Glemad
    Glemad EditorialDevelopers & API3 min read

    Introducing the ADT APIs

    ADT is now available as a suite of high-integrity APIs designed for developers.

    Introducing the ADT APIs
    3 min read


    Modern infrastructure demands intelligence that can understand context, reason about risk, and respond with clarity. With ADT-4, we’re making that intelligence accessible through a set of focused APIs that integrate seamlessly into existing systems whether cloud, hybrid, or on-premise.

    The ADT APIs enable monitoring, detection, analysis, and defense without requiring a full platform deployment. They provide the same core reasoning engine that powers the PulseADT, now exposed in lightweight, developer-friendly interfaces.

    Below is an overview of the current API family and what each unlocks.

    Threat Intelligence API

    An intelligence layer for understanding IPs, domains, files, behaviours, and attack indicators.

    What it does:

    • Evaluates indicators in real time
    • Provides reputation scoring
    • Maps signals to known attack patterns
    • Supports proactive defense and fraud prevention

    Designed for:
    SOC pipelines, fintech risk systems, anti-fraud engines, email gateways, secure access flows.

    Attack Detection API

    High-fidelity detection powered by ADT’s reasoning engine.

    What it does:

    • Interprets log events
    • Scores threat likelihood
    • Identifies attack types with narrative context
    • Combines behavioural, statistical, and pattern-based signals

    Designed for:
    Applications that need to know when an action, request, session, or event is malicious instantly and with clarity.

    Active Defense API

    Autonomous response coordinated through your own infrastructure.

    What it does:

    • Suggests or executes defensive actions
    • Coordinates with firewalls, proxies, gateways
    • Operates within strict safety boundaries
    • Produces evidence and justification for every action

    Examples:
    Block IP → Notify analyst → Push firewall rule → Confirm → Report.

    VAPT Scan API

    Continuous vulnerability and penetration testing through a single endpoint.

    What it does:

    • Scans applications, networks, cloud resources
    • Identifies configuration weaknesses
    • Assesses exploitability
    • Produces structured insight, not a raw scanner dump

    Designed for:
    DevSecOps pipelines, weekly audit cycles, build-time compliance gates.

    Compliance Scoring API

    Institution-grade compliance reasoning.

    What it does:

    • Maps posture to global standards
    • Supports African regulatory frameworks (CBN, NDPR, POPIA, etc.)
    • Generates compliance deltas
    • Highlights control gaps

    Designed for:
    Banks, fintechs, regulated SaaS, MSPs, and enterprise governance teams.

    Audit Evidence API

    Structured, verifiable, continuously assembled evidence.

    What it does:

    • Converts logs, configurations, and events into audit-ready evidence
    • Categorizes findings per framework
    • Supports regulators and enterprise customers
    • Provides cryptographic hashes for integrity

    Designed for:
    Audit teams, compliance officers, vendor assessments, security reviews.

    Risk Scoring API

    Adaptive risk evaluation with context awareness.

    What it does:

    • Calculates organizational risk based on signals
    • Considers severity, exploitability, impact, exposure
    • Produces prioritized lists
    • Enables clear remediation pathways

    Designed for:
    CISOs, risk teams, and governance functions that need reliable scoring.

    Incident Management API

    A full incident lifecycle engine, programmatically accessible.

    What it does:

    • Creates, updates, correlates, and completes incidents
    • Generates timelines and evidence packages
    • Supports operator-defined workflows
    • Ensures traceability across systems

    Designed for:
    SOC teams, MSPs, and any organization with monitoring pipelines.

    Built on the same foundations as the PulseADT

    Each API uses the same underlying reasoning, alignment, and safety framework as the full platform:

    • agentless event ingestion
    • lightweight agent telemetry
    • auditability of decisions
    • strict safety boundaries
    • deterministic reasoning scaffolding

    You can use one API, several, or all of them depending on your needs.

    “ADT APIs bring our intelligence system directly to developers. You don’t need to adopt an entire platform to build secure, trustworthy systems. You can start with a single call and expand as your needs grow.”
    ; David Idris, Founder & CEO