A division of Jiranisoko Market Ltd
JIRANISOKO Tech
Solutions

Pillar 05 — Frameworks & API

API Design, Integration, Testing & Security Audit

APIs specified before they are built, contract-tested against their consumers, and audited against the OWASP API risks. We also review APIs we did not build, and we report what we find without softening it.

Business outcomes

What you get from the engagement

  • A published contract consumers can build against with confidence
  • Breaking changes caught in the pipeline rather than by a consumer
  • Authorisation defects identified before exposure, not after
  • Documentation generated from the specification and therefore current
Technical capabilities

What we do inside it

  • OpenAPI-first design and governance
  • Consumer-driven contract testing
  • Versioning, deprecation and lifecycle policy
  • API gateway, rate limiting and authentication design
  • OWASP API Security Top 10 audit

Architecture and stack

How we build it

Architectural position

Object-level authorisation is tested per endpoint and per role. Broken object-level authorisation remains the most common finding in the APIs we audit.

Representative technologies

  • OpenAPI
  • .NET
  • Laravel
  • Kong
  • Pact
  • OAuth 2.0
  • Postman

Technology selection follows the requirement. This list is representative of engagements in this service line, not a constraint we impose on yours.

Service assurance

SLA, compliance and governance

Engagements in this service line are delivered under the Platinum service tier by default, against the compliance obligations below. Both are set in the engagement contract, not by this page.

Default tier
Platinum — 99.95% availability target, P1 response within 15 minutes, coverage 24 × 7 × 365.
Compliance scope
  • OWASP API Top 10
  • ISO/IEC 27001
  • Penetration testing
Governance
Written architecture decision records, weekly delivery reporting, and a documented handover comprising runbooks, source and credential transfer at engagement close.
Intellectual property
Client-commissioned work product vests in the client on payment. Source escrow available on request.
Service level tiers, availability targets and response commitments
Tier Availability target P1 response P1 resolution target Coverage Service credits
Platinum 99.95% 15 minutes 4 hours 24 × 7 × 365 Yes
Gold 99.9% 1 hour 8 hours 24 × 5 plus on-call Yes
Silver 99.5% 4 hours 2 business days 09:00–18:00 EAT No
Publication gate G-05 — outstanding

These values illustrate the structure of the table. Each figure must be confirmed by whoever will be contractually bound by it, and the availability targets must be achievable on the underlying cloud provider SLAs before publication. Publishing a 99.95% target on infrastructure whose own composite SLA is lower creates an obligation that cannot be met.

Request for Proposal

Begin with a scoped conversation, not a sales call.

Our intake is structured so that the first response you receive is technical. Tell us which of the following describes your position and we will route your enquiry to the engineering lead who owns that practice.

Enquiries are acknowledged within one business day and answered substantively within two business days. All submissions are treated as confidential; a mutual non-disclosure agreement is available before disclosure of scope.