US Enterprises Are Outrunning Their Own API Visibility
APIs now carry the majority of production traffic across US banking, healthcare, SaaS, retail, and government systems, and increasingly, the traffic behind that traffic: AI agents, copilots, and Model Context Protocol (MCP) servers calling APIs on an organization’s behalf. For buyers, the practical question is specific: can a platform actually discover, govern, and protect every API you run, including the ones no human remembers deploying, not just the endpoints sitting behind your public gateway?
This guide compares the top API security providers in the USA for 2026, helping enterprise, financial services, healthcare, SaaS, and cloud-native organizations evaluate the right platform for their environment.
What Getting This Wrong Actually Costs
In early June 2026, ServiceNow began notifying customers that data in customer instances had been queried through a ServiceNow API endpoint reportedly
/api/now/related_list_edit/create— without normal authentication controls. No credentials were stolen. No malware was involved. According to community and third-party reporting, a Scripted REST Resource had been deployed withrequires_authentication=falseso the endpoint answered requests it should never have accepted. Every WAF sitting in front of that traffic waved it through, because from a network perspective it looked like a normal, authenticated call.
ServiceNow applied a security update to hosted instances on June 5, 2026, and notified affected customers directly. At the time of writing, ServiceNow has not assigned a CVE to this issue. While community analysis has identified specific API endpoints and suggested a likely root cause, ServiceNow has not publicly confirmed those technical details. ServiceNow has confirmed that it observed anomalous activity and evidence of successful queries against a subset of customer instances. The company has also indicated that some of the observed activity appears to have originated from security researchers and customer bug bounty submissions rather than exclusively malicious actors.
The caveats don’t blunt the lesson. That’s the story API security has to reckon with in the US right now, and it isn’t isolated: the attackers increasingly aren’t breaking in they’re logging in, or querying an endpoint that never checked whether they should be allowed to.
US Cyber & API Threat Landscape in Numbers (2025–2026)
| Metric | 2025–26 figure | Trend |
|---|---|---|
| Published security bulletins tied to APIs | 11,053 of 67,058 (17%) | API share of all reported vulnerabilities – Wallarm |
| API attacks arriving through authenticated sessions | 95% | According to Salt Security telemetry |
| IC3 complaints reported | 1,008,597 | First year over 1 million |
| Reported cybercrime losses (2025) | $20.877 billion | +26% year-over-year |
| “AI-related” fraud complaints (new IC3 category) | 22,000+ / ~$900M in losses | First year tracked separately |
| Organizations reporting API growth over 50% YoY | 66% | Salt Security, 1H 2026 |
| Organizations lacking maturity to secure agentic/AI environments | 92% | Salt Security, 1H 2026 |
| Commerce organizations that know which of their APIs expose sensitive data | Only 22% | According to Akamai Survey, July 2026 |
| Enterprises broadly with full API inventories including sensitive-data mapping | ~23% | Akamai 2026 API Security Impact Study |
Source: FBI IC3 2025 Annual Report; Wallarm 2026 API ThreatStats Report; Salt Security 1H 2026 State of AI and API Security; Akamai State of the Internet, July 2026
What Security Teams Now Have to Protect
Why Authenticated Traffic Is the New Perimeter
Every stage of a typical account-takeover chain runs through an API: a login endpoint absorbing stuffed credentials, a session-refresh endpoint replaying a stolen cookie, an account-recovery endpoint an attacker walks through once inside. None of it looks unusual to a tool built to inspect network traffic rather than understand what a specific account, service, or agent normally does.
That gap is compounding fast. Salt Security warns of “Shadow MCP” AI agents creating undocumented endpoints and connecting to unapproved services. Akamai’s latest research found that only 22% of commerce organizations know which APIs expose sensitive data, while just 23% of organizations maintain complete API inventories with sensitive-data mapping. You can’t secure what you can’t see, and for most organizations, API visibility remains one of the biggest security blind spots.
The Four-Part Test for an API Security Solution Provider
Most security teams can point to their public-facing APIs without much effort. What trips them up is everything behind that: the internal API a microservice calls, the East-West traffic moving through a Kubernetes cluster, the AI agent talking to a backend nobody flagged for review. The ServiceNow incident is the case study for why that gap matters, the breach didn’t happen at an endpoint anyone was monitoring.
An API security provider worth shortlisting should be able to answer yes to each of these, not just the first:
- Discovery: Can it find every API running in production right now including shadow, zombie, and endpoints nobody documented?
- Runtime detection: Does it protect against business logic abuse and credential misuse at runtime, or only against attacks matching a known signature?
- East-West visibility: Does its visibility extend into Kubernetes and cloud East-West traffic, where lateral movement actually plays out after a breach?
