Get a Demo
Under Attack?
Illustration of a cargo dock with stacks of blue and pink shipping containers, some bearing the logo Upwind. The scene includes overhead structures and rows of containers along a dock under bright lighting.

Automatically Discover API Sensitive Data Flows

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>33</b><br />
Joshua Burgin October 22, 2024

Automatically Discover API Sensitive Data Flows

We are excited to announce a significant new addition to Upwind’s API Security capability – the automatic discovery and classification of sensitive data flows.

Upwind automatically tracks sensitive data routes and classifies sensitive data as PCI, PII, and PHI by analyzing API samples recognized by the Upwind sensor, making it easy to identify where you are at elevated risk.

Screenshot-2024-08-30-at-9.50.26%E2%80%AFAM-1024x656

Examples of sensitive data that Upwind identifies include:

  • PHI data: patient information, medical records & insurance information
  • PII data: SSNs, IDs and emails
  • PCI data: credit cards and billing information
Screenshot-2024-08-30-at-9.50.02%E2%80%AFAM-1024x732

How Upwind Identifies Sensitive Data Flows

In order to identify sensitive data flows, Upwind searches for patterns at the packet level and then masks any data found, ensuring it remains secure and is never sent outside of your environment. When an API request for sensitive data  is detected, Upwind labels it with a sensitive data tag and classifies it by its type and category, such as PCI for a MasterCard number. We are continuing to extend this capability, and customers will soon be able to create their own custom regular expression (regex) to classify sensitive data.

Screenshot-2024-09-04-at-6.13.58%E2%80%AFAM-1024x483

Use Upwind’s automated sensitive data flow tracking to easily understand API data security risks, prioritize remediation efforts for APIs with sensitive data flows, and ensure a proactive approach to data security. 

Learn More

To learn more about Upwind API Security, visit the Upwind Documentation Center (login required), or schedule a demo.

401 Authorization Required

401 Authorization Required


nginx
Contents

Further Reading

Superhuman AI

Security AI Needs an Honest Scoreboard: What It’s Superhuman At, and Where It Comes Up Short

If you follow AI at all, you know the leaderboards. Every few weeks a model takes the top spot, and we all check where our favorite landed. But a leaderboard only tells you who's ahead, and it stays quiet about where any of those models still come up short. Which, conveniently, is the part that…
Focus Mode

Find What Matters with Upwind Focus Mode

Focus Mode is now available in the Upwind platform, giving security teams a faster, more focused way to work. Instead of navigating across the platform, you can switch to Focus Mode to slice and dice the Upwind platform by Vulnerability Management, Cloud Security Posture, Attack Surface Management, Administration, or Threats, and starting next week, AI…
Early Advisories

Introducing Early Advisories: Turn Emerging Threats into Action

We’re excited to introduce Early Advisories as part of the Upwind platform. Powered by Upwind's security research team, Early Advisories notify customers about emerging threats, including zero-days and supply chain attacks, before they receive a CVE identifier. Early Advisories are published directly into the Vulnerabilities module alongside CVE-based findings and automatically correlated with your live…