--- title: "Scan Policy Performance" slug: "scan-policy-performance" description: "Performance testing results for eight predefined policies by Traceable for API Security Testing." tags: ["API Security", "Performance Testing", "Predefined Policies"] status: "update" updated: 2026-09-10T05:20:30Z published: 2026-09-10T05:20:30Z canonical: "traceabledocs.document360.io/scan-policy-performance" --- > ## Documentation Index > Fetch the complete documentation index at: https://traceabledocs.document360.io/llms.txt > Use this file to discover all available pages before exploring further. # Scan Policy Performance ##### Updates (July 2026 to September 2026) - *September 2026* — Updated the document to add results from DAST Scans. For more information, see [DAST scan](/v1/docs/scan-policy-performance#dast-scan). Traceable’s API Security Testing (APIST) provides you with a set of predefined scan policies you can use without defining your own attack selections. Each predefined policy bundles a fixed set of test plugins chosen for a specific testing requirement, so you can start scanning without deciding which individual attacks to enable. Predefined policies appear alongside your own policies under **Testing → Policies**. For more information on predefined policies, see [Available policies](/v1/docs/ast-policies#available-policies). Traceable measures the performance of predefined policies to help you anticipate scan behavior before running one in your own environment. ## What you will learn from this topic By the end of this topic, you will be able to understand: - What you need in place before running a scan with a predefined policy. - How predefined policies perform as API counts increase, according to traffic type. --- ## Performance testing The performance results provide a reference as API counts increase. They are based on controlled testing under realistic performance conditions. The results highlight how scan duration and test-case count scale across policies, helping you select the right policy and traffic type for your use case. ### Scope The following table defines the scope of the testing: | Parameter | Value | | --- | --- | | Environment | Production-like benchmark environment | | Traffic type | Replay, DAST | | API counts | 10, 20, 40, 80 | | Policies | Eight predefined policies | | Auth hook | Enabled on echo app | | Runners | 1 (to isolate variables) | ### Fixed test configuration The following parameters were held constant across all runs, ensuring comparable results: | **Parameter** | **Replay** | **DAST** | | --- | --- | --- | | App | `echo` (perf-echo) | `echo` | | Pipeline`test_type` | `perf_replay` | `perf_quick_live` | | `policy_type` | Built-in name | Built-in name | | API latency | 200 ms | 200 ms | | Authentication | Enabled | Enabled | | Request headers | 5 | 5 | | Request body | 20 | 20 | | Request query | 5 | 5 | | Scenarios per API | 40 | 40 | | API buffer % | 25% | 25% | | Scan execution threads | 40 | 40 | | CLI version | 2.7.0 or later | 2.7.0 or later | | Runners | 1 | 1 | | Runner configuration | 2 CPU, 4Gi Memory | 2 CPU, 4Gi Memory | | Environment | Production | Production | --- ## Results The test results show the execution times and the number of test cases generated as the API count increases, according to the traffic type. ### Replay scan The following tables show the performance results of 8 predefined policies for Replay scans: #### PipelineScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 31s | 130 | | 20 | 32s | 260 | | 40 | 41s | 520 | | 80 | 1 min | 1.04k | #### DailyScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 5 min | 12.45k | | 20 | 8 min | 24.90k | | 40 | 14 min | 49.80k | | 80 | 26 min | 99.60k | #### SafeScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 1 min | 300 | | 20 | 1.2 min | 600 | | 40 | 2 min | 1.20k | | 80 | 2 min | 2.40k | #### QuickScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 6 min | 16.94k | | 20 | 11 min | 33.88k | | 40 | 20 min | 67.74k | | 80 | 38 min | 135.52k | #### PciDssScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 8 min | 25.92k | | 20 | 13 min | 49.13k | | 40 | 23 min | 96.11k | | 80 | 40 min | 176.04k | #### OwaspTopTenScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 7 min | 27.32k | | 20 | 13 min | 50.87k | | 40 | 23 min | 100.59k | | 80 | 41 min | 191.96k | #### WeeklyScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 7 min | 29.28k | | 20 | 13 min | 58.55k | | 40 | 24 min | 117.10k | | 75 | 45 min | 219.57k | #### ExtensiveScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 16 min | 100.61k | | 20 | 35 min | 208.30k | | 40 | 1 hr 12 min | 424.29k | | 80 | 2 hr 16 min | 850.01k | ### DAST scan The following tables show the performance results of 8 predefined policies for DAST scans: #### PipelineScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 48s | 88 | | 20 | 1 min | 174 | | 40 | 1 min | 344 | | 80 | 1 min 22s | 684 | #### DailyScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 4 min 35s | 1.69k | | 20 | 9 min 4s | 3.39k | | 40 | 16 min 21s | 6.75k | | 80 | 32 min 10s | 13.48k | #### SafeScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 1 min | 300 | | 20 | 58s | 600 | | 40 | 1 min 10s | 1.20k | | 80 | 1 min 29s | 2.40k | #### QuickScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 6 min 43s | 2.44k | | 20 | 11 min 15s | 4.86k | | 40 | 23 min 8s | 9.72k | | 80 | 43 min 45s | 19.41k | #### PciDssScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 8 min 53s | 3.88k | | 20 | 17 min 19s | 7.72k | | 40 | 24 min 56s | 13.39k | | 80 | 1 hr 11 min 17s | 31.01k | #### OwaspTopTenScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 9 min 46s | 4.04k | | 20 | 14 min 41s | 7.06k | | 40 | 25 min 51s | 13.99k | | 80 | 1 hr 17 min 45s | 32.14k | #### WeeklyScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 14 min 52s | 5.15k | | 20 | 26 min 43s | 10.28k | | 40 | 43 min 10s | 18.48k | | 75 | 1 hr 49 min 16s | 41.09k | #### ExtensiveScanPolicy | API count | Execution time | Tests generated | | --- | --- | --- | | 10 | 33 min 52s | 14.88k | | 20 | 55 min 29s | 26.00k | | 40 | 1 hr 54 min 18s | 54.69k |