Hope that makes it more clear!
120 karma · joined March 29, 2022
Hope that makes it more clear!
You can also manually configure an allowlist/blocklist of operations for specific use cases.
Since then, we have completely revamped it to create py-multiauth v2 that supports basically all form of authentication as you can see in the docs https://docs.escape.tech/authentication/
py-multiauth v2 is not open source for now, but our eng team might be ok to open source it if there is interest from the community
We try to make our product as straightforward as possible. It’s a long journey for such technical topic but it gets better everyday.
And we listen to feedback. I’ll take a look at Azure Marketplace.
Of course, for investors, we would have written things differently, but we are not looking to raise money at the moment.
Hope that makes it more clear!
I guess we can be proud that they are our users and wanted to help. There was no intent to break HN's rules. We apologize for that happening, and we have told them about the rules so it doesn't happen again.
Although, by nature, the security market is mostly enterprise, we do have plans for startups and SMB as well. Happy to have your feedback on our pricing btw, always something hard to get right.
You are right in the sense that using automated security testing tools in production creates a risk. But there are workarounds:
1) Most of Escape's security scans happen on staging or pre-prod environments, where there is little risk of breaking something critical or finding real customer data.
2) We have designed a specific scan mode for production APIs, that is made with safety in mind. It will not attempt the riskiest attack scenarios and, thus will be safe for production use at the cost of scanning depth.
You can chose a scan mode when adding a new application for testing in Escape. So far, most of our users use both modes, one for the production environment and one for the development environment, to spot bugs early.
No user ever had problems with the production scanning mode.
By the way, the core algorithm powering Escape is more a graph traversal algorithm than LLMs. We do use a small, self-hosted LLM for specific inference tasks, but everything is made in-house, and we don't use OpenAI or any other inference API.
Hope that helps!
Mind you that you can also use your personal GitHub account to register because we noticed people are way less likely to do risky stuff with their Github account than with a personal email :)
Thanks for the great ideas, I share your opinion on those
There are limitations indeed, though if you compare similar APIs with similar business intent, their structure should also have similarity, unlike your example.
For the popularity metrics, I will take a look - I admit we can do better :)
This is kind of a side project for us, but I'll definitely think about it