Salt Security added API security posture insights and automated OpenAPI Specification (OAS) analysis and reporting capabilities to its API Protection Platform.

The move comes as API security vulnerabilities such as those that led to the Experion and Peloton data leaks highlight the need to identify flaws and secure APIs before they reach production. And Salt Security’s updates help teams do this by “shifting left,” or integrating security earlier in the development process, said Elad Koren, chief product officer at Salt Security.

“When we first embarked upon this this mission of API security, we started from the right side — the production, runtime,” he said. “One of the things we have heard from customers is: ‘Why wait until production?’” Koren said.

To this end, Salt added a security posture insights feature to the platform that identifies API risks and vulnerabilities before they can be exploited. It essentially tells customers “nothing happened yet, but you should be aware of the fact that this is a big vulnerability. It’s a gap [in your security posture] and you should fix that,” Koren explained.

The platform analyzes pre-production traffic, and it alerts companies about sensitive data in the URLs and security misconfigurations, he added.

The Salt platform now also performs OAS analysis, comparing OAS documentation and the actual APIs and sensitive data that the platform discovers. “We’ll show you the endpoints and how many of them are shadow endpoints — those that are undocumented but actually in use — and shadow parameters. Some of them may contain sensitive data,” Koren said. “If this is done in pre-prod, you can flag those endpoints that contain sensitive data before they get to production.

The company claims that, on average, customer evaluations reveal 40% to 800% more APIs in use than companies have in their documentation and 10- to 20-times the number of parameters.

Salt sends real-time alerts whenever the APIs and exposed parameters it discovers do not match OAS documentation. Organizations can export the full discovery of APIs and exposed data as updated and accurate OAS files to ensure documentation is complete before APIs are published.

Customers want visibility into security vulnerabilities earlier in the application development process, “which is why we developed the ability to get the security insights even sooner in pre-prod, and it is why we are developing more and more capabilities around shift left,” Koren said. But, he adds, “I don't think that it’s enough.”

And that is why Salt will continue shifting left, and it aims to build security insights into the continuous integration/continuous development (CI/CD) process later this year, Koren said. “The next hop on that shift would be to allow the developers to get some insights, even before it gets to pre-prod, so one of the things that we’re adding is the ability to get development pipeline integration seamlessly,” he said.

However, Salt is also shifting right. “Our customers are constantly asking for more things that are related to their ability to control their ecosystem from within Salt,” Koren explained.

And to this end, the company is developing technology to block threats on the API level from the Salt platform. “This is something we’re also addressing in the roadmap,” Koren said. “To be able to interact further with these environments, and orchestrate everything related to APIs.”