Before I design & build something for them, I want to research more and seeking market data around 3 questions right now:
1. How concerned companies generally are around their API security? 2. Is API visibility more important than running security tests on APIs? 3. Are you using any API security tool in your company? If yes, which one & why? If no & you're an enterprise business with lots of API, why not?