1. Home
  2. Products
  3. X-Security

Free Tools · Open source

X-Security

One API security policy, compiled to every WAF and gateway.

gateway and WAF targets from one spec
7
policy categories per route
17+
OWASP API Top 10 mapped, coverage per class
API1–10
open source, deterministic, no API keys
Apache-2.0

Overview

X-Security is a universal schema for writing API security policy as code. You declare security once per route, as an extension of the OpenAPI spec you already have, and a deterministic compiler turns it into enforceable rules for the WAFs and API gateways you run: Cloudflare, AWS API Gateway and WAFv2, Kong, Coraza and ModSecurity, BunkerWeb, Check Point Open AppSec and Envoy. Layer them for defence in depth, switch gateways without rewriting a line of policy, and fail CI when policy and API drift apart. Battle-tested and fully open source under Apache-2.0.

How it works

From setup to enforcement

  1. Step 01

    Write one policy per route

    Add an x-security block to each route in your OpenAPI file, by hand or with the visual policy builder. Start from a profile such as auth-endpoint, standard-crud, file-upload, webhook-receiver or admin-panel.

  2. Step 02

    Compile deterministically

    xsecurity generate --target <gateway> produces the native artifact for each gateway, with no LLM and no API keys in the compiler.

  3. Step 03

    Verify before it ships

    Every generated rule cites the file and line it came from and is byte-verified against your code. Anything unproven goes to review and is never enforced.

  4. Step 04

    Deploy safely, gate drift

    Rules land in log or shadow mode where the gateway supports it, promote one at a time, and roll back automatically within 60 seconds on a regression. A CI drift gate fails the build when policy and API diverge.

Features

Key features

01

Universal schema

Authentication, authorisation (RBAC, ownership rules, ABAC), rate limits, body caps, property allow-lists, response redaction, CORS, mTLS and more, in one portable format.

02

Compile to many targets

The same spec compiles to Cloudflare, AWS API Gateway and WAFv2, Kong, Coraza and ModSecurity (including an NGINX preset), BunkerWeb, Open AppSec and Envoy.

03

Defence in depth

Layer gateway, WAF and a host-firewall egress adjunct for SSRF, all from the same policy, for a multi-layered enforceable defence.

04

OWASP API Top 10 coverage

Full perimeter coverage for broken object-level authorisation (API1), broken function-level authorisation (API5) and SSRF (API7), with every partial gap named instead of rounded up.

05

Injection and prompt-injection guards

SQL, NoSQL, OS command, XPath, LDAP, code eval, XSS and deserialisation guards, plus an AI prompt-injection guard for LLM endpoints.

06

Byte-verified citations

Every rule points to the exact file and line it protects, and is checked against your code before compiling.

07

Shadow mode and auto-rollback

Log before block, promote per rule, and roll back automatically if error rate or latency regresses after a promote.

08

Signed audit chain

Append-only, hash-chained and signed with your organisation key, exportable as evidence for SOC 2 and customer audits.

09

Honest about limits

Logic flaws, races and valid-input DoS need code fixes; the coverage report flags them instead of pretending a WAF rule patches them.

Who it's for

Built for how teams actually work

Teams running more than one gateway

Keep one source of truth for API security across Cloudflare, AWS and self-hosted gateways, instead of hand-writing each vendor's config.

Switching or adding gateways

Move from one WAF to another, or add a second layer, without rewriting policy.

Closing the OWASP API Top 10 at the edge

Enforce object- and function-level authorisation, SSRF allow-lists and injection guards at the perimeter while code fixes land.

Security as code review

Policy lives in git, diffs like code, is reviewed in pull requests, and fails CI when it drifts from the API.

Technical details

Works with your stack

Targets
Cloudflare (GA, hosted), AWS API Gateway and WAFv2 (beta, hosted), Kong (beta), Coraza and ModSecurity with NGINX preset (beta), BunkerWeb (beta), Check Point Open AppSec (beta), Envoy (alpha), iptables egress for SSRF
Format
x-security extension to OpenAPI, validated by JSON Schema
Profiles
auth-endpoint, standard-crud, file-upload, webhook-receiver, public-read-only, admin-panel, server-rendered-page, graphql-resolver and more
CLI
npm i -g @chain305/x-security, then xsecurity generate, test and verify
Editors
Plugins for Claude Code, Cursor and Codex
Deployment safety
Log-first by default, per-rule promote, 60-second auto-rollback window (30 to 600 s)
Licence
Apache-2.0, 100% open source

Pricing

Plans

Free and open source under Apache-2.0.

Open source

Free Apache-2.0

The schema, CLI and every compile target.

  • Universal x-security schema
  • Deterministic compiler for all targets
  • Test, verify and CI drift gate
  • Editor plugins

FAQ

Questions teams ask

Does it replace fixing the code?

No. A perimeter layer narrows your attack surface. Logic flaws, race conditions and expensive-but-valid requests need code fixes, and the coverage report names them.

Does the compiler use an LLM?

No. Compilation is deterministic and needs no API keys. Every rule is byte-verified against your code before it is emitted.

What if a rule blocks real traffic?

Rules start in log or shadow mode where the gateway supports it, are promoted one at a time, and roll back automatically if errors or latency regress after a promote.

Products

More from Cyphlon

See all products →

Book a call

Book a 30-minute call

Pick a time that suits you. We'll talk through what you're building and where your security stands, then suggest where to start.

Logo

Cyphlon

1:1 Consultation Call

30 min Google Meet

An introductory call with our engineers about any engagement: a pentest, continuous testing, managed AppSec, security engineering, agentic AI security or a fractional CISO. We'll ask about your stack, your deadlines and what your customers or auditors expect, and tell you plainly if we're not the right fit.

Logo Cyphlon

Research and tool releases by email

Unsubscribe any time. Privacy Policy

About Us

Cyphlon is a security engineering company. We implement DevSecOps, application security, Zero Trust and supply-chain security, build the products we deploy, and publish our research.

[email protected]

© 2026 Cyphlon LLC · Dubai, United Arab Emirates · Founded 2016

Privacy Policy Terms of Use