Rabia - your idea is in progress. Remzi - yours is being worked on too.
One bigger update: ORCA will be connected to our new tool, Argus. When an endpoint shows abnormally high abuse frequency, Argus will pull the raw source code for that endpoint and use AI to assess whether an attacker could actually cause damage there - so you get real exploitability context, not just traffic anomalies.
Orca watches your live API traffic and auto-generates documentation ranked by real usage - so your busiest endpoints get documented first, and nothing you actually ship goes undocumented.
API security without agents, code changes, or cloud proxies. ORCA passively observes traffic from a network mirror - discovering shadow APIs, mapping every endpoint and consumer, and catching DNS exfiltration, fully on-premises, zero latency. If you can configure a mirror port, you're done.