Radware has launched a new API Security Service designed to provide continuous protection across the entire API lifecycle, combining discovery, posture management and real-time runtime defence in a single platform.
The new service aims to address one of the fastest-growing attack surfaces in modern enterprise environments, as APIs increasingly underpin cloud applications, digital services and third-party integrations.
According to Radware, many existing API security tools rely heavily on static analysis or generate large volumes of theoretical alerts, leaving security teams struggling to identify genuine risk. Shadow APIs, unmanaged third-party connections and limited runtime visibility further complicate detection and response, particularly when it comes to sophisticated business logic attacks.
Radware’s API Security Service is designed to close these gaps by analysing live production traffic to identify real-world threats as they occur. The platform delivers continuous API discovery, runtime posture management and automated protection against the OWASP Top 10 API Security Risks, including Layer 7 HTTPS DDoS attacks.
“APIs are dynamic, business-critical, and increasingly targeted—but most security approaches are still static,” said Haim Zelikovsky, vice president of cloud security business at Radware. “Our API Security Service continuously analyses real traffic to identify real risk, automatically block real attacks, and help organisations reduce noise, shorten MTTR, and meet regulatory requirements with confidence.”
Key capabilities include real-time posture management based on attacker intent, automated mapping of API workflows to detect business logic abuse, and adaptive behaviour-based protection designed to prevent disruption to legitimate traffic—even during large-scale DDoS events.
The service also provides continuous visibility into API inventories, schemas and usage patterns, including shadow and third-party APIs. A unified portal is intended to support collaboration across Dev, Sec and DevSecOps teams while simplifying compliance reporting and reducing operational complexity.
Radware said the platform uses AI-driven detection to minimise false positives, enabling security operations teams to focus on active threats rather than theoretical vulnerabilities.
The API Security Service is generally available now as both a standalone solution and as part of Radware’s broader application security and delivery portfolio.
As API adoption continues to accelerate, vendors are racing to provide more practical, runtime-driven security controls—particularly as attackers increasingly exploit business logic flaws and automated abuse rather than traditional vulnerabilities.








