Listing Thumbnail

    Salt Security API Protection Platform

     Info
    Deployed on AWS
    Salt Security protects the APIs that power your business including the APIs behind AI agents, mobile apps, SaaS platforms, and microservices. Our platform delivers deep visibility, threat detection, and runtime protection to stop API attacks and secure your entire API ecosystem leveraging the AWS infrastructure.

    Overview

    Play video

    Salt Security is the leader in API security, delivering the industry's most comprehensive solution to discover, protect, and govern the APIs that power modern applications and agentic AI. Our platform provides continuous discovery of all APIs including internal, shadow, and third-party APIs without relying on traffic replay or manual effort.

    Salt uses patented AI and ML to detect anomalies in API behavior, stop attacks in real time, and help organizations shift left by integrating security insights into development pipelines.

    As AI agents, LLMs, and MCP servers reshape the software landscape, Salt uniquely enables security teams to see which agents are active, what data they access, and whether they are operating within policy. Salt deploys in minutes, scales across your AWS cloud environment, and helps businesses protect critical data, reduce risk, and accelerate digital innovation with confidence.

    Highlights

    • Salt Discovery - Discover all APIs and exposed sensitive data
    • Salt Prevention - Stop attacks early, during reconnaissance
    • Salt Remediation - Improve your API security posture

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Salt Security API Protection Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (2)

     Info
    Dimension
    Description
    Cost/12 months
    Overage cost
    Enterprise
    Console Access and Support + up to 100M API calls/month for 12 months
    $100,000.00
    Startup
    Console Access and Support + up to 5M API calls/month for 12 months
    $36,000.00
    -

    Vendor refund policy

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    The Salt Security license includes access to customer support and customer success teams for full on-boarding support, including deployment support and technical integrations for alerts, enforcement, remediation tickets, and other security tasks. support@salt.security 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Testing
    Top
    50
    In Managed Services

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    12 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    API Traffic Analysis
    Collects and analyzes API traffic across entire application landscape using big data and AI/ML techniques
    Threat Detection
    Uses patented AI to baseline legitimate API behavior and identify potential attackers during reconnaissance phase
    API Discovery
    Automatically identifies all APIs, including shadow and zombie APIs, with continuous and automated discovery mechanisms
    Vulnerability Identification
    Proactively detects and highlights API vulnerabilities before production traffic deployment
    Attack Prevention
    Correlates attacker activities to a single entity and blocks attackers comprehensively instead of individual transactions
    API Discovery
    Automated identification and comprehensive cataloging of APIs across different environments
    Vulnerability Assessment
    Systematic evaluation of API security posture and potential weaknesses before production deployment
    Runtime Protection Mechanism
    Real-time safeguarding of APIs and associated resources during active execution
    Active Security Testing
    Proactive identification and remediation of API vulnerabilities during development lifecycle
    Infrastructure Integration
    Seamless integration capabilities with existing application environments like API gateways, load balancers, and web application firewalls
    API Discovery
    Automated identification and mapping of internal and external APIs using patented analytics engine
    Machine Learning Traffic Analysis
    Advanced machine learning techniques for analyzing API traffic without requiring JavaScript instrumentation or mobile SDK integration
    Attack Detection and Prevention
    Customizable rules and policies to detect and mitigate automated attacks like account takeovers, credential stuffing, and API business logic abuse
    Behavioral Fingerprinting
    Dynamic tracking of attack patterns using behavioral fingerprint technology across different attack methodologies
    Flexible Mitigation Options
    Multiple response mechanisms including blocking, rate limiting, geofencing, and deceptive response generation for API protection

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    |
    13 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    IgmarRautenbach

    Provides visibility and control over all APIs

    Reviewed on Jan 08, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We use it to provide enhanced and improved security around API integrations for organizations. Given the product's backing by Google and Sequoia Capital, it's truly great.

    What is most valuable?

    It fills a gap in the market. Organizations lack visibility into their API landscape and posture. They don't know if APIs are secure, well-developed, or have vulnerabilities. They also can't detect API attacks until it's too late. 

    Salt Security  gives you visibility of all your APIs, identifies API security issues, and immediately alerts you of attacks.

    These are the main things organizations lack, even if they're already using APIs. Salt fills that gap for them.

    What needs improvement?

    I've built integrations for different systems, and some specific integrations might not be built in yet. This might be an issue for large customers but is not a major concern overall. 

    So, the integration part could be a bit extended. Every organization has different systems, but Salt integrates with 90% of them. If a custom integration is needed, they can build it. They're very good at integrations. So, Salt Security  can provide a proof of concept with system integration and share results within two weeks, which often leads to customer purchases.

    At this point, the product covers everything needed. They keep adding new features, and my local customers haven't requested any missing functionality. The product roadmap is good for the market.

    For how long have I used the solution?

