What we do
What we review in your backend
- Excess fields in responses (OWASP API3)
- Functions without access control (OWASP API5)
- Inventory of published routes (OWASP API9)
- Endpoint contract and catalog
- Security headers
- Blocking of probes and fake crawlers
- Personal data in the logs