- Go to the KuppingerCole Booking tool webpage using the button below.
- Under Select a Service, select Leadership Compass Briefing 55 mins.
- Under Select Staff, scroll down and select Alexei Balaganski
- Choose date and time between Sept 21, 2026 - Oct 30, 2026 that are convenient for your team.
- You will receive an MS Teams invite
- Please prepare a slide deck and provide it to the analyst.
Recommended briefing outline
1 Company and Product Context (5 minutes)
- Brief company overview and positioning in the API security and governance market
- Product scope and major components relevant to this Leadership Compass
- Primary customer profiles, typical estate size, and deployment scenarios
2. Architecture and Deployment Model
- Supported delivery models, including SaaS, self-managed, hybrid, and containerized
- How traffic and API metadata are ingested: inline enforcement, out-of-band analysis, agent, sidecar, gateway plugin, log ingestion, or code repository scanning
- Latency, availability, and failure characteristics, including behavior when the control plane is unreachable
- Integration with existing API gateways, service meshes, ingress controllers, and CI/CD pipelines
- Separation of policy definition from policy enforcement, and how consistency is maintained across heterogeneous enforcement points
- Approach to legacy, on-premises, and non-cloud-native APIs
- Jurisdictional control over the location of the control plane, policy data, and telemetry
3. Core Capabilities
Please structure this section explicitly around the evaluation categories below. The first three are required for a rated evaluation; the remaining five are differentiating. We do not expect every solution to cover all categories, so please concentrate on those you genuinely support. You do not need to cover every feature exhaustively, but clarity and technical depth are essential. Where a capability is delivered through a partner or an adjacent product, please say so explicitly.
- Discovery, Inventory, and Classification: Discovery method and coverage across environments; identification of shadow, zombie, third-party, and agent-created APIs; coverage of MCP servers and agent tool endpoints; enrichment with ownership, protocol, authentication method, and data sensitivity; protocol breadth beyond REST
- Runtime Enforcement and Consumption Control: Schema and specification validation; method and endpoint allowlisting; treatment of undocumented and deprecated endpoints; response-side controls; rate limiting and per-consumer request and token quotas; how enforcement is applied when analysis is out of band
- Analytics, Observability, and Audit Evidence: Traffic and usage visibility attributed to individual consumers; distributed trace propagation; logging, retention, and immutability; automated evidence generation for regulatory frameworks; export to SIEM, SOAR, and XDR
- Contract Governance and Pre-Production Validation: Linting and ruleset conformance; test generation derived from the contract; detection of specification-to-implementation drift and breaking changes; pipeline enforcement gates; assessment of design attributes such as naming, idempotency, documented side effects, and machine-readable errors
- Business Logic and Behavioral Abuse Detection: Detection of BOLA, BFLA, object identifier manipulation, mass assignment, and excessive data exposure; behavioral baselining across call sequences and aggregation patterns; how baselines are established and how false positives are managed
- Exposure Governance: Mediation, transformation, and per-audience interface shaping as controls; secure-by-default publication; curation of agent-facing tool sets on least-privilege principles; generation of MCP servers from the contract
- Agentic and Non-Human Consumer Enforcement: Policy coverage of MCP servers and agent tool endpoints; validation of identity context presented by non-human callers, including delegated and on-behalf-of assertions; re-evaluation of authorization during long-running or chained interactions; step-up and human-approval gates for high-risk operations
- Federated Policy Governance and Enforcement Architecture: Policy expressed as code with version control and drift detection; automated policy generation and application at scale; enforcement across multiple gateways and meshes; interoperability with external decision points through open standards
4. Demonstration (Mandatory, 20 minutes)
- Discovery results against a realistic estate, including how an undocumented or previously unknown API surfaces
- Posture findings, risk prioritization, and the path from finding to remediation
- Enforcement of a declared contract, including rejection of a request to an undocumented, deprecated, or malformed endpoint
- Detection of an authorization or business logic abuse scenario, ideally one that produces no malicious payload
- Policy definition and distribution across more than one enforcement point
- An agentic or non-human consumer scenario, where supported
- Investigation and audit workflows, including the evidence a compliance reviewer would receive
The demo should reinforce the claims made earlier, not introduce entirely new concepts. There is no need to spend time on trivial operations; please focus on major differentiating capabilities and innovative workflows. Please use a demo environment with realistic data in sufficient quantities. An inventory containing a dozen sample APIs does not demonstrate discovery at enterprise scale, and a detection demonstrated against synthetic attack traffic tells us little about behavior in production.
5. Differentiation and Roadmap (5 minutes)
- Clear articulation of what differentiates your platform from peers
- Near-term roadmap priorities relevant to API security and governance
- Known limitations or trade-offs (openness is appreciated and expected)
6. Wrap-Up and Q&A (5 minutes)
- Reference customers, deployments, or representative use cases
- Time for clarification questions and discussion