    I have been with this solution for 18 months. It's new to the EDR market. I only launched in the New York market two years ago. We deal with the latest version.

    What do I think about the stability of the solution?

    It's really great. I would rate the stability a nine out of ten. I haven't encountered any instability issues.

    What do I think about the scalability of the solution?

    It's really, really scalable. Some customers handle seven billion API calls a month. That requires cloud deployment and scaling resources, which they do well, so ten out of ten.

    It's relatively new, about ten organizations in South Africa, but we have ongoing proof of concept. The adoption is rapid.

    How are customer service and support?

    The customer service and support are good; they know their stuff.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We still use XY and Netscout VSN, but they offer limited API security compared to Salt's comprehensive integration and stability. Salt created its own category. 

    Other vendors might be on-premise, part of larger solutions, or more complex. That's Salt's advantage and why it's gaining market share.

    How was the initial setup?

    It's a SaaS solution that mirrors traffic, so it's not an inline solution. That means two weeks is a general guideline for implementation.

    The deployment model is hybrid. Typically, in our market, it's hybrid with an on-prem server and the solution itself in the cloud.

    The challenge with deployments is limited personnel due to rapid growth. I work with over a hundred companies in EMEA for evaluation, so technical constraints might arise. 

    However, we assist customers with integrations as it's more organizational than software-related.

    What about the implementation team?

    We have a team of 20 engineers skilled in the solution to provide local support.

    What's my experience with pricing, setup cost, and licensing?

    It is an annual subscription fee. It's very affordable. The value it provides justifies the cost, considering automation and availability features. Compared to other solutions, it's within a typical price range.

    Which other solutions did I evaluate?

     

    What other advice do I have?

    My initial discussions with organizations often reveal they lack visibility into their API landscape and sensitive data. The first discussion is how many APIs you have. How many integrations? Do you have sensitive data in your organization? And the answer from the head of security is, typically, "We don't know!"

    Organizations need a solution. And from what you've seen, that's where solutions like Salt come in. So, I would recommend this to to any organization, large and small.

    I would rate it a ten out of ten because it addresses fundamental risks that exist in dealing with sensitive information. It's crucial to have a solution like Salt in place. It's like a basic requirement, not just something that enhances efficiency.

    Information Technology and Services

    Senior Manager, Security

    Reviewed on Jul 10, 2023
    Review provided by G2
    What do you like best about the product?
    The product has been instrumental in helping us resolve attacks and better understanding vulnerabilities. The responsiveness from Salt team is great.
    What do you dislike about the product?
    Better root cause findings when issues are identified. However, the product is consistently getting better.
    What problems is the product solving and how is that benefiting you?
    Helping determine API vulnerabilities and prevent attacks.
    Insurance

    Amazing API security tool

    Reviewed on Jun 05, 2023
    Review provided by G2
    What do you like best about the product?
    First of all, the entire Salt team is a pleasure to work with. They are always responsive and are always eager to assist. Secondly, the Salt Security is the creme de la creme of API security tools. It does so much, and is a valuable tool in assisting with keeping our APIs safe.
    What do you dislike about the product?
    There is nothing that I dislike about this too.
    What problems is the product solving and how is that benefiting you?
    Salt Security is solving the issue of API security. As our organization starts to utilize APIs a lot more, we realized that there was a gap in monitoring those APIs. Now that we have brought on Salt, we can rest easy that our APIs are being monitored and protected.
    Retail

    Good Solution in Changing Landscape

    Reviewed on Feb 01, 2022
    Review provided by G2
    What do you like best about the product?
    A very lightweight solution that builds upon existing integrations, a responsive and open-minded support team, and an easy-to-navigate product. Salt isn't trying to solve every problem; they've found a niche and have focused on tightly sealing that gap.
    What do you dislike about the product?
    The product is still relatively new and missing quite a few bells and whistles. The SIEM logging integrations are missing native action logging, and we've had difficulties getting APIs going through a gateway to report correctly as unique items. However, Salt is a great partner and has been working with us through our requirements to improve the functionality that we need.
    What problems is the product solving and how is that benefiting you?
    We have not yet finished our implementation, but Salt will help us better secure our APIs without having to rely on heavy customization of some of the larger WAF-like products that are built to protect traditional applications.
    Financial Services

    Salt Security Survey

    Reviewed on Jan 31, 2022
    Review provided by G2
    What do you like best about the product?
    Attack traffic is probably the most consulted screen, however the security insights, sensitive information screens and endpoint autodiscovery are all also very useful
    What do you dislike about the product?
    I would like to see API compositions and other calls chains (sequences of APIs calling each other) stitched together graphically so the exact specific call chain that each API call was part of is super clear.
    What problems is the product solving and how is that benefiting you?
    Identifying potentially malicious traffic, tightening up the handling of sensitive information, detecting improper use of authentication and other security details.
    View all reviews