Secure AI code before it ships. Save your seat

Secure APIs across your AWS environment

Salt and AWS deliver full lifecycle API security with zero friction. Get deep visibility into every API, continuously monitor posture, and stop runtime threats. All without slowing innovation or adding complexity.

Why Salt + AWS?

APIs are the lifeblood of cloud-native applications, and AWS is the cloud of choice for most enterprises. Salt Security natively integrates with AWS to provide seamless, scalable protection across your environment:

Introducing Salt Cloud Connect

Salt Cloud Connect simplifies onboarding and enables rapid time to value. It connects directly to your AWS environments to:

Map and classify APIs by account, service, and region
Monitor sensitive data in motion
Eliminate blind spots from shadow, rogue, or deprecated APIs
Enable policy enforcement and threat detection — without deploying inline proxies
“We connected Salt via Cloud Connect and had full visibility into our APIs in under an hour — no changes to code or traffic flow.”
—Enterprise Financial Services Customer

How it works

Salt deploys using traffic mirroring, flow logs, and direct API integrations — no agents or inline components required:

Key benefits

Zero friction deployment:
Fully agentless, no code changes, deploy in minutes
Cloud-native coverage:
Full AWS service visibility, not limited to API Gateway
Unified insights:
Send enriched findings to AWS Security Hub and SIEMs
Proactive protection:
Block logic-based attacks WAFs miss — like broken auth and privilege abuse

Salt and AWS together give security teams the context, coverage, and control they need to secure modern cloud environments, without slowing down development.

AWS WAF Integration

APIs now power nearly every digital experience, and AI agents are rapidly becoming the fastest-growing source of API traffic. Traditional WAF rules were never designed to understand the behavioral nuances of APIs or the dynamic nature of AI-powered agents, leaving security teams with blind spots that existing tools do not cover.

The Salt Managed Rules deliver:

  • Advanced API threat detection, blocking common and complex attack vectors including credential brute force, excessive GraphQL queries, SSRF, prototype pollution, and JWT-based anomalies.
  • Industry-first Model Context Protocol (MCP) awareness, identifying and labeling traffic from MCP endpoints, blocking unauthenticated MCP access, and providing deeper observability into MCP interactions in AWS WAF environments.
  • Context-aware rate limiting, with smart limits on sensitive parameters such as user IDs and email addresses to stop enumeration and abuse patterns.
  • Security signal enrichment, labeling critical request attributes (auth headers, user identifiers, GraphQL queries) to boost detection fidelity and downstream analytics.

Ready to see us in action?

Schedule a demo today to see ways to protect yourself from the API threat vector.