API security uplift for an insurance platform

Clandestine
Cybersecurity
March 26, 2026
9 months
The Challenge
The insurer faced undocumented broker APIs exposing policyholder data, requiring a full inventory and enforceable controls without breaking partner integrations.
Key Issues:
- Undocumented shadow APIs
- Broken object-level authorisation
- No rate limiting on quotes
- Sensitive data in API responses
The Solution
We inventoried every broker API, closed authorisation gaps, and placed a managed gateway in front of all policyholder data endpoints.
Key Actions:
- Full discovery of the shadow API estate
- Object-level authorisation testing on every route
- Managed gateway with adaptive rate limits
- Schema validation in the pipeline
An API you have not documented is an API you cannot defend. Every undiscovered endpoint quietly becomes somebody else's route into your records.

Compliance & Risk Management
Insurers hold policyholder data that carries lasting consequences when exposed. Our API programme documents every endpoint, its owner, and its controls, so GDPR and regulatory reviews draw on a living inventory rather than a diagram that stopped being accurate.
- Insurers hold policyholder data that carries lasting consequences whenever it is exposed.
- API Discovery & Inventory – Continuous mapping of every internal and partner route.
- Authorisation Testing – Object-level checks across all policyholder data endpoints.
- Gateway & Rate Limiting – Adaptive controls protecting quote and claims traffic.
Outcome and Business Impact
73%
API Risk Reduced
430K
Malicious Calls Blocked
100%
Broker Routes Mapped
Read more Case studies
Manage Work Faster with Connected Team Tools.
Automate tasks, centralize projects, and collaborate in real time — all from one sleek
FREE 14-DAY TRIAL · NO CREDIT CARD

