Frequently asked questions
R/Pulse is a preemptive resilience platform that helps organizations anticipate high and critical risks across APIs, regulated integrations, authorized surfaces, and AI agents before they become exploitation, incidents, or operational impact.
The "R" in R/Pulse represents essential dimensions for operating critical systems with more confidence: risk, resilience, robustness, resistance, reaction, and recovery.
R/Pulse is a modular platform. API Resilience Core is the module that originated the product, but the platform also includes specialized modules for Open Finance & Insurance Resilience, Autonomous Adaptive Security Agent, and Agent Resilience & Observability.
No. It complements certification and mandatory validations with complex, negative, and unexpected scenarios, helping institutions find relevant gaps in regulated APIs.
No. AASA complements traditional approaches with authorized, recurring, context-driven simulations, helping assess applications, APIs, and exposure paths defined within scope.
Yes. In the Agent Resilience & Observability module, R/Pulse helps observe behavior, assess risks, and generate resilience evidence for AI agents, tools, connectors, APIs, and digital journeys.
Yes. Modules can be adopted point-in-time, continuously, or self-hosted, according to maturity, criticality, and governance requirements.
That is not how we position R/Pulse. The focus is not 'API testing' in the traditional sense. The focus is anticipating risks, generating evidence, supporting remediations, and proving resilience in critical APIs.
R/Pulse assesses the real behavior of surfaces, but is not generic scanning. The focus is not on maximizing coverage of known classes — it is on revealing relevant risks in the real behavior of APIs, based on the application's context.
R/Pulse is best suited for business-critical APIs: endpoints supporting digital journeys, sensitive data, relevant integrations, critical processes, partners, internal systems, or interfaces that agents and automations can use to act.
When available, documentation and application context help deepen the analysis. What is used in each assessment depends on the agreed scope — and always happens in an authorized way.
R/Pulse delivers prioritized risks and evidence for action, including impacted endpoint, used input, observed response, severity, reproduction context, grouped variations, and inputs for remediation and re-evaluation.
R/Pulse can re-evaluate APIs, integrations, or critical surfaces after remediations to support verification that the risk was addressed or reduced within the analyzed scope. The idea is to move from "it was fixed" to "it was re-evaluated with evidence".
No. Gateways control traffic, authentication, policies, and rate limiting. R/Pulse operates in a different layer: it reveals risks in the real behavior of APIs, integrations, surfaces, and agents.
No. Observability is an important part of the path. R/Pulse complements that layer by connecting observed signals, traces, and behaviors to context, risk, evidence, and re-evaluation.
Yes. R/Pulse can evolve to continuous CI/CD operation and can also operate in a self-hosted model, including with the customer's own infrastructure and AI key when required.
R/Pulse was designed for enterprise environments, with SSO, role-based access control, audit logs, encryption at rest and in transit, and a self-hosted deployment option. The R/Pulse platform, developed by Sofist, is covered by the ISO 27001:2022 certified scope of the product operation.
For point-in-time executions, the scope is defined upfront: APIs, endpoints, environment, permissions, and analysis criteria. R/Pulse assesses high and critical risks and delivers reproducible evidence for prioritization and action. In the API Resilience Core and Open Finance & Insurance Resilience modules, if no high or critical risks are found within the agreed scope, the customer does not pay for that execution.