- Fine-grained governance: Does it govern access down to the sub-resource level, so a new API or agent shipping next sprint doesn't quietly widen your exposure?
If a platform can only do the first of these, it’s a discovery tool wearing an API security label, not a full solution.
To keep this list honest, three ground rules:
- Same test for everyone. Every provider below Prophaze included is measured against the same four public criteria above (discovery, runtime detection, East-West visibility, sub-resource governance), plus deployment model. We don't score vendors on capabilities we can't verify from public documentation, analyst coverage, or hands-on evaluation.
- We disclose our stake. Prophaze publishes this guide and is one of the vendors on it. Where we describe Prophaze, we tie each claim back to a testable capability so you can validate it in a trial — not to marketing adjectives.
- We name what we don't know. Where a capability depends on your environment (e.g., legacy vs. microservices), we flag it as an Evaluation Consideration rather than a verdict.
What to Look for in an API Security Solution Provider
Discovery & Visibility
- Continuous runtime discovery across external, internal, shadow, and zombie APIs, outdated documentation is exactly what let ServiceNow's exposed endpoint go unnoticed.
- Full East-West visibility inside Kubernetes and service mesh, where lateral movement happens after a breach.
Detection Built for Authenticated Traffic
- Behavioral baselining across accounts and services, since 95% of API attacks now arrive through sessions that already passed authentication.
- Business logic abuse detection that doesn't rely on signatures, the attacks getting through aren't using known exploits.
Fine-Grained Access Governance
- Sub-resource-level access scoping for every API, service, and integration, containing exposure as new endpoints ship faster than teams can review them.
- Policy that holds as API volume grows past 50%+ YoY, which two-thirds of organizations are already seeing.
Why US Enterprises Prioritize API Security Now
- The ServiceNow pattern will repeat. An API answering a request it should refuse doesn't need malware or stolen credentials, just a gap in discovery.
- 2025 was a record year for losses. Reported cybercrime losses of $20.877B mean the cost of skipping API security is no longer theoretical.
- Compliance needs numbers, not estimates. Continuous posture data turns "we think we know what's exposed" into an actual audit trail. relevant to HIPAA, PCI-DSS 4.0, GLBA/GLBA Safeguards Rule, SOX, and FFIEC guidance for US-regulated organizations.
- API growth won't slow down. Governing access now costs far less than retrofitting it after volume, and exposure, outpace your visibility.
Top 7 API Security Providers in the USA (2026)
1. Prophaze
AI-native API security built for modern cloud-native applications. Unlike platforms that rely on static rules and manual policy tuning, Prophaze continuously learns application behavior, discovers shadow, zombie, orphaned, and undocumented APIs at runtime, and detects business logic abuse and zero-day exploits through behavioral analysis and deep payload inspection.
Built Kubernetes-native, Prophaze secures external APIs, internal APIs, and East-West traffic, providing continuous visibility, governance, and runtime protection from a single platform.
With Prophaze, organizations can:
- Discover shadow, zombie, orphaned, and undocumented APIs
- Gain visibility across external, internal, and East-West API traffic
- Detect business logic abuse with behavioral API security that holds false positives down near zero against signature-based tools.
- Govern REST/GraphQL access down to the sub-resource level , scoping exactly what any client, service, or integration can reach.
- Deploy agentless, in minutes, with no code changes
- Choose self-managed or fully managed deployment, with WAF, bot management, and L7 DDoS unified in one console.
Prophaze has been named a Representative Vendor in a Gartner Market Guide for Cloud WAAP and has also been recognized by KuppingerCole for its innovation in application security. These industry recognitions reinforce our commitment to helping organizations secure modern applications and APIs with AI-driven protection.
Prophaze is built to defend against how modern API attacks actually work including the authenticated-looking, signature-evading traffic pattern of the kind reported in the ServiceNow incident.
2. Cloudflare API Shield
Cloudflare API Shield runs machine learning and heuristics across Cloudflare’s global network to catalog every endpoint, including undocumented ones, then enforces a positive security model that blocks any request failing schema validation, the same mechanism that would have flagged ServiceNow’s unauthenticated query pattern as anomalous.
Evaluation Consideration: Organizations with complex API environments should evaluate runtime discovery depth, governance capabilities, and visibility into internal APIs and East-West traffic alongside protection for internet-facing APIs.
3. Akamai API Security
Akamai organizes protection around four published domains, Discovery, Posture Management, Runtime Protection, and Testing, and layers behavioral analytics on a historical data lake, with a Shadow Hunt managed service that routes ML-flagged signals to human analysts rather than closing the loop purely on automation.
Evaluation Consideration: Organizations should assess deployment complexity, policy tuning requirements, and the depth of runtime visibility needed for cloud-native environments.
