Salt Security API Protection Platform logo

    Salt Security API Protection Platform

    Salt Security protects the APIs that power your business including the APIs behind AI agents, mobile apps, SaaS platforms, and microservices. Our platform delivers deep visibility, threat detection, and runtime protection to stop API attacks and secure your entire API ecosystem leveraging the AWS infrastructure.

    Ratings and reviews

    4.7
    15 ratings
    3 star
    2 star
    1 star
    73%
    27%
    0%
    0%
    0%
    0 AWS reviews
    |
    15 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (15)
    Tbaker Baker

    Behavioral AI has protected critical applications and now blocks complex external attacks

    Reviewed on Jun 22, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Salt Security is that one of my clients uses it as a security vendor for their security across all of their overlying applications.

    I can give you a specific example of how my client uses Salt Security to secure their applications. They use it to track behavior and leverage the AI to track behavior and block any attacks that could be coming in from outside the company, such as phishing or cybersecurity data breach attacks.

    My client generally conducts a quarterly review where they receive any outstanding threats from Salt Security or review them, ensuring that any data is properly assessed and analyzed, and if there are any logic flaws, they are able to work through them at that time.

    What is most valuable?

    The best features Salt Security offers are definitely their behavioral AI to track API behavior as well as their vendor support.

    One of my clients had a complex attack come through that Salt Security was able to identify and stop before it came through. They have also had questions about the application, and they were able to reach out and get proper support for implementing a change that they were looking for.

    Their behavioral AI and vendor support are two of the key strengths of the application.

    Salt Security has positively impacted my organization and my client's organization by being able to stop cyberattacks and ensure that they have proper security over all their applications. It gives them a sense of peace of mind that they have security over something that could ultimately take down the whole company if not mitigated properly.

    What needs improvement?

    I think Salt Security could improve their implementations. The one that I saw was very complex and took quite a bit of time, and if the environment is unique at all, it takes quite a bit of time to figure out how to properly ensure that it will be implemented.

    A lot of times there is a steep learning curve for someone that hasn't been in it to figure out the APIs and really dig deep into it, but once you get used to it, it is easy. However, that ramp-up period could be tough.

    I think Salt Security could use a more enterprise focus. Some of the smaller companies that I have referred them to think it is a little bit too complex for them, so if they could come up with a different version or something a little bit easier to simplify their platform, they may be able to find more customers that way.

    For how long have I used the solution?

    I have been using Salt Security for three years.

    What do I think about the stability of the solution?

    Salt Security is stable.

    What do I think about the scalability of the solution?

    Regarding scalability, for users in smaller environments, it is not exactly the best. As companies continue to grow, it is something that could be simplified, but it is not the most out-of-the-box, intuitive platform.

    How are customer service and support?

    The customer support for Salt Security is phenomenal and has some of the best vendor support I have ever seen.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution. The security was done in-house, and it was taking too long, and attacks were not being properly mitigated or stopped.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing is that I think it was affordable. For smaller companies, it might be a barrier to entry, but for the large enterprise that I was working with, it was not a problem.

    What was our ROI?

    I have seen a return on investment of 240 man-hours saved by the fact that they were able to stop and mitigate attacks.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that I think it was affordable. For smaller companies, it might be a barrier to entry, but for the large enterprise that I was working with, it was not a problem.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Salt Security. This was the first RFP we put out, and we were fine with it.

    What other advice do I have?

    I rate Salt Security an eight out of ten.

    I give it an eight because the implementation complexity kept it from being a nine or ten.

    My advice for others looking into using Salt Security is that if you are a larger company that needs quite a bit of security, it is a great option. However, if you are a smaller company or in a smaller environment, there may be other options for you.

    Salt Security's AI capabilities regarding governance and security are very strong and help companies get peace of mind that they have the proper governance and security in place to stop any attacks that could possibly happen.

    Salt Security's AI capabilities regarding accuracy and reliability of output are very accurate and very reliable, as I have seen use cases where it has actually stopped attacks.

    Tacio Veiga

    Improved API visibility has revealed sensitive data exposures and supports faster remediation

    Reviewed on May 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use Salt Security primarily for API discovery, mainly regarding data-sensitive information across the company. Before using Salt Security for API discovery and sensitive information, I didn't have any visibility regarding APIs in my environment. This was a significant issue because I had some APIs configured incorrectly and exposing sensitive information. With Salt Security, I could see these APIs and report to the owners to correct them.

