API Secure enables you to identify your entire attack surface everyday and prevents data breaches at every layer of the application stack. API Secure product is designed to:
Inventory all your APIs
Hack your APIs
Remediate security issues within the CI/CD pipeline
Data Theorem's security analyzer engine continuously discovers vulnerabilities in multi-cloud/on-premise environments and provides critical alerts/remediation solutions in real time. API security issues within authentication, authorization, and encryption are all covered with 1000+ tests across several hacking toolkits.
Data Theorem is a leading provider of modern application security. Its core mission is to prevent AppSec data breaches. The Data Theorem Analyzer Engine continuously scans mobile and web applications, APIs, and cloud resources in search of security flaws and data privacy gaps. Our security products provide automated hacking and full application stack discovery that protects your data.
Highlights
Monitor, hack, and secure 100% of your RESTful APIs, serverless, & single page web apps
Auto-remediate issues across your attack surface before a breach occurs
Discovers dynamic run-time security flaws across all 5 pillars of security - Authentication, authorization, encryption, availability, auditing
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
API Secure prices by the number of API operations you monitor. Three paid tiers scale with your API count: Basic covers 1-25 API operations, Standard covers 26-50, and Enterprise covers 51-100. You pick the tier that matches your environment's size. All three deliver the same continuous API security service; only the covered operation count changes. A separate 30-day free trial lets you evaluate the service before you commit to a paid tier.
Top-of-mind questions for buyers
What counts as one API operation for billing purposes?
An API operation is a distinct endpoint action the service monitors, such as a GET or POST on a specific API route. The service discovers these through blackbox scanning of your public perimeter, cloud environments, and gateways. Each tier caps how many operations you can protect, so your count determines the tier you pick.
What happens if my API operation count grows past my current tier limit?
Each tier covers a fixed range: Basic up to 25 operations, Standard 26-50, and Enterprise 51-100. If your operation count exceeds your tier's range, you move to the tier matching your new size. The change is not automatic — you select the tier that fits your environment.
Do all three paid tiers include the same security capabilities?
Yes. Basic, Standard, and Enterprise all deliver the same continuous API security service. That includes API discovery and inventory, security posture management, testing, and runtime protection across more than 200 attack signals. Only the number of covered API operations changes between tiers.
www.datatheorem.com
Helpful?
Vendor refund policy
Fully refundable within 90 days
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Fortinet Managed Rules for AWS WAF - API Security provides protection against API based attacks, with rules based on threat intelligence from FortiGuard Labs, Fortinet threat intelligence and research organization.
Protects against API attacks, web attacks (such as XML external entity attacks) and server side request forgery. The rule set includes support for XML and JSON payloads, and common web API frameworks.
Akto is a SaaS based API security platform. Akto collects API traffic across your entire app surface to discover your APIs, their exposed sensitive data, test for vulnerabilities in CI/CD, and find, block API threats in runtime.
Radware API Security Service delivers end-to-end API protection through continuous API discovery, runtime posture management, contextual testing, and AI-driven defense. It helps organizations identify exposed or misconfigured APIs, reduce risk, and protect against business logic abuse, automated threats, and DDoS attacks across modern application environments.
Salt Security protects the APIs that power your business including the APIs behind AI agents, mobile apps, SaaS platforms, and microservices. Our platform delivers deep visibility, threat detection, and runtime protection to stop API attacks and secure your entire API ecosystem leveraging the AWS infrastructure.