API surface evidence

API Security Review

LumicSec can collect safe public API and documentation signals as evidence inside an authorized website review. Discovery is evidence, not proof that every API exists or that an undiscovered API does not exist.

OpenAPI / Swagger document discovery

Stored as bounded review evidence and interpreted with evidence-confidence rules.

GraphQL and API surface signals

Stored as bounded review evidence and interpreted with evidence-confidence rules.

Public endpoint inventory

Stored as bounded review evidence and interpreted with evidence-confidence rules.

Sensitive path indicators

Stored as bounded review evidence and interpreted with evidence-confidence rules.

HTTP method classification

Stored as bounded review evidence and interpreted with evidence-confidence rules.

Authentication-requirement signals

Stored as bounded review evidence and interpreted with evidence-confidence rules.

Public API documentation exposure

Stored as bounded review evidence and interpreted with evidence-confidence rules.

API CORS observations

Stored as bounded review evidence and interpreted with evidence-confidence rules.