Honest product surface: security scanning, cost governance, compliance scoring, and GitHub/Slack integrations that are available today — without claiming unshipped certifications or connectors.
Payload library covering common jailbreaks, indirect injection, and system-prompt leakage patterns. Continuously expanded as new attack vectors appear.
BOLA/IDOR heuristics, insecure HTTP methods, missing auth, CORS misconfigurations. Findings mapped to OWASP API Top 10 where applicable.
Detects common cloud and LLM credentials (AWS, GitHub, OpenAI, Anthropic, Stripe, Slack, JWT, private keys) plus India-specific ID patterns.
Static route extraction for popular frameworks from imported collections and source patterns — without requiring production traffic.
Redaction helpers for emails, phone numbers, and common ID formats on supported gateway paths. Coverage depends on deployment configuration.
Track token usage and estimated spend across supported LLM providers when traffic flows through the RaksHex gateway or instrumented paths.
Trend and forecast views for upcoming spend based on recent usage — confidence bands improve with more history.
Flags unusual spend patterns relative to your recent baseline so teams can investigate spikes early.
Circuit breaker that blocks LLM calls when budget or policy thresholds trip. Response time depends on your deployment topology.
Separates reasoning/thinking tokens where providers expose them so cost reports stay accurate for o-series and similar models.
Generate structured evidence exports mapped to common Trust Services themes. Not a SOC 2 certification and not a Vanta/Drata connector.
Maps relevant API-security findings to PCI DSS control language for remediation guidance. Does not claim PCI attestation.
Score views for OWASP API Top 10 and LLM Top 10 based on your scan findings and trend over time.
Export workspace audit events as JSON/CSV for your GRC tooling. Retention policies are plan- and deployment-dependent.
Tools to support GDPR/DPDP-oriented workflows (export/erasure paths). Legal compliance remains the customer’s responsibility.
Scan collections and review findings from the editor when the published extension is installed and authenticated.
Webhook-driven PR scans with findings posted as pull-request comments when the GitHub App is installed.
Programmatic access to collections, scans, and findings via the RaksHex API. Dedicated public SDKs are on the roadmap.
Import OpenAPI, Postman, and Bruno collections to kick off security scans without rewriting your specs.
Lifecycle webhooks (scan, finding, quota, kill-switch) plus Slack when configured. Manage endpoints in Settings → Webhooks.
Configure OIDC or SAML providers in Settings → SSO. Enable after verifying IdP settings; plan entitlements may apply.
Shared workspaces with role-based access for collections, scans, and billing boundaries.
Retention and export controls for scan and audit data based on your workspace settings.
Higher-touch support options for Enterprise agreements (SLA details in your contract).
Docker Compose and container-based self-host paths for teams that need to run RaksHex in their own cloud.