What does that mean exactly?
Do you manually assess what is risky for a particular API, or is it up to the system to choose?
If it's up to it, what happens if it thinks that's not risky to delete user data?
You can also manually configure an allowlist/blocklist of operations for specific use cases.
Since then, we have completely revamped it to create py-multiauth v2 that supports basically all form of authentication as you can see in the docs https://docs.escape.tech/authentication/
py-multiauth v2 is not open source for now, but our eng team might be ok to open source it if there is interest from the community
I’ll test it out with them and see what they think. I will say that we were originally exploring Bright, but we had to rely on telling them what APIs and endpoints to hit, and they wanted to embed an engineer with us to help us onboard their product.
We wanted something simple that we could pay money for, have it discover all of our endpoints, pentest, and return a report.
1) please move pricing onto main site 2) please consider deploying on Azure Marketplace
The fact you’re including GraphQL is a big positive too.
We try to make our product as straightforward as possible. It’s a long journey for such technical topic but it gets better everyday.
And we listen to feedback. I’ll take a look at Azure Marketplace.
Of course, for investors, we would have written things differently, but we are not looking to raise money at the moment.
Hope that makes it more clear!
edit: some of those comments have now disappeared. Make of that what you want.
I guess we can be proud that they are our users and wanted to help. There was no intent to break HN's rules. We apologize for that happening, and we have told them about the rules so it doesn't happen again.
Although, by nature, the security market is mostly enterprise, we do have plans for startups and SMB as well. Happy to have your feedback on our pricing btw, always something hard to get right.
Hope that makes it more clear!