Threats & API defense
See active attack signals and harden the API paths that matter.
See active attack signals and harden the API paths that matter.
What this feature is for
Threats & API defense combines public attack-surface checks, rate-limit evidence, key scope, and live threat signals so security work stays connected to app behavior. The important distinction is that PreFlight stores the observation alongside the app, release, provider, or customer path it belongs to. That context is what turns a signal into an operational decision.
Before you open it
A verified domain, known API routes, and a plan for handling or escalating a detected threat.
Use a real app in the workspace and start with the smallest useful scope. A narrow, representative check gives you a stronger baseline than connecting every environment and every provider at once.
Run the workflow
Review the attack surface, inspect the most recent events, verify policy headers and key scope, and use the linked remediation before closing a risk.
- Open the feature from the dashboard outcome hub.
- Choose the app and environment that match the decision you are making.
- Run or save the configuration, then wait for the evidence state to settle.
- Assign the next action to an owner before leaving the page.
Read the evidence
The evidence shows source signal, route or asset, severity, timestamp, and the action taken. A green state means the configured assertion passed at the recorded time. It does not claim that every unconfigured path is healthy. A warning is a useful lead; a failure should have a concrete owner and a verification run.
When the result is not healthy
Do not block a broad range based on one ambiguous event. Confirm the request pattern, protect the route, and preserve evidence for the incident record.
Do not erase the failed result after fixing the underlying system. Keep the history, rerun the check, and link the new passing evidence to the deployment or incident that caused the change. This gives the team a useful before-and-after record.
Use it with the rest of PreFlight
Use API defense with Audit, Incidents, Domain Ownership, and Release desk. Outcome hubs are deliberately connected: Audit finds risk, Deploy decides whether to promote, Health watches the running system, Revenue verifies the money path, Growth manages discoverability, and Trust publishes safe proof. Use the related links below to move between those decisions without losing context.
