Skip to content

Security overview

What API-dex is

API-dex is the developer portal that sits above Apigee, Gravitee and Azure API Management: one catalog, one access model and one set of credentials across every gateway an organisation runs. It connects to the gateways and presents what they expose. API traffic never passes through API-dex, so the product is never in the request path of your APIs. See What is API-dex for the product picture.

Assurance level

  • Self-assessed against OWASP ASVS 4.0.3, Level 1 for release 3.1.0, assessed 2026-08-04. Level 2 and Level 3 are not claimed.
  • Assessment method: code and configuration review, dependency advisory review, identity-provider configuration review and feature-level security review.
  • Detailed results are shared under NDA. See Available under NDA.

Standing security controls

Every API-dex release passes through the same controls:

ControlWhat it gives you
Static application security testing (SAST)Source code is scanned for security defects on every change
Software composition analysis (SCA)Third-party dependencies are checked against published vulnerability advisories
Software Bill of Materials (SBOM)A component inventory in CycloneDX format is produced per release and shared under NDA
Identity and accessSign-in, sessions and roles are handled by Keycloak, federated to your identity provider

Deployment and data handling

  • Deployment model: on-premise or hybrid, on your infrastructure, per client contract. API-dex is not offered as a hosted service, and your data does not leave your environment.
  • Identity and sessions: Keycloak, federated to your identity provider, with a documented hardening baseline applied per environment. Access follows the accounts and groups you already manage.
  • Logging: sensitive values are redacted from application logs.
  • Accessibility: core components meet WCAG 2.2 Level A as of release 3.1.0. See the Accessibility statement.

Public-sector and financial-services reviews

Frameworks such as Saudi Arabia's NCA Essential Cybersecurity Controls require documented third-party due diligence and evidence that controls still hold, not a report from a past audit. API-dex's per-release controls above are built for that expectation. For a framework-specific review, request the detailed assessment results under NDA and tell us which framework you are mapping to.

Contact

For a specific security questionnaire, an NDA to receive the detailed results, or a framework-specific review, use Talk to us in the top bar or contact your AppyThings account representative.