP syntax, rate limits, and authentication signatures. Because a BOLA request contains a valid JWT/Session and well-formed parameters, WAFs see it as 100% legitimate traffic and allow attackers to systematically enumerate citizen NIRs, patient records, and banking IBANs.

Traditional WAF / API Gateway

  • Blind to multi-tenant object authorization context
  • Approves valid JWT even if accessing peer user IDs
  • Unable to parse nested GraphQL ASTs or SOAP XML entity keys
  • High alert noise without reproducible exploit validation

API Angel Vulnerability Discovery Engine

  • Continuous A/B cross-account privilege validation
  • Native recognition of French NIR, IBAN, and contractual IDs
  • Deep decoding of Base64, UUIDs, and GraphQL Node IDs
  • Undeniable HTTP evidence dossiers & automated retest loop

Anatomy of a BOLA Detection & Evidence Dossier

See how API Angel systematically isolates authorization breakdowns in HTTP traffic and produces auditable evidence dossiers with actionable remediation guidance and automated retest verification.

MUTATED TEST REQUEST & RAW LEAK
// Loading exploit sample...
API ANGEL EVIDENCE DOSSIER & REMEDIATION
// Loading remediation sample...

Autonomous 5-Step BOLA Verification Lifecycle

From non-invasive traffic ingestion to verified remediation guidance and retesting: how API Angel uncovers vulnerabilities in your production and pre-production APIs without slowing down development cycles.

1

Zero-Touch Passive Ingestion

Capture live API traffic via passive mirror, eBPF, or import HAR, Burp Suite, and PCAP exports. Zero latency overhead on production.

2

Deep Semantic AST & Token Parsing

Automatically unpacks Base64, UUIDs, GraphQL Node IDs, and SOAP XML envelopes, recognizing sensitive French PII formats (NIR, IBAN, SIRET).

3

A/B Privilege Boundary Fuzzing

Executes targeted mutation scenarios across user identities to uncover both horizontal (peer) and vertical (privilege escalation) BOLA paths.

4

Evidence Dossier & Risk Scoring

Confirms each vulnerability with exact HTTP request/response payloads, status codes, and mutated parameter traces, providing undeniable proof for engineering and compliance.

5

Remediation Guidance & Retest Gate

Provides actionable architectural remediation guidance and executes automated retests to verify fixes and block regressions in CI/CD.

api-angel.internal / exchanges (passive mirror)
LIVE CONSOLE
Exchanges Ingestion Payload Details & PII Parsing Attack Scenarios & Mutation BOLA Exploit Vector & Evidence AI Contextual Analysis

Engineered for Complex Enterprise API Ecosystems

Comprehensive coverage across modern microservices and legacy institutional protocols.

French & EU PII + 1-Click Custom Data Rules

Native parsers for French NIR (Sécurité Sociale), French IBANs (FR76), SIREN/SIRET, mutual contracts, plus instant 1-click custom regex and keyword rules for your company-specific sensitive data.

REST, GraphQL AST & SOAP XML

Full AST inspection of GraphQL queries, legacy SOAP XML element trees, URL-encoded forms, and Base64 transcoded tokens across all editions.

Vertical & Horizontal BOLA Mapping

Differentiates peer data access from administrative privilege escalation, boosting risk scores for high-impact vertical breaches.

Tri-Interface: UI, REST API & MCP

Complete parity across Web Dashboard, headless REST API for CI/CD gating, and sovereign MCP (Model Context Protocol) server for AI coding assistants (Cursor, Claude, Copilot).

Configurable Fuzzing Aggressiveness

4 distinct operational levels (Low, Medium, High, Max) allowing type-safe targeted swaps or full host-level identifier permutations.

Reproducible Evidence & Automated Retest

Generates audit-ready evidence dossiers with exact HTTP replays, plus a 1-click automated retest engine to verify developer patches before release.

100% Local Processing · Zero Data Exfiltration

Your API traffic contains your most sensitive citizen and customer data. API Angel is built with strict privacy-by-design guarantees.

100% On-Premises & Air-Gapped Ready

Runs entirely within your private network or private cloud (OVHcloud, Scaleway, AWS Outposts). No outbound telemetry required.

Lightweight Single-Command Deployment

Standard Docker Compose or Kubernetes Helm chart. Minimal footprint: 2 vCPU, 4 GB RAM, zero external daemon agents.

