Endpoints Discovery & Automation, engineered for CISOs.
GiraffeORCA mirrors production API traffic out-of-band - discover shadow routes, approve contracts, and automate schema baselines with 0ms added latency and absolute on-prem sovereignty.
Endpoints Discovery & Automation
The CISO console for shadow API inventory - scan mirrored traffic, threshold by hit volume, then approve contracts into your automation baseline.
A passive mirror. Never in the path.
Your gateway copies each request to ORCA out-of-band. The business flow never waits on us - ORCA analyses the mirror while your app answers the user.
Request arrives
A user, app, service or AI agent hits your API through the normal gateway.
nginx mirrors it
A one-line mirror directive sends a copy to ORCA. The original is untouched.
ORCA analyses
A Go service inspects endpoint, headers and payload, checks your schema, and scores anomalies.
You approve
Discovered routes land in Endpoints Discovery - approve into automation or dismiss noise.
Read every request the way your app does.
A WAF sees a request cross the boundary. ORCA parses the mirrored copy down to the field - which route, which method, what body, what headers actually came through - and scores anything that drifts.
A passive mirror, out-of-band by design.
ORCA lives beside your stack, not inside it. The gateway hands it a copy; the original request continues uninterrupted. If ORCA is slow, down or overloaded, production traffic never notices.
No SDK to embed in every service. No change to application code. One mirror directive and a Go service inside your network.
Deep visibility, zero production risk.
Everything ORCA does happens on a mirrored copy - so you can watch the most sensitive part of your stack without ever touching the request the user is waiting on.
Endpoint & payload analysis
Every mirrored call is parsed down to the field: route, method, body, headers.
Anomaly detection
Unusual shapes, sizes, sequences and access patterns are scored and surfaced.
Approve workflow
Promote discovered routes into automation with one click - or dismiss noise with the dismiss control.
Schema enforcement
Define the contract you expect. ORCA flags every request that drifts from it.
Postman import
Bring existing collections - ORCA turns them into the baseline it measures against.
100% on-premises
Runs entirely inside your perimeter. No payloads leave your network.
A firewall proves a request entered. ORCA shows what it’s doing inside.
APIs are how modern systems communicate - identity, business logic, data and automation all travel through them. A WAF can’t tell you that an authorised token just walked off with 40,000 records.
ORCA gives you the visibility the OWASP API Top 10 assumes you already have.
Different question, different layer.
A WAF guards the boundary. ORCA understands the conversation happening inside it.
| Capability | Traditional WAF | API Gateway | GiraffeORCA |
|---|---|---|---|
| Reads full request payload | signatures only | routing only | field-level |
| Zero impact on request path | inline | inline | passive mirror |
| Schema / contract enforcement | no | partial | Postman-based |
| Endpoint discovery + approve | no | partial | built-in |
| Anomaly scoring on business logic | no | no | built-in |
| 100% on-premises | varies | varies | always |
Questions, answered.
No. ORCA receives an out-of-band mirror of each request via a standard nginx mirror directive. If ORCA is slow, down, or overloaded, your production traffic is completely unaffected - the user’s request never waits on us.
A WAF matches signatures at the boundary to block known-bad traffic. ORCA reads the request the way your application does - endpoint, headers, payload - to tell you what an already-authorised request is actually doing. They’re complementary layers, not replacements.
Nowhere. ORCA runs entirely on-premises inside your perimeter. No payloads, headers or metadata are sent to any cloud or third party. Findings forward only to systems you already run, like your SIEM.
Import the Postman collections you already maintain. ORCA uses them as the schema baseline and flags any live request that drifts - undocumented routes, unexpected fields, wrong types - without you writing a separate spec.
Add one mirror directive to your gateway config and run the ORCA analysis service (Go) inside your network. There’s no SDK to embed in every service and no change to application code.
See Endpoints Discovery on your traffic.
Book a walkthrough with the Giraffe team. We’ll mirror a sample of your traffic and show shadow routes, approve workflows, and findings - no production change required.