Middleware SecurityAvailable
Security for the layer between your services.
Vectasec is a middleware security product that audits API gateways, message brokers, and service meshes for the platform teams who own them.
- Coverage
- Gateways · brokers · meshes
- Deployment
- On-prem or VPC
- Detection
- Deterministic rules
The problem
Everything routes through middleware. Almost nothing audits it.
Gateways, brokers, and meshes carry every request and appear in almost no threat model. Configuration drifts between environments, authentication gets bypassed for 'internal' traffic, and topics accumulate consumers nobody remembers. Vectasec makes that layer visible.
Coverage
Three surfaces, one consistent model.
API gateways
Routes without authentication, permissive CORS, missing rate limits, shadow endpoints that bypass the gateway entirely.
Message brokers
Anonymous producers and consumers, unencrypted channels, wildcard ACLs, dead-letter queues holding sensitive payloads.
Service meshes
mTLS gaps, over-broad authorization policies, and drift between what the mesh enforces and what your policy repo says it should.
Operation
Reads configuration. Touches nothing.
Vectasec follows the same trust model as every ZHASK product: read-only credentials, deployment inside your boundary, findings backed by the configuration snapshots that produced them. It diffs environments against each other and against your declared policy, so staging-to-production drift surfaces before an incident does.