middleBrick

Vulnerabilities

  • Prompt Injection
  • BOLA / IDOR
  • Auth Bypass
  • JWT Misconfiguration
  • SSRF
  • Data Exposure
  • Rate Limiting
  • Mass Assignment
  • GraphQL Attacks
View all 60+

Frameworks

  • FastAPI
  • Express
  • Spring Boot
  • Django
  • NestJS
  • Rails
  • Laravel
  • Gin
  • ASP.NET
View all 30+

LLM Security

  • OpenAI
  • Anthropic
  • Google Gemini
  • Mistral
  • Meta Llama
  • LangChain
  • LlamaIndex
View all 15+

By Industry

  • Fintech
  • Healthcare
  • SaaS
  • IoT

By Protocol

  • REST
  • GraphQL
  • gRPC
  • WebSocket

CWE Database

  • CWE-89: SQL Injection
  • CWE-79: XSS
  • CWE-287: Auth Bypass
  • CWE-200: Data Exposure
  • CWE-918: SSRF
  • CWE-502: Deserialization
View all 200+

Attack Techniques

  • Credential Stuffing
  • JWT Cracking
  • Prompt Injection
  • SSRF Metadata
  • IDOR Enumeration
View all 40+
Scan Your API Now — Free

Standards

  • OWASP API Top 10
  • PCI-DSS
  • HIPAA
  • SOC 2
  • GDPR
  • ISO 27001
  • NIST
  • CIS

Popular Checks

  • OWASP: Auth Bypass
  • PCI-DSS: Data Exposure
  • HIPAA: PII Leakage
  • SOC 2: Encryption
  • GDPR: Data Protection

Regulations

  • GDPR (EU)
  • CCPA (California)
  • LGPD (Brazil)
  • PSD2 (EU)
  • DORA (EU)
  • NIS2 (EU)
  • PIPL (China)
  • CMMC (US DoD)
  • FedRAMP (US)
View all 20+

By use case

  • Pre-launch API gate
  • CI/CD security gate
  • Pre-merge PR check
  • Post-deploy verification
  • New endpoint discovery
  • Pre-production scan
View all use cases

By role

  • For CISOs
  • For DevSecOps
  • For AppSec engineers
  • For Platform engineers
  • For AI / ML engineers
  • For Security architects
View all roles
Scan Your API Now — Free

middleBrick vs

  • vs Burp Suite
  • vs OWASP ZAP
  • vs 42Crunch
  • vs StackHawk
  • vs APIsec
  • vs Akto
All comparisons

Alternatives to

  • Alternatives to Burp Suite
  • Alternatives to OWASP ZAP
  • Alternatives to 42Crunch
  • Alternatives to StackHawk
  • Alternatives to Snyk
  • Alternatives to Salt
All alternatives
Case Studies Pricing Docs
EN ES PT DE FR
Get Started

Sub-Processor List

Last updated: May 2026 | RSS Feed

middleBrick uses the following sub-processors to deliver the service. Changes are announced at least 30 days in advance. Subscribe to the RSS feed for automatic notifications.

Sub-Processor Purpose Region Since
Cloudflare, Inc. Hosting, CDN, compute, database, storage Global (edge) 2025-12
Stripe, Inc. Payment processing, subscription billing US 2026-01
Resend, Inc. Transactional email delivery US 2026-02
Google LLC OAuth identity provider (optional, user-initiated) US 2026-01
GitHub, Inc. OAuth identity provider (optional, user-initiated) US 2026-03

What is NOT a sub-processor

  • Customer-side identity providers (Okta, Azure AD, etc.) — configured by the customer; middleBrick does not control or initiate data flows to these systems
  • Cloudflare Workers AI — runs on Cloudflare infrastructure already listed above; no separate data transfer

Data flow summary

  • Customer API scan data stays within Cloudflare (Workers + D1 + R2). Never routed to external AI providers.
  • Stripe receives billing information only (email, card via Stripe.js — card numbers never touch our servers).
  • Resend receives email addresses for transactional notifications only.
  • OAuth providers receive authentication redirects only when the user initiates login.

Questions about our sub-processors? Contact [email protected].

Product

Pricing Dashboard Status Case Studies

Security

Prompt Injection BOLA / IDOR Auth Bypass Data Exposure SSRF

Compliance

OWASP API Top 10 PCI-DSS 4.0 SOC 2 GDPR HIPAA

Trust

Trust Center DPA Sub-Processors VDP security.txt Privacy Policy Terms of Service

Developers

Documentation CLI GitHub Action MCP Server API Reference

middleBrick is a Zevlat Intelligence venture

hello@middlebrick.com