What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
- Integration list: partially confirmed, verify against vendor docs
- Exact scope of the API discovery capability and which sources it inventories from: verify
- Depth of REST coverage relative to GraphQL coverage: confirm with vendor
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Escape works from an API's structure rather than from crawling a user interface. Given a GraphQL schema or an OpenAPI description it builds a model of types, operations, parameters and the relationships between them, then generates request sequences from that model. Because it understands which fields feed which operations, it can chain calls: create an object with one call, then attempt to read or mutate it as a different user with another. That is the mechanism behind its authorization testing, and it is what separates it from scanners that fire independent payloads at independent endpoints.
On top of the traversal it runs the expected injection and misconfiguration checks, plus GraphQL specific issues that generic scanners do not model at all: introspection exposure, query depth and complexity limits, alias and batching abuse, field level authorization gaps. It also offers discovery, inventorying APIs from code repositories and other sources so that the testing scope includes endpoints nobody documented. Scans run headlessly so they can be triggered from a pipeline.
Where it fits
This runs in CI or on a schedule against a staging environment, and it is usually configured by whoever owns the API, with results reviewed by security. It needs a schema or specification and, critically, credentials for at least two accounts with different privilege levels if you want the authorization testing to be meaningful. Teams with a generated schema and a clean staging environment get value quickly; teams whose API documentation has drifted from reality will spend time on setup first.
Strengths
- Schema driven traversal reaches multi step, stateful behavior that request by request scanners cannot exercise.
- Genuine authorization testing across user roles, which is one of the highest value and most commonly missed vulnerability classes.
- GraphQL specific checks are deeper than what general purpose DAST tools offer.
- API discovery reduces the risk that testing scope is limited to the endpoints someone remembered to list.
Limitations
- Coverage depends on an accurate schema. A stale or incomplete specification produces a scan that looks clean because it never reached the risky endpoints.
- Multi role testing needs credential provisioning and maintenance, which is ongoing operational work.
- Focused on APIs, so it is not the tool for testing a traditional server rendered web application.
- Younger vendor with a smaller integration and support footprint than the established DAST suites.
Who it suits
A strong fit for teams running GraphQL or API first architectures who are worried about broken object level authorization and business logic abuse rather than classic injection. Less relevant for organizations whose estate is mostly conventional web applications, and not the right purchase if you have no maintained API specifications and no appetite to create them.
Used Escape? Recommend it under your own name and title.
Recommend this tool