    What is most valuable?

    Salt Security gave me much better visibility into API risk. It helped me identify exposed endpoints, misconfigured APIs, and sensitive data flowing through APIs that required additional controls. Salt Security has become an important part of my API security program.

    The tool was straightforward to set up, and I gained visibility regarding the APIs that I didn't have before.

    What needs improvement?

    Alert tuning can require some time depending on API volume. Some findings need internal validation before actioning. The collaboration flows between security and engineering teams could be expanded further.

    While the solution was straightforward to set up and gave me the visibility that I needed, it has to improve some details and features to achieve a perfect rating.

    For how long have I used the solution?

    I have been using Salt Security for three years.

    What do I think about the stability of the solution?

    I experienced no stability issues.

    What do I think about the scalability of the solution?

    I experienced no scalability issues.

    How are customer service and support?

    Customer service was good.

    How was the initial setup?

    The tool was straightforward to set up, and I gained visibility regarding the APIs that I didn't have.

    What was our ROI?

    Salt Security impacted my ROI positively. I mainly avoided incidents after using Salt Security.

    What's my experience with pricing, setup cost, and licensing?

    The setup cost was acceptable, but adding additional APIs was actually quite expensive.

    What other advice do I have?

    If you want to have more visibility into your network and API security, I recommend Salt Security. Be aware that it will be somewhat expensive. I would rate this product a nine out of ten.

    IgmarRautenbach

    Provides visibility and control over all APIs

    Reviewed on Jan 08, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We use it to provide enhanced and improved security around API integrations for organizations. Given the product's backing by Google and Sequoia Capital, it's truly great.

    What is most valuable?

    It fills a gap in the market. Organizations lack visibility into their API landscape and posture. They don't know if APIs are secure, well-developed, or have vulnerabilities. They also can't detect API attacks until it's too late.

    Salt Security gives you visibility of all your APIs, identifies API security issues, and immediately alerts you of attacks.

    These are the main things organizations lack, even if they're already using APIs. Salt fills that gap for them.

    What needs improvement?

    I've built integrations for different systems, and some specific integrations might not be built in yet. This might be an issue for large customers but is not a major concern overall.

    So, the integration part could be a bit extended. Every organization has different systems, but Salt integrates with 90% of them. If a custom integration is needed, they can build it. They're very good at integrations. So, Salt Security can provide a proof of concept with system integration and share results within two weeks, which often leads to customer purchases.

    At this point, the product covers everything needed. They keep adding new features, and my local customers haven't requested any missing functionality. The product roadmap is good for the market.

    For how long have I used the solution?

    I have been with this solution for 18 months. It's new to the EDR market. I only launched in the New York market two years ago. We deal with the latest version.

    What do I think about the stability of the solution?

    It's really great. I would rate the stability a nine out of ten. I haven't encountered any instability issues.

    What do I think about the scalability of the solution?

    It's really, really scalable. Some customers handle seven billion API calls a month. That requires cloud deployment and scaling resources, which they do well, so ten out of ten.

    It's relatively new, about ten organizations in South Africa, but we have ongoing proof of concept. The adoption is rapid.

    How are customer service and support?

    The customer service and support are good; they know their stuff.

    Which solution did I use previously and why did I switch?

    We still use XY and Netscout VSN, but they offer limited API security compared to Salt's comprehensive integration and stability. Salt created its own category.

    Other vendors might be on-premise, part of larger solutions, or more complex. That's Salt's advantage and why it's gaining market share.

    How was the initial setup?

    It's a SaaS solution that mirrors traffic, so it's not an inline solution. That means two weeks is a general guideline for implementation.

    The deployment model is hybrid. Typically, in our market, it's hybrid with an on-prem server and the solution itself in the cloud.

    The challenge with deployments is limited personnel due to rapid growth. I work with over a hundred companies in EMEA for evaluation, so technical constraints might arise.

    However, we assist customers with integrations as it's more organizational than software-related.

    What about the implementation team?

    We have a team of 20 engineers skilled in the solution to provide local support.

    What's my experience with pricing, setup cost, and licensing?

    It is an annual subscription fee. It's very affordable. The value it provides justifies the cost, considering automation and availability features. Compared to other solutions, it's within a typical price range.

    Which other solutions did I evaluate?

    What other advice do I have?

    My initial discussions with organizations often reveal they lack visibility into their API landscape and sensitive data. The first discussion is how many APIs you have. How many integrations? Do you have sensitive data in your organization? And the answer from the head of security is, typically, "We don't know!"

