Ermetic
Ermetic is a cloud security company founded in 2019 that pioneered cloud infrastructure entitlement management (CIEM) as part of a unified, identity-first cloud-native application protection platform (CNAPP) spanning AWS, Azure, and GCP. The platform provides full visibility into permissions and entitlements across multi-cloud environments, least-privilege and just-in-time access controls, anomaly detection against behavioral baselines, and compliance and cloud security posture management (CSPM). Ermetic raised roughly $100M from investors including Accel, Norwest Venture Partners, Glilot Capital Partners, and Target Global, and was acquired by Tenable in October 2023 for approximately $265M. The product now ships as Tenable Cloud Security; the ermetic.com domain redirects to Tenable, and the former Ermetic customer application (us.app.ermetic.com) exposes a login-gated REST API.
Index entry only — little beyond a description and a link, and nothing machine-readable enough for an agent to act on without a human reading the site first.
API Evangelist profiles Ermetic the way a machine reads it — 1 machine-readable artifact, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Ermetic scores 8.5/100 (minimal), with a separate agent-readiness read of 0/100 (human only). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
How we profile Ermetic
Each block below is one kind of artifact we hold for Ermetic. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
Security Posture 1
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Every other property we hold for Ermetic — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Documentation 1
Reference material describing how the API behaves
Access & Security 1
Authentication, authorization, and security posture
Company 2
The organization behind the API
← All providers · Data indexed from github.com/api-evangelist/ermetic · machine-readable index on apis.io