Zero Cloud Exfiltration Guarantee

Payloads, tokens, and PII are never transmitted to third-party servers. All AI heuristic models execute locally inside your boundary.

Multi-Architecture Support

Native support for Linux x86_64 and ARM64. Verified on RHEL, Debian, Ubuntu, and macOS.

docker-compose.yml STRICT AIR-GAP COMPATIBLE
# Stack Souveraine Locale (100% On-Premises)
services:
  transformer:
    image: apiangel/transformer:latest
    restart: unless-stopped
    depends_on: [mongo, rabbitmq]
    networks: [apiangel_internal]

  attacker:
    image: apiangel/attacker:latest
    restart: unless-stopped
    depends_on: [mongo, rabbitmq, validator]
    networks: [apiangel_internal]

  validator:
    image: apiangel/validator:latest
    restart: unless-stopped
    depends_on: [mongo, rabbitmq]
    networks: [apiangel_internal]

networks:
  apiangel_internal:
    internal: true # Confinement Air-Gap strict (zéro sortie WAN)

Direct Compliance Mapping: NIS 2, DORA & RGPD

Satisfy executive audits, supervisory authority requirements (ANSSI, ACPR, CNIL), and insurance cyber-warranty clauses.

MANDATORY 2024-2026

NIS 2 Directive (ANSSI)

Satisfies Article 21 for regular automated vulnerability testing and supply chain API security for Essential & Important Entities (EE/IE).

FINANCIAL ENTITIES

DORA Framework

Addresses Chapters II & IV for ICT security risk management and threat-led testing of banking and insurance financial APIs.

CNIL / EU LAW

RGPD / GDPR Compliance

Demonstrates proactive Article 32 technical measures to prevent personal data leaks (NIR, IBAN) and avoid multi-million euro CNIL sanctions.

STANDARD BENCHMARK

OWASP API Security Top 10

Full native coverage for API1:2023 (BOLA), API2:2023 (Broken Authentication), and API3:2023 (BOPLA).

See API Angel in Action

Watch how API Angel automatically isolates broken authorization logic in live API traffic and produces verified evidence dossiers with actionable remediation guidance.

Get Started — $99/mo Request Enterprise POC

Real-World Bug Bounty & Research Findings

Actual critical vulnerabilities uncovered by API Angel during authorized bug bounty programs and responsible disclosure coordinates.

Insurance

"A complex vulnerability was detected, bypassing an encrypted customer ID. API Angel was a game-changer!"

Encrypted Customer ID Bypass (BOLA)

Bug Bounty Program · Insurance Sector

Automotive Industry

"Thanks to API Angel, we secured our customers' data in the automotive industry."

Vehicle Telematics & Fleet API Protection

Bug Bounty Program · Automotive Industry

Service Provider

"API Angel identified a BOLA vulnerability in minutes with zero touch, enabling a quick fix."

Zero-Touch Fast BOLA Identification

Responsible Disclosure · Service Provider

Designed by CISSPs and Machine Learning PhDs

API Angel bridges theoretical AI research and rigorous offensive cybersecurity engineering.

Vincent Jeanselme

PhD Research Scientist - Machine Learning

PhD in Machine Learning & LLM Research · Specializing in heuristic fuzzing algorithms · NYC, USA

Julien Jeanselme

Lead Data Scientist & Full-Stack Architect

Data Science & High-Throughput Distributed Systems · Full-Stack Security Engineering · France

Nicolas Jeanselme

Cybersecurity & API Security Expert - CISSP

CISSP Certified Security Leader · API Security & Identity Governance Specialist · France

Enterprise Security Plans Tailored to Your Scale

Predictable licensing with on-premises deployment, priority support, and compliance guarantees.

Personal / Pro

For developers, security researchers, and engineers testing their own APIs.

$99 / month
  • File import (HAR, Burp export, PCAP)
  • Full BOLA, IDOR & Business Logic testing
  • GraphQL AST, SOAP XML & Base64 parsers
  • French & EU PII (NIR, IBAN, SIRET) + 1-click custom rules
  • Reproducible HTTP evidence & remediation guidance
  • Tri-Interface parity: Web UI, REST API & MCP
  • Single Docker instance deployment
Start Now — $99/mo

Request a Sovereign Proof of Concept

Schedule a CISO technical briefing or deploy a 14-day evaluation instance inside your perimeter.