How it works

Three steps to live protection.

1. Run one container

Pull the iris agent and start it with a single command. No SDK, no code changes, no application restart.

2. It learns your normal

The agent discovers your active endpoints, and Cyron starts building a behavioural baseline within hours.

3. Threats get caught

Attacks are scored as they arrive and the source is blocked at the kernel. Borderline events get a reasoned verdict from the AI analyst.

What it catches

Attacks that pass a firewall but should not pass you.

Cyron API Security reads payload intent and behaviour, so it sees abuse that signature matching never will.

Business logic fraud

Checkout enumeration, coupon abuse and inventory manipulation, caught by how the API is used, not just what is sent.

Account takeover

Credential stuffing and account enumeration spotted from behavioural patterns across sessions.

Data exfiltration

Object-level authorisation breaches, abnormal data pulls and secrets or regulated data leaking through API responses, flagged before they become a breach you report.

Attacks inside streams

31 real-time detectors for WebSocket, gRPC, Server-Sent Events and Socket.IO, where many tools stop reading at the handshake.

An honest API inventory

Automatic discovery keeps a list of every active endpoint, including the ones nobody documented.

Forensics on demand

System 2 Thinking, Cyron's AI analyst, investigates ambiguous events and writes an explanation a human can act on.

Standards coverage

OWASP API Security Top 10

Cyron API Security has dedicated detection logic for all ten categories.

Risk areaOWASP categoriesCovered
Data theft and exfiltrationAPI1, API3Yes
Account takeoverAPI2, API5Yes
Business logic fraudAPI6Yes
Infrastructure disruption and server-side request forgeryAPI4, API7Yes
Misconfiguration, forgotten endpoints and injectionAPI8, API9, API10Yes
Architecture

It never sits in your way.

Live API traffic is never routed through Cyron. The agent captures a kernel-level copy with eBPF and analyses it out of band, so a problem in the analyser can never slow or break your production path.

  • Zero added latency to the live request path
  • Secrets are removed before the AI analyst sees an event
  • SaaS hosted in Germany, or the whole platform on your own servers
  • Signed, OCSF-aligned events for any SIEM that accepts a webhook

Works with your WAF, not instead of it

A web application firewall blocks known patterns inline at the edge. Cyron API Security reads intent and behaviour out of band and catches the business logic abuse a WAF cannot see. Run both for defence in depth.

GDPR NIS2 DORA PCI DSS 4.0 HIPAA
Pricing

Start free. Grow when you need to.

Annual billing saves two months. Try behavioural intelligence and the AI analyst free for 14 days, or start on the free plan with no card.

Free
$0
Free forever
  • Threat detection on REST, WebSocket, gRPC and streaming protocols
  • 7 threat intelligence feeds
  • Sensitive data scanning
Lite
$15 /mo
$12/mo billed annually
  • Everything in Free
  • Kernel-level blocking
  • SIEM webhooks, endpoint discovery
Standard
$65 /mo
$55/mo billed annually
  • Everything in Essential
  • System 2 Thinking
  • Forensic reports, protocol analysis
Premium
$165 /mo
$138/mo billed annually
  • Everything in Standard
  • Higher throughput
  • Priority email support
View full pricing and start a trial

Need on-premise or higher volumes? Talk to us.

FAQ

Questions teams ask first.

No. The iris agent taps traffic at the Linux kernel with eBPF and analyses a mirrored copy out of band. Your live request path is never proxied, so it stays exactly as fast as before.
No. There is no SDK, no library to import and no application restart. You run a single Docker container and it discovers your active endpoints automatically.
REST and HTTP, WebSocket, gRPC with Protobuf analysis, Server-Sent Events and Socket.IO. It also recognises MCP and A2A traffic from AI agents.
No, it complements one. A WAF blocks known patterns inline at the network edge. Cyron API Security analyses payload intent and behaviour out of band, catching business logic abuse a WAF cannot see. Most teams run both.
The SaaS platform is hosted in Germany. Cyron keeps the traffic it analyses so incidents can be investigated, and removes secrets before the AI analyst sees an event. With Cyron On-Premise, traffic and findings stay on your own servers.
There is a free plan with no credit card required. Paid plans start at 15 USD per month for Lite, and you can try behavioural intelligence and the AI analyst free for 14 days.
They are three products on one loop and each deploys independently. Cyron API Security sees what reaches your APIs. Cyron AI Security inspects what your AI agents send to tools and to other agents. Cyron AI Compliance, in development, will turn findings into attested filings. On-premise, the first two install together.

Where Cyron API Security sits in the loop

Cyron API Security is the see layer. Cyron AI Security inspects what your AI agents send to tools and to other agents, and Cyron AI Compliance, in development, will turn that record into regulator-ready evidence. Each stands on its own. Full technical detail: cyron.io/platform/

See all three products

See your first findings today.

Start on the free plan, or talk to us about running it on your own servers.