
Rocket.Chat
The Secure CommsOS™ for mission-critical operations

The Secure CommsOS™ for mission-critical operations

Checklist of the most important security countermeasures when designing, testing, and releasing your API

The easiest, and most secure way to access and protect all of your infrastructure.

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Your gateway to OWASP. Discover, engage, and help shape the future!

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

Exploit for CVE-2022-22947: remote code execution in Spring Cloud Gateway via crafted requests to the Actuator endpoint. Includes Python script and…

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

layerleak the Docker Hub Secret Scanner

Reverse engineering of the oBike protocol communication (BLE and HTTP)

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…