© 2026 Akamai Technologies
API Security & Compliance: Implicit and explicit requirements for data protection
Executive Summary
Overview of API security: The white paper offers a thorough guide to API security and compliance, underlining the significance of safeguarding sensitive data, including customer information, from potential threats and misuse.
Explicit requirements: This section outlines specific regulatory requirements, such as GDPR and HIPAA, that mandate the protection of data exchanged through APIs.
Implicit requirements: The paper also discusses implicit requirements, such as best practices for securing APIs, which may not be explicitly stated in regulations but are crucial for maintaining data integrity and trust.
Akamai solutions: Akamai API Security and App & API Protector solutions are recognized as effective methods for discovering, monitoring, and safeguarding APIs from a range of threats, including DDoS assaults, bot activities, and OWASP Top 10 exploits.
Best practices: The white paper concludes with a set of best practices for API security, including implementing strong authentication, encryption, and access controls, as well as continuous monitoring and threat detection.