Security
Zero trust, enforced at the edge
Authentication and authorization are not features bolted onto your services — they are a layer every request must cross before your code ever runs. APIFlow validates identity, intent and payload at 31 edge locations, in under a millisecond.
Authentication
Four authentication layers, one enforcement point
Mix mechanisms per route: OIDC for user traffic, client credentials for services, HMAC for partners, mTLS for your most sensitive links. All of them terminate at the gateway — your services receive verified claims, not raw credentials.
OAuth 2.0 & OpenID Connect
Full authorization-code, client-credentials and device flows, with any OIDC provider — or our built-in identity broker.
JWT Validation
Signature, issuer, audience, expiry and custom-claim checks at the edge. Keys rotated via JWKS without downtime.
API Keys & HMAC Signing
Scoped, rotatable keys with HMAC request signing for machine-to-machine traffic that cannot hold a token.
Mutual TLS
Certificate-pinned client authentication for partner and internal traffic, with managed CA and automated rotation.
Enforcement
What happens to every request
-
01
TLS terminate
TLS 1.3 only, HSTS pinned
-
02
DDoS / WAF
Anycast absorption + API-tuned rules
-
03
Authenticate
JWT, key, HMAC or mTLS
-
04
Authorize
RBAC / ABAC policy decision
-
05
Forward
Claims + injected secret to upstream
Total enforcement overhead: < 1 ms p99 · Failed requests never reach your infrastructure
Controls
Built for your security review
Security teams get artefacts, not assurances: audit trails, penetration-test summaries, sub-processor lists and a trust centre that answers the questionnaire before you send it.
Zero-Trust Enforcement
No request reaches an upstream without passing authentication, authorization and schema validation at the edge.
RBAC / ABAC Policies
Role-based and attribute-based access decisions expressed as declarative policy, evaluated in under a millisecond.
Token Vault
Upstream secrets never touch your services — the gateway injects them at the last hop and stores them encrypted (AES-256, envelope keys).
DDoS Shield & WAF
Anycast absorption, L3–L7 filtering and managed WAF rulesets tuned for API traffic patterns.
Audit Log Store
Immutable, append-only audit trail of every auth decision, policy change and key operation — exportable to your SIEM.
Compliance Posture
SOC 2 Type II, ISO 27001, GDPR-ready data processing with UK and EU residency and a published sub-processor list.
Bring your security team to the conversation
Request the trust pack, architecture review or a guided threat-model session with our engineering team.