MAYA - AI Agent
Team Leader of AI Agents
Remediation Agent
Runs a dry run, waits for your approval, then fixes it
Evidence Collector
Collects your SOC 2, ISO 27001 and DPDP proof from the tools you already use
IP Scanner
Checks every public address for open ports, known CVEs and weak TLS
DAST (Public + Private)
Tests your APIs for 300+ vulnerability classes, inside and outside the network
CSPM
1,000+ checks across AWS, Azure and Google Cloud, mapped to your frameworks
Cloud Cost Optimization
Rightsizing and idle detection - customers cut cloud spend 28% on average
Integrations
20+ Integrations with your favorite tools
Asset Management
Finds vulnerabilities on your laptops and servers
ECR Container Image Scanning
Scans every ECR image for CVEs before it reaches production
Cloud Security
Keeping AWS, GCP and Azure locked down
AI Governance
Using AI at work without losing control of it
Data Privacy
DPDP, GDPR and looking after personal data
GRC
Audits, controls and staying ready for them
FinOps
Spending less on cloud without breaking things
API Security
Finding holes in your APIs before anyone else
API Security & Discovery Find every API. Secure every endpoint.
Automatically discover APIs across your Nginx and Kubernetes infrastructure using lightweight agents - with zero blind spots and continuous monitoring for sensitive data exposure.
API Security & Discovery at a glance
- What it does
- Automatically discover APIs across your Nginx and Kubernetes infrastructure using lightweight agents - with zero blind spots and continuous monitoring for sensitive data exposure.
- In one line
- Nginx + K8s agents auto-discover every API, including shadow APIs.
- Human control
- Point it at staging first.
- Setup
- About 15 minutes, read-only access, no credit card.
- Pricing
- Free first scan; Pro from $99/month; Enterprise from $10,000/year. See pricing.
Your API list and your actual APIs stopped matching a while ago.
Endpoints get shipped faster than they get written down. A route added for one integration, a version nobody deprecated, a service that quietly returns more than its docs say. The list in the wiki is honest - it is just eighteen months old.
Four steps to done.
- 01Agent Deploy
Lightweight Nginx and Kubernetes agents deploy in minutes with no infrastructure changes required.
- 02Auto-Discovery
Agents automatically discover every API endpoint across your entire infrastructure - including undocumented and shadow APIs.
- 03Data Classification
Identifies APIs exposing PII, credentials, payment data, and other sensitive information matching GDPR and CCPA patterns.
- 04Continuous Monitoring
Ongoing monitoring for new endpoints, changed schemas, and emerging vulnerabilities with instant alerts.
Everything included.
Automatic API discovery via Nginx and Kubernetes agents
Zero-config deployment - no infrastructure changes needed
Sensitive data detection (PII, credentials, payment info)
GDPR and CCPA compliance validation per endpoint
Shadow API and undocumented route detection
Continuous monitoring with real-time change alerts
Point it at staging first.
Scans are scoped and scheduled by you, any endpoint can be excluded, and a running scan stops from the screen you started it on. Most teams run against staging until they trust the result, then move to production in a window that suits them.
- An active scan sends real requests. Start on staging, and exclude anything you would rather not touch.
- It tests the endpoints you expose. It cannot test a partner's API on your behalf.
- Private endpoints need the private scanner - one binary, running inside your network.
Common questions about API Security & Discovery.
Automatically discover APIs across your Nginx and Kubernetes infrastructure using lightweight agents - with zero blind spots and continuous monitoring for sensitive data exposure. Nginx + K8s agents auto-discover every API, including shadow APIs.
1. Agent Deploy: Lightweight Nginx and Kubernetes agents deploy in minutes with no infrastructure changes required. 2. Auto-Discovery: Agents automatically discover every API endpoint across your entire infrastructure - including undocumented and shadow APIs. 3. Data Classification: Identifies APIs exposing PII, credentials, payment data, and other sensitive information matching GDPR and CCPA patterns. 4. Continuous Monitoring: Ongoing monitoring for new endpoints, changed schemas, and emerging vulnerabilities with instant alerts.
An active scan sends real requests. Start on staging, and exclude anything you would rather not touch. It tests the endpoints you expose. It cannot test a partner's API on your behalf. Private endpoints need the private scanner - one binary, running inside your network.
Connecting takes about 15 minutes with read-only access. No credit card and no sales call are needed to run the first scan.
It is included in DeDups: one full scan of one AWS account is free with no card, Pro is $99 a month plus published per-unit rates, and Enterprise starts at $10,000 a year. All rates are on the pricing page.
Ready to try API Security & Discovery?
15 minutes to connect. No credit card. No sales call required.