Escape Attack Surface Management
Escape · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Legacy EASM finds hosts and ports. Your engineers ship APIs, SPAs, MCPs, and AI apps.
Escape Attack Surface Management maps your actual application layer. Every REST API, GraphQL endpoint, SPA, MCP, gRPC and SOAP service your engineers are shipping across your distributed org. If it's exposed, Escape finds it. Including the ones nobody filed a ticket for.
Show the rest of the publisher’s description (6 more lines)
What you get with Escape ASM
- Application-layer discovery, not just hosts and ports. Customers find 30% more attack surface on average from shadow APIs alone. The endpoint that shipped without a ticket, the staging service nobody took down, the MCP a developer prototyped and forgot. Agentless scanning plus native connectors map your full attack surface in under an hour.
- Findings that route themselves to owners. Every asset is mapped to the team that built it, pulled from your repos. No more "who owns this?" Slack threads. Findings reach the right engineer with the asset context already attached. Security engineers save roughly 12 hours per month on triage and routing.
- Proof of exploitability, not just inventory. There's a difference between a vulnerability that exists and one that can actually be exploited. Every asset comes with a code fix and a proof-of-exploit trace - the request sequence that demonstrates the issue is real and reachable. Engineers trust what was found and ship the fix.
- Scales with your org, including M&A. Public API, CLI, custom reporting, programmable workflows. New acquisition, new product line, new team, every new asset is discovered, attributed, scanned, prioritized, and routed without anyone filing a ticket.
- Multiplies your existing stack. Every discovered asset flows into Wiz with full application-layer context: owner, type, exposure level, associated risk. Your risk platform gets smarter. Manual asset hygiene drops.
Highlights
Highlighted by the publisher on AWS Marketplace.
Application-layer discovery, not ports and hosts Map every REST API, GraphQL endpoint, SPA, MCP, gRPC, and SOAP service your engineers are shipping. Find 30% more attack surface from shadow APIs alone.
From asset to action in one hour. Agentless scans and native code-repo connectors map your full API attack surface in under an hour. Every asset routed to the team that built it, with proof of exploit attached.
Built to scale with M&A and distributed orgs. Programmable via public API and CLI. New acquisitions, product lines, and teams onboarded automatically. Every asset flows into Wiz with full application-layer context.
Preview
3 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Plans and pricing as listed
1 listed- Units
Refund terms
As stated by the publisher on AWS Marketplace.
Refunds are not generally provided for AWS Marketplace contract purchases. For billing disputes or service issues, contact support@escape.tech within 30 days of subscription start.
Sources
Publisher resources
4 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

