This documentation site is no longer updated. All new content and future updates are published on our Harness Developer Hub site. Please bookmark the new link, as existing pages here may become outdated.

Scan Policy Performance

Prev Next
Updates (July 2026 to September 2026)
  • September 2026 — Updated the document to add results from DAST Scans. For more information, see DAST scan.

Traceable’s API Security Testing (APIST) provides you with a set of predefined scan policies you can use without defining your own attack selections. Each predefined policy bundles a fixed set of test plugins chosen for a specific testing requirement, so you can start scanning without deciding which individual attacks to enable.

Predefined policies appear alongside your own policies under Testing → Policies. For more information on predefined policies, see Available policies. Traceable measures the performance of predefined policies to help you anticipate scan behavior before running one in your own environment.

What you will learn from this topic

By the end of this topic, you will be able to understand:

  • What you need in place before running a scan with a predefined policy.

  • How predefined policies perform as API counts increase, according to traffic type.


Performance testing

The performance results provide a reference as API counts increase. They are based on controlled testing under realistic performance conditions. The results highlight how scan duration and test-case count scale across policies, helping you select the right policy and traffic type for your use case.

Scope

The following table defines the scope of the testing:

Parameter

Value

Environment

Production-like benchmark environment

Traffic type

Replay, DAST

API counts

10, 20, 40, 80

Policies

Eight predefined policies

Auth hook

Enabled on echo app

Runners

1 (to isolate variables)

Fixed test configuration

The following parameters were held constant across all runs, ensuring comparable results:

Parameter

Replay

 DAST

App

echo (perf-echo)

echo

Pipelinetest_type

perf_replay

perf_quick_live

policy_type

Built-in name

Built-in name

API latency

200 ms

200 ms

Authentication

Enabled

Enabled

Request headers

5

5

Request body

20

20

Request query

5

5

Scenarios per API

40

40

API buffer %

25%

25%

Scan execution threads

40

40

CLI version

2.7.0 or later

2.7.0 or later

Runners

1

1

Runner configuration

2 CPU, 4Gi Memory

2 CPU, 4Gi Memory

Environment

Production

Production


Results

The test results show the execution times and the number of test cases generated as the API count increases, according to the traffic type.

Replay scan

The following tables show the performance results of 8 predefined policies for Replay scans:

PipelineScanPolicy

API count

Execution time

Tests generated

10

31s

130

20

32s

260

40

41s

520

80

1 min

1.04k

DailyScanPolicy

API count

Execution time

Tests generated

10

5 min

12.45k

20

8 min

24.90k

40

14 min

49.80k

80

26 min

99.60k

SafeScanPolicy

API count

Execution time

Tests generated

10

1 min

300

20

1.2 min

600

40

2 min

1.20k

80

2 min

2.40k

QuickScanPolicy

API count

Execution time

Tests generated

10

6 min

16.94k

20

11 min

33.88k

40

20 min

67.74k

80

38 min

135.52k

PciDssScanPolicy

API count

Execution time

Tests generated

10

8 min

25.92k

20

13 min

49.13k

40

23 min

96.11k

80

40 min

176.04k

OwaspTopTenScanPolicy

API count

Execution time

Tests generated

10

7 min

27.32k

20

13 min

50.87k

40

23 min

100.59k

80

41 min

191.96k

WeeklyScanPolicy

API count

Execution time

Tests generated

10

7 min

29.28k

20

13 min

58.55k

40

24 min

117.10k

75

45 min

219.57k

ExtensiveScanPolicy

API count

Execution time

Tests generated

10

16 min

100.61k

20

35 min

208.30k

40

1 hr 12 min

424.29k

80

2 hr 16 min

850.01k

DAST scan

The following tables show the performance results of 8 predefined policies for DAST scans:

PipelineScanPolicy

API count

Execution time

Tests generated

10

48s

88

20

1 min

174

40

1 min

344

80

1 min 22s

684

DailyScanPolicy

API count

Execution time

Tests generated

10

4 min 35s

1.69k

20

9 min 4s

3.39k

40

16 min 21s

6.75k

80

32 min 10s

13.48k

SafeScanPolicy

API count

Execution time

Tests generated

10

1 min

300

20

58s

600

40

1 min 10s

1.20k

80

1 min 29s

2.40k

QuickScanPolicy

API count

Execution time

Tests generated

10

6 min 43s

2.44k

20

11 min 15s

4.86k

40

23 min 8s

9.72k

80

43 min 45s

19.41k

PciDssScanPolicy

API count

Execution time

Tests generated

10

8 min 53s

3.88k

20

17 min 19s

7.72k

40

24 min 56s

13.39k

80

1 hr 11 min 17s

31.01k

OwaspTopTenScanPolicy

API count

Execution time

Tests generated

10

9 min 46s

4.04k

20

14 min 41s

7.06k

40

25 min 51s

13.99k

80

1 hr 17 min 45s

32.14k

WeeklyScanPolicy

API count

Execution time

Tests generated

10

14 min 52s

5.15k

20

26 min 43s

10.28k

40

43 min 10s

18.48k

75

1 hr 49 min 16s

41.09k

ExtensiveScanPolicy

API count

Execution time

Tests generated

10

33 min 52s

14.88k

20

55 min 29s

26.00k

40

1 hr 54 min 18s

54.69k