Cloud, Security & Operations
API Security
Discovery, testing and protection of the APIs behind your mobile apps, partner integrations and microservices, focused on the authorisation flaws attackers exploit most.
Capability overview
What api security involves
APIs expose business logic and data directly, often with less scrutiny than the web pages built on top of them. The most damaging API flaws are rarely exotic: an endpoint that returns another customer's record when an ID is changed, or an admin function reachable by a normal user.
We work through the OWASP API Security Top 10, starting with broken object level and function level authorisation, and check how tokens are issued and validated. Protection is then enforced at the gateway with authentication, schema validation and rate limits.

What is included
Areas of focus
API inventory
Endpoints discovered from gateway logs, traffic and code, including undocumented, deprecated and shadow versions still reachable in production.
Authorisation testing
Requests replayed across user roles and tenants to confirm each object and function checks who is asking, not just whether they are logged in.
Token and OAuth review
OAuth 2.0 and OpenID Connect flows, JWT signing, expiry and scope handling checked against current best practice.
Gateway protection
OpenAPI schema validation, per-client quotas and anomaly alerts configured in gateways such as Kong, Apigee, AWS API Gateway or Azure API Management.
How we work
How we deliver api security
Specification gathering
OpenAPI or Postman collections obtained, or generated from traffic when documentation does not exist.
Role and tenant matrix
Test accounts created for each role and tenant so cross-account access can be tested systematically.
Manual testing
Each endpoint exercised for authorisation, mass assignment, excessive data exposure and injection weaknesses.
Gateway hardening
Validation rules, quotas and logging added at the gateway, starting in report-only mode to avoid breaking clients.
Regression suite
Authorisation test cases handed over as automated tests your team can run on every release.
Related capabilities
Related capabilities in Cybersecurity
Cloud Security
Security posture management for AWS, Azure and Google Cloud: identity and permissions, network exposure, logging, encryption and guardrails that stop misconfigurations before they reach production.
Network Security
Design, hardening and review of firewalls, VPNs, wireless and internal segmentation across offices, data centres and branch sites, so a single compromised device cannot reach everything.
Endpoint Security
Protection for laptops, desktops, servers and mobile devices through endpoint detection and response, hardening, patching and device management that works for remote and office staff.
Identity & Access Management
Single sign-on, multi-factor authentication, joiner-mover-leaver automation, privileged access control and access reviews that make sure the right people have the right access, and no more.
Explore further
Explore connected pages
Related services
Related solutions
Cloud Transformation Solutions
Cloud, security, integration, modernization and platform engineering solutions. Acmez shapes…
Cybersecurity Solutions
Cloud, security, integration, modernization and platform engineering solutions. Acmez shapes…
Managed Technology Solutions
Quality, infrastructure, managed services and dedicated team solutions. Acmez shapes managed…
Where this applies
Healthcare & Life Sciences
Technology systems for regulated environments where privacy, auditability and continuity…
Manufacturing & Industrial
Connected operations, asset, field, supply chain and industrial platforms for complex operating…
Banking, Financial Services & Insurance
Technology systems for regulated environments where privacy, auditability and continuity…
E-Commerce
Digital platforms for customer experience, operations, commerce, content, marketing and service…
Questions & answers
Questions about API Security
Cannot find what you need? Our team responds to technical and commercial questions within one business day.
Ask a questionAPIs are consumed by programs, not browsers, so browser protections do not apply and flaws are easier to automate at scale. The testing approach and controls are different.
Yes. We intercept the app's traffic to map its endpoints, then test the API directly, which is how an attacker would approach it.
An API with thirty to fifty endpoints and a few roles typically needs one to two weeks of testing. Gateway hardening is scheduled after findings are agreed.
Only partly. A gateway can enforce authentication, schemas and quotas, but checking whether a user may see a particular record depends on business rules that must live in the application code itself.
Next step
Discuss api security with Acmez
Share what you need to change, build, integrate or support. We will map the practical next step.