
Cryptomator
BoxCryptor
Mega
Nextcloud
Tresorit
Google Drive
Cloudfogger
Dropbox
middleBrick
Wallarm
Metlo API Security
PromptGuard
SecureStack
middleBrick scans any API endpoint and returns a security risk score (A+ through F) with actionable findings โ no agents, no config, no credentials required.
Submit a URL or OpenAPI spec. middleBrick runs 12+ security checks in parallel and delivers a prioritized report with severity ratings and remediation guidance in under 60 seconds. It tests what an unauthenticated attacker would see โ black-box, zero setup.
The only self-service scanner with dedicated LLM checks: * System prompt leakage detection * Prompt injection testing * Jailbreak probes * Data exfiltration vectors * Excessive agency and cost exploitation
OWASP API Security Top 10: * Access Control: BOLA/IDOR and BFLA. * Authentication: Multi-method bypass detection and JWT analysis. * Data Exposure: PII, API keys, and credit cards with Luhn validation. * Technical Vulnerabilities: Input Validation, Rate Limiting, SSRF, and Security Misconfiguration. * Modern Architecture: GraphQL vulnerabilities, Encryption & Transport Security, and API Inventory gaps. * Specifications: Full OpenAPI 2.0/3.0/3.1 spec analysis included.
npx middlebrick scan in your terminal or CI pipeline.
Cryptomator
middleBrickNo middleBrick videos yet. You could help us improve this page by suggesting one.
middleBrick's answer:
middleBrick assigns a quantitative risk score (0-100) to any API in seconds, not weeks. It covers OWASP API Top 10, GraphQL, and LLM/AI-specific security checks in a single scan. It integrates directly into developer workflows via CLI, GitHub Action, and MCP server for AI assistants โ no sales calls, no setup meetings.
middleBrick's answer:
Most API security tools require enterprise contracts, complex onboarding, or inline proxies. middleBrick is fully self-service: scan any API endpoint in minutes even with a free account.
middleBrick's answer:
DevSecOps engineers, API developers, and security teams at startups and scale-ups who need to test their APIs for vulnerabilities without long procurement cycles. Also teams building AI/LLM-powered products who need to secure their model-facing APIs.
Based on our record, Cryptomator seems to be more popular. It has been mentiond 303 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.
> I dislike Dropbox for reasons that aren't technical, but the big thing for me is that I want either E2EE, or control/ownership of where my data is stored. You could run something like Cryptomator on top of Dropbox: https://cryptomator.org/ It even has (paid) iOS and Android apps for mobile access. - Source: Hacker News / 4 months ago
This is Nice. However, how do one access their diary, when you stopped maintaining it? Is this targeted more at the technically inclined, high-profile people who need to keep secrets? Personally, I believe that for something like a diary/journal, it should be in a format easily readable by most tools (so a Plain-Text or a MarkDown at best), then it is in a container/folder. Now, encrypt that container/folder... - Source: Hacker News / 6 months ago
If you still want/need cloud storage, but don't want to roll your own (with the warts that brings), Cryptomator is an excellent tool for source encrypting your data before uploading them. It works transparently, and has clients for Mac/Windows as well as iOS/Android. It's also open source, and "free" (IIRC there's a one time fee for the mobile client). https://cryptomator.org/. - Source: Hacker News / 9 months ago
- Syncthing (https://syncthing.net/) to keep the files synchronized between desktops and laptops computers - Webdav (https://github.com/hacdias/webdav) to access the files on the server via other applications - Cryptomator (https://cryptomator.org/) to crypt/decrypt sensible directories. - Source: Hacker News / 10 months ago
While I get the whole homelab thing is exiting and a great learning experience, it's simply not worth the time and effort for the majority of people. You will end up paying much more for your services, along with spending a ton of time maintaining it (and if you don't, you will probably find yourself on the end of a 0-day hack sometime). In Northern/Western Europe, where power costs around โฌ0.3/kWh on average,... - Source: Hacker News / about 1 year ago
BoxCryptor - Boxcryptor encrypts your sensitive files before uploading them to cloud storage services like Dropbox, Google Drive, Microsoft OneDrive, Box, and many others.
Wallarm - Wallarm WAF is AI-powered Platform that automates real-time application protection combines Active Threat Verification engine with a DevOps friendly NG-WAF and security testing for websites, microservices and APIs across public and private clouds.
Mega - Secure File Storage and collaboration
Metlo API Security - Open Source API Security Platform
Nextcloud - With Nextcloud enterprises host their own secure cloud solution for storage, collaboration & communication from any device, anywhere.
PromptGuard - The firewall for AI prompts.