F5 ASM Essential Plan - API Support

F5 ASM
OWASP
IPI

Service Introduction

The Essential API plan protects your core API endpoints using basic profile tuning, enforced JSON/XML formats, and structured signature updates. It includes key security features such as hostname restrictions, illegal response handling, and basic rate-limiting. Suited for APIs with stable payloads and predictable consumer behavior, this plan provides baseline defense without overcomplicating your dev process — perfect for startups, internal APIs, or low-risk public integrations.

HTML Basic (Single Policy)

£2500 / HTML Website / Web Application / Yearly

HTML Basic
Features

OWASP Coverage

Violations and Learning Review
Monthly
Broken Access ControlCryptographic FailuresInjectionInsecure Design
Violations and Learning Review
Monthly
Injection
Violations and Learning Review
Monthly
Broken Access ControlCryptographic FailuresInjectionInsecure DesignSecurity Misconfiguration
Violations and Learning Review
Monthly
Broken Access ControlCryptographic Failures
Violations and Learning Review
Compact / Selective
Broken Access ControlInjection
Violations and Learning Review
Never / Compact
Broken Access ControlCryptographic FailuresSecurity Misconfiguration
Violations and Learning Review
Selective / Always
Violations and Learning Review
Selective / Always
Violations and Learning Review
Selective / Always
Violations and Learning Review
Selective / Always

Challanges Solved

Web application firewalls often give a false sense of security. Without regular tuning, policies become stale, missing new evasion techniques and generating noisy false positives that frustrate users and devs alike. Parameters go unvalidated, bot activity slips through, and outdated file or URL controls quietly introduce risk. Many businesses don’t realise that 'default protection' leaves critical gaps, especially as their app evolves with new features, endpoints, or third-party integrations.