Discover what matters most, before you test.
Where do you start security testing when your company has hundreds of services and thousands of APIs? Thatโs the question we kept hearing from teams using StackHawkโand itโs big. In modern environments, itโs not just about discovering APIs. Itโs about understanding which APIs matter most.
And thatโs why we built Sensitive Data Identification โ currently in beta and available in API Discovery.

This new capability helps you identify where sensitive data is being handled (such as PII, PCI, or HIPAA-related information) across your repositories before scanning, allowing you to focus on the APIs that truly matter to your business and customers.
Why We Built It
Letโs be honest: most teams are guessing.
When it comes to prioritizing what to test, many rely on tribal knowledge, spreadsheets, or whatโs top-of-mind, not actual data. That might get you part of the way there, but it leaves big gaps when it comes to understanding which APIs carry the most risk.
And while some teams try to patch those gaps with static analysis or runtime monitoring tools, those solutions:
- Often requires heavy tuning
- Donโt provide source-level context
- Only work after an API is deployed
We wanted to change that.
What It Does
API Discovery, now with Sensitive Data Identification, analyzes your codebase for references to sensitive data types, including PII fields, cardholder data, and health information. Then, it brings that context right into your Attack Surface view inside API Discovery. Now, instead of sifting through hundreds of repositories to wonder where to start, you get a prioritized view of what to test, based on whatโs most sensitive and most important.
No manual tagging. No guesswork. Just clear, actionable insights.
What This Unlocks
With this new capability, you can:
- Focus on what matters โ prioritize APIs based on actual data sensitivity
- Reduce manual effort โ let StackHawk surface key targets automatically
- Accelerate security onboarding โ get new services under test faster
- Support compliance efforts โ with clear visibility into regulated data coverage
Early adopters are already seeing the benefits โ including up to 55% more applications under test after enabling API Discovery.
Built for Modern Teams
Security is shifting left โ but not everyoneโs moving at the same pace. Our goal with Sensitive Data Identification is to provide teams with a clearer map, not just more tools. Whether youโre in AppSec, platform engineering, or just trying to wrangle API sprawl across your org, this release helps answer a critical question:
โAre we testing the right things?โ
Now youโll know.
Try It Today
Sensitive Data Identification is live for all StackHawk customers using API Discovery.
Log in to your StackHawk account and start prioritizing what matters
โ KaaKaww