Discover unauthorized data exposure paths before attackers do. API Angel passively captures live traffic, decodes complex GraphQL ASTs, SOAP XML, and Base64 identifiers, providing undeniable HTTP evidence dossiers and automated retesting to verify fixes.
In the recent wave of French data breaches, attackers did not bypass firewalls or use zero-day SQL injections. They exploited Broken Object Level Authorization (BOLA / IDOR) on legitimate endpoints using valid authentication tokens.
Traditional Web Application Firewalls (WAFs) and API Gateways inspect HTTP syntax, rate limits, and authentication signatures. Because a BOLA request contains a valid JWT/Session and well-formed parameters, WAFs see it as 100% legitimate traffic and allow attackers to systematically enumerate citizen NIRs, patient records, and banking IBANs.
See how API Angel systematically isolates authorization breakdowns in HTTP traffic and produces auditable evidence dossiers with actionable remediation guidance and automated retest verification.
// Loading exploit sample...
// Loading remediation sample...
From non-invasive traffic ingestion to verified remediation guidance and retesting: how API Angel uncovers vulnerabilities in your production and pre-production APIs without slowing down development cycles.
Capture live API traffic via passive mirror, eBPF, or import HAR, Burp Suite, and PCAP exports. Zero latency overhead on production.
Automatically unpacks Base64, UUIDs, GraphQL Node IDs, and SOAP XML envelopes, recognizing sensitive French PII formats (NIR, IBAN, SIRET).
Executes targeted mutation scenarios across user identities to uncover both horizontal (peer) and vertical (privilege escalation) BOLA paths.
Confirms each vulnerability with exact HTTP request/response payloads, status codes, and mutated parameter traces, providing undeniable proof for engineering and compliance.
Provides actionable architectural remediation guidance and executes automated retests to verify fixes and block regressions in CI/CD.
Comprehensive coverage across modern microservices and legacy institutional protocols.
Native parsers for French NIR (Sécurité Sociale), French IBANs (FR76), SIREN/SIRET, mutual contracts, plus instant 1-click custom regex and keyword rules for your company-specific sensitive data.
Full AST inspection of GraphQL queries, legacy SOAP XML element trees, URL-encoded forms, and Base64 transcoded tokens across all editions.
Differentiates peer data access from administrative privilege escalation, boosting risk scores for high-impact vertical breaches.
Complete parity across Web Dashboard, headless REST API for CI/CD gating, and sovereign MCP (Model Context Protocol) server for AI coding assistants (Cursor, Claude, Copilot).
4 distinct operational levels (Low, Medium, High, Max) allowing type-safe targeted swaps or full host-level identifier permutations.
Generates audit-ready evidence dossiers with exact HTTP replays, plus a 1-click automated retest engine to verify developer patches before release.
Your API traffic contains your most sensitive citizen and customer data. API Angel is built with strict privacy-by-design guarantees.
Runs entirely within your private network or private cloud (OVHcloud, Scaleway, AWS Outposts). No outbound telemetry required.
Standard Docker Compose or Kubernetes Helm chart. Minimal footprint: 2 vCPU, 4 GB RAM, zero external daemon agents.
Payloads, tokens, and PII are never transmitted to third-party servers. All AI heuristic models execute locally inside your boundary.
Native support for Linux x86_64 and ARM64. Verified on RHEL, Debian, Ubuntu, and macOS.
# Stack Souveraine Locale (100% On-Premises)
services:
transformer:
image: apiangel/transformer:latest
restart: unless-stopped
depends_on: [mongo, rabbitmq]
networks: [apiangel_internal]
attacker:
image: apiangel/attacker:latest
restart: unless-stopped
depends_on: [mongo, rabbitmq, validator]
networks: [apiangel_internal]
validator:
image: apiangel/validator:latest
restart: unless-stopped
depends_on: [mongo, rabbitmq]
networks: [apiangel_internal]
networks:
apiangel_internal:
internal: true # Confinement Air-Gap strict (zéro sortie WAN)
Satisfy executive audits, supervisory authority requirements (ANSSI, ACPR, CNIL), and insurance cyber-warranty clauses.
Satisfies Article 21 for regular automated vulnerability testing and supply chain API security for Essential & Important Entities (EE/IE).
Addresses Chapters II & IV for ICT security risk management and threat-led testing of banking and insurance financial APIs.
Demonstrates proactive Article 32 technical measures to prevent personal data leaks (NIR, IBAN) and avoid multi-million euro CNIL sanctions.
Full native coverage for API1:2023 (BOLA), API2:2023 (Broken Authentication), and API3:2023 (BOPLA).
Watch how API Angel automatically isolates broken authorization logic in live API traffic and produces verified evidence dossiers with actionable remediation guidance.
Actual critical vulnerabilities uncovered by API Angel during authorized bug bounty programs and responsible disclosure coordinates.
"A complex vulnerability was detected, bypassing an encrypted customer ID. API Angel was a game-changer!"
"Thanks to API Angel, we secured our customers' data in the automotive industry."
"API Angel identified a BOLA vulnerability in minutes with zero touch, enabling a quick fix."
API Angel bridges theoretical AI research and rigorous offensive cybersecurity engineering.
PhD in Machine Learning & LLM Research · Specializing in heuristic fuzzing algorithms · NYC, USA
Predictable licensing with on-premises deployment, priority support, and compliance guarantees.
For developers, security researchers, and engineers testing their own APIs.
For security teams requiring continuous API monitoring, CI/CD gating, and on-premises sovereign confinement.
Schedule a CISO technical briefing or deploy a 14-day evaluation instance inside your perimeter.