    Organizations need a solution. And from what you've seen, that's where solutions like Salt come in. So, I would recommend this to to any organization, large and small.

    I would rate it a ten out of ten because it addresses fundamental risks that exist in dealing with sensitive information. It's crucial to have a solution like Salt in place. It's like a basic requirement, not just something that enhances efficiency.

    Information Technology and Services

    Senior Manager, Security

    Reviewed on Jul 10, 2023
    Review provided by G2
    What do you like best about the product?
    The product has been instrumental in helping us resolve attacks and better understanding vulnerabilities. The responsiveness from Salt team is great.
    What do you dislike about the product?
    Better root cause findings when issues are identified. However, the product is consistently getting better.
    What problems is the product solving and how is that benefiting you?
    Helping determine API vulnerabilities and prevent attacks.
    Insurance

    Amazing API security tool

    Reviewed on Jun 05, 2023
    Review provided by G2
    What do you like best about the product?
    First of all, the entire Salt team is a pleasure to work with. They are always responsive and are always eager to assist. Secondly, the Salt Security is the creme de la creme of API security tools. It does so much, and is a valuable tool in assisting with keeping our APIs safe.
    What do you dislike about the product?
    There is nothing that I dislike about this too.
    What problems is the product solving and how is that benefiting you?
    Salt Security is solving the issue of API security. As our organization starts to utilize APIs a lot more, we realized that there was a gap in monitoring those APIs. Now that we have brought on Salt, we can rest easy that our APIs are being monitored and protected.
    Retail

    Good Solution in Changing Landscape

    Reviewed on Feb 01, 2022
    Review provided by G2
    What do you like best about the product?
    A very lightweight solution that builds upon existing integrations, a responsive and open-minded support team, and an easy-to-navigate product. Salt isn't trying to solve every problem; they've found a niche and have focused on tightly sealing that gap.
    What do you dislike about the product?
    The product is still relatively new and missing quite a few bells and whistles. The SIEM logging integrations are missing native action logging, and we've had difficulties getting APIs going through a gateway to report correctly as unique items. However, Salt is a great partner and has been working with us through our requirements to improve the functionality that we need.
    What problems is the product solving and how is that benefiting you?
    We have not yet finished our implementation, but Salt will help us better secure our APIs without having to rely on heavy customization of some of the larger WAF-like products that are built to protect traditional applications.
    Financial Services

    Salt Security Survey

    Reviewed on Jan 31, 2022
    Review provided by G2
    What do you like best about the product?
    Attack traffic is probably the most consulted screen, however the security insights, sensitive information screens and endpoint autodiscovery are all also very useful
    What do you dislike about the product?
    I would like to see API compositions and other calls chains (sequences of APIs calling each other) stitched together graphically so the exact specific call chain that each API call was part of is super clear.
    What problems is the product solving and how is that benefiting you?
    Identifying potentially malicious traffic, tightening up the handling of sensitive information, detecting improper use of authentication and other security details.
    Erich Y.

    Visibility into All APIs

    Reviewed on Jan 28, 2022
    Review provided by G2
    What do you like best about the product?
    we have a centralized view of the APIs and we have alerts generated for events that are not common that could be attacks in our enviroment
    What do you dislike about the product?
    Salt could generate some detailed reports and also have some link on OAS to show how to fix those appointments
    What problems is the product solving and how is that benefiting you?
    The visibility of our APIs and alerting us when something different is happening in our enviroment
    Marcel G.

    A promising new approach of API Security

    Reviewed on Jan 26, 2022
    Review provided by G2
    What do you like best about the product?
    Easy navigation and the detection of atacks at business logic layer.
    What do you dislike about the product?
    The tool could have more options to extract detailed statistic data.
    What problems is the product solving and how is that benefiting you?
    The salt could be an excellent tool to help with incident causes investigation.
    Jeff S.

    Small, nimble, and very capable.

    Reviewed on Jan 25, 2022
    Review provided by G2
    What do you like best about the product?
    I love the product and its intuitive nature. It helps with both attacks and remediations.
    What do you dislike about the product?
    They're small, young, and nimble. They have all the need-to-have features but are still working towards some of the nice-to-have features.
    What problems is the product solving and how is that benefiting you?
    API security, especially rouge APIs, and ensuring complete coverage for all endpoints on the gateway.