Best Practices

14 posts

How to maintain security compliance at a Fintech: A complete guide
Compliance

How to maintain security compliance at a Fintech: A complete guide

If you're responsible for security at a financial services or fintech company, here is your comprehensive overview of what you need to do to be compliant.
Sanjana Iyer
Sanjana Iyer
12 min read
An Analysis of Kuppinger Cole’s Selection Criteria for API Management and Security
Best Practices

An Analysis of Kuppinger Cole’s Selection Criteria for API Management and Security

Discover how Escape fits the Kuppinger Cole selection criteria of API Management and Security Solutions.
Mia Berthier
Mia Berthier
10 min read
How to build secure APIs with Ruby on Rails: Security guide
API Security

How to build secure APIs with Ruby on Rails: Security guide

Are your Ruby on Rails APIs as secure as they could be? In today's world, where digital security is no longer an option, ensuring the robustness of your APIs is crucial. If you find yourself uncertain when attempting to answer this question, then this guide is for you.
Alexandre Tang
Alexandre Tang
13 min read
10 best practices to secure your Spring Boot applications
API Security

10 best practices to secure your Spring Boot applications

Explore the top 10 Spring Boot security best practices from the Escape team to secure your Java web applications efficiently.
Tristan Kalos
Tristan Kalos
6 min read
ASP.NET security best practices
API Security

ASP.NET security best practices

Curious about the key strategies to ensure the security and reliability of your ASP.NET applications, including building APIs? Dive into our latest blog post, where we guide you through ASP.NET security best practices. Explore how these practices can not only enhance the security of your web applications but
Tristan Kalos
Tristan Kalos
7 min read
CSRF vs XSS: What is the difference?
Best Practices

CSRF vs XSS: What is the difference?

Web safety matters. XSS is like sneaky bad notes, while CSRF tricks sites as if it's you. Both misuse website trust. We'll explore how they work and how to protect sites, including using CSRF tokens. Learn about online security with us!
Swan Beaujard
Swan Beaujard
8 min read
What are Insecure Direct Object References (IDOR) in GraphQL, and how to fix them
GraphQL

What are Insecure Direct Object References (IDOR) in GraphQL, and how to fix them

As developers, ensuring the security of our applications is crucial. Insecure Direct Object References (IDOR) are common security vulnerabilities that occur when a system's internal implementation is exposed to users, allowing them to manipulate references to access unauthorized data. GraphQL, a powerful data query and manipulation language for
Tristan Kalos
Tristan Kalos
8 min read
Demystifying GraphQL Security: A Comprehensive Guide to GraphQL Introspection
GraphQL Vulnerability

Demystifying GraphQL Security: A Comprehensive Guide to GraphQL Introspection

Whether or not to disable introspection in GraphQL has been a common debate among GraphQL developers since its inception. In this blog post, we will explain why completely disabling GraphQL introspection is not necessary and why it can be counterproductive. I can't really find any good reasons for
Antoine Carossio
Antoine Carossio
5 min read
The State of Public APIs 2023
Research

The State of Public APIs 2023

tl;dr we scanned 6056+ public APIs on the internet with our in-house feedback driven exploration tech and ranked them using security, performance, reliability, and design criteria. We decided to analyze the resulting data and produce a full featured report: The State of Public APIs 2023 Why build this report?
Escape - Offensive Security
Escape - Offensive Security
2 min read
GraphQL errors: the Good, the Bad and the Ugly
Best Practices

GraphQL errors: the Good, the Bad and the Ugly

Managing GraphQL errors can be quite a challenging task, and we tried a lot of different approaches over time. Keep reading to know what we've learned along the way.
Gautier Ben Aïm
Gautier Ben Aïm
7 min read
GraphQL Error Handling Best Practices for Security
Best Practices

GraphQL Error Handling Best Practices for Security

Error messages in GraphQL are rarely seen as a security concern, yet they should. The risk? Leaking information and data! Learn more about GraphQL errors and how to handle them.
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
5 min read
GraphQL Security: 9 Best Practices You Need to Know
AppSec

GraphQL Security: 9 Best Practices You Need to Know

GraphQL has no security by default. All doors are open for the most basic attacks. Read more to learn about the exact threats and some simple strategies you can implement to get your users' data under lock and key 🔐
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
8 min read
Top 7 DevSecOps Best Practices
DevSecOps

Top 7 DevSecOps Best Practices

DevSecOps aims at integrating security inside the development process. It can be hard to know where to start. In this article, learn the best practices to implement DevSecOps in your engineering teams.
Tristan Kalos
Tristan Kalos
5 min read
Guide to handling relational databases with Prisma, NestJS and GraphQL
Tutorial

Guide to handling relational databases with Prisma, NestJS and GraphQL

This articles presents a basic GraphQL application illustrating our methods and guidelines for producing backend code.
Maxence Lecanu
Maxence Lecanu
5 min read