4. Imperva API Security
Now part of Thales since its 2023 acquisition, Imperva runs a three-step Discover–Assess–Mitigate model and has drawn particular attention for BOLA detection, broken object-level authorization, the exact vulnerability class behind a large share of ATO-adjacent API incidents.
Evaluation Consideration: Organizations with rapidly growing API estates should validate discovery accuracy, governance capabilities, and operational simplicity within dynamic cloud-native environments.
5. Salt Security
Salt Security takes an out-of-band approach with no inline filtering node in the traffic path, correlating activity across LLM connections, MCP servers, and API sequences through what it calls its Agentic Security Graph, and scans code repositories pre-deployment through Salt Code to catch risky integrations before they ship.
Evaluation Consideration: Buyers should confirm detection latency and alert workflow given the out-of-band model, particularly for time-sensitive business logic attacks.
6. Wallarm
Wallarm deploys NGINX-based inline filtering nodes combining machine learning with signature matching at the request level, and, unusually for this category, covers the full application portfolio (APIs, web apps, and microservices) from a single platform without requiring a separate WAF or gateway to enforce mitigation.
Evaluation Consideration: Organizations should evaluate governance depth and AI/MCP-specific coverage as part of their evaluation, given the platform’s roots in traditional application security.
7. Traceable AI (Harness)
Traceable AI, acquired by Harness in 2025, uses a distributed tracing approach built on OpenTelemetry to follow API calls throughout the entire application stack rather than inspecting traffic only at network boundaries. This enables runtime discovery of shadow and internal APIs while extending visibility to GenAI-specific risks such as prompt injection attempts, AI-driven data exfiltration, and the monitoring of sensitive data sent to third-party AI services.
Evaluation Consideration: Since Traceable’s core strength runs through tracing infrastructure, organizations should validate integration effort in non-microservices or legacy environments, and confirm how deployment fits their existing DevSecOps tooling now that it sits inside Harness’s broader platform.
Running Prophaze Back Through Its Own Four-Part Test
We set the bar; it’s only fair to hold ourselves to it. Here’s how Prophaze answers the same four questions — with the caveat that you should confirm each in your own proof-of-concept, not take our word for it:
- Discovery - Can it find every API in production, including shadow, zombie, and undocumented endpoints? Yes. Prophaze discovers shadow, zombie, orphaned, and undocumented APIs continuously at runtime not on a scan schedule closing the exact kind of documentation gap that let ServiceNow's exposed endpoint go unnoticed.
- Runtime detection - Business logic and credential misuse, or only signature-matched attacks? Prophaze runs on continuous behavioral learning rather than static rule sets, so it's built to catch authenticated-looking, signature-evading traffic, not just known exploit patterns.
- East-West visibility -Into Kubernetes and cloud East-West traffic? Yes. One policy layer spans external, internal, and East-West traffic, rather than splitting governance across separate tools for what's public-facing and what isn't.
- Governance - Down to the sub-resource level? REST/GraphQL governance is scoped to the sub-resource level, giving teams precise control over exactly what any client, service, or integration can reach rather than broad, all-or-nothing permissions.
On deployment, Prophaze answers a fifth question this guide didn’t ask but every buyer eventually does: how long before this is actually running? It’s agentless and lives in minutes with no code changes, and available self-managed or fully managed depending on how a team wants to operate it.
- Would You Have Caught the Next ServiceNow?
No credentials were stolen. No malware ran. An API just answered a request it should have refused, and every tool watching the perimeter had no reason to stop it. That’s not a rare failure mode anymore. it’s the shape most 2025–26 API incidents actually take.
Before your next audit, board update, or incident review, ask a harder question than “do we have a WAF”: do you know every API running in your environment right now, and could you prove it?
Frequently Asked Questions (FAQ)
1. Why did the ServiceNow breach get past traditional API security tools?
Public reporting indicates the attackers queried an unauthenticated endpoint using traffic that looked legitimate, the kind of gap behavioral, discovery-first monitoring is built to catch that signature-based tools typically miss.
2. Why do US enterprises need runtime API protection now specifically?
API growth over 50% year-over-year at two-thirds of organizations, combined with a record $20.877B in 2025 reported cybercrime losses and a formal “AI-related” fraud category appearing for the first time, means static, perimeter-only defenses are falling behind the pace of both legitimate growth and attacker adaptation.
3. What is runtime API discovery?
Runtime API discovery continuously identifies APIs operating in production, including shadow, zombie, internal, deprecated, and AI/MCP-connected APIs, providing organizations with an accurate, real-time inventory rather than relying on outdated documentation.
4. How is Prophaze different from WAF-extension vendors?
Discovery, behavioral protection, and sub-resource governance are core to the platform rather than modules layered onto an existing firewall or CDN product.