Passive API Intelligence Layer

Endpoints Discovery & Automation, engineered for CISOs.

GiraffeORCA mirrors production API traffic out-of-band - discover shadow routes, approve contracts, and automate schema baselines with 0ms added latency and absolute on-prem sovereignty.

0msadded to the path
100%on-prem · zero cloud
OWASPAPI Top 10 visibility
Endpoint Discovery Automation Ready Passive Mirror Schema Enforcement On-Premises
Product surface

Endpoints Discovery & Automation

The CISO console for shadow API inventory - scan mirrored traffic, threshold by hit volume, then approve contracts into your automation baseline.

orca · endpoints discovery & automation LIVE

Endpoints

Routes observed from out-of-band traffic mirrors - approve to lock into schema automation.

0 candidates above threshold · passive mirror · 0ms path impact Approve → Postman / OpenAPI automation
How it works

A passive mirror. Never in the path.

Your gateway copies each request to ORCA out-of-band. The business flow never waits on us - ORCA analyses the mirror while your app answers the user.

STEP 01

Request arrives

A user, app, service or AI agent hits your API through the normal gateway.

STEP 02

nginx mirrors it

A one-line mirror directive sends a copy to ORCA. The original is untouched.

STEP 03

ORCA analyses

A Go service inspects endpoint, headers and payload, checks your schema, and scores anomalies.

STEP 04

You approve

Discovered routes land in Endpoints Discovery - approve into automation or dismiss noise.

orca · analysis stream
LIVE
Signals Intelligence

Read every request the way your app does.

A WAF sees a request cross the boundary. ORCA parses the mirrored copy down to the field - which route, which method, what body, what headers actually came through - and scores anything that drifts.

Clean traffic passes untouched
BOLA, shadow routes and resource abuse flagged in place
Every finding bound to the device fingerprint
ClientDevice request
Gatewaynginx / firewall
App engineprocesses · mirrors copy
mirror ⟶
ORCA● analyzing
Endpoint · headers · payload · anomalies - correlated with the device fingerprint on every mirrored request.
Zero Impact

A passive mirror, out-of-band by design.

ORCA lives beside your stack, not inside it. The gateway hands it a copy; the original request continues uninterrupted. If ORCA is slow, down or overloaded, production traffic never notices.

No SDK to embed in every service. No change to application code. One mirror directive and a Go service inside your network.

Capabilities

Deep visibility, zero production risk.

Everything ORCA does happens on a mirrored copy - so you can watch the most sensitive part of your stack without ever touching the request the user is waiting on.

Endpoint & payload analysis

Every mirrored call is parsed down to the field: route, method, body, headers.

Anomaly detection

Unusual shapes, sizes, sequences and access patterns are scored and surfaced.

Approve workflow

Promote discovered routes into automation with one click - or dismiss noise with the dismiss control.

Schema enforcement

Define the contract you expect. ORCA flags every request that drifts from it.

Postman import

Bring existing collections - ORCA turns them into the baseline it measures against.

100% on-premises

Runs entirely inside your perimeter. No payloads leave your network.

Why ORCA

A firewall proves a request entered. ORCA shows what it’s doing inside.

APIs are how modern systems communicate - identity, business logic, data and automation all travel through them. A WAF can’t tell you that an authorised token just walked off with 40,000 records.

ORCA gives you the visibility the OWASP API Top 10 assumes you already have.

OWASP API Top 10ORCA sees it
01Broken Object Level Authorizationpayload+identity
02Broken Authenticationtoken context
03Unrestricted Resource Consumptionrate + size
05Broken Function Level Authorizationroute map
09Improper Inventory Managementshadow routes
ORCA vs a traditional WAF

Different question, different layer.

A WAF guards the boundary. ORCA understands the conversation happening inside it.

CapabilityTraditional WAFAPI GatewayGiraffeORCA
Reads full request payloadsignatures onlyrouting onlyfield-level
Zero impact on request pathinlineinlinepassive mirror
Schema / contract enforcementnopartialPostman-based
Endpoint discovery + approvenopartialbuilt-in
Anomaly scoring on business logicnonobuilt-in
100% on-premisesvariesvariesalways
FAQ

Questions, answered.

No. ORCA receives an out-of-band mirror of each request via a standard nginx mirror directive. If ORCA is slow, down, or overloaded, your production traffic is completely unaffected - the user’s request never waits on us.

A WAF matches signatures at the boundary to block known-bad traffic. ORCA reads the request the way your application does - endpoint, headers, payload - to tell you what an already-authorised request is actually doing. They’re complementary layers, not replacements.

Nowhere. ORCA runs entirely on-premises inside your perimeter. No payloads, headers or metadata are sent to any cloud or third party. Findings forward only to systems you already run, like your SIEM.

Import the Postman collections you already maintain. ORCA uses them as the schema baseline and flags any live request that drifts - undocumented routes, unexpected fields, wrong types - without you writing a separate spec.

Add one mirror directive to your gateway config and run the ORCA analysis service (Go) inside your network. There’s no SDK to embed in every service and no change to application code.

See Endpoints Discovery on your traffic.

Book a walkthrough with the Giraffe team. We’ll mirror a sample of your traffic and show shadow routes, approve workflows, and findings - no production change required.