ASX AppsGraphQL Security Gateway

The GraphQL Security Gateway

Rainbow app logo

Rainbow.

Simple. Secure. Powerful.

Put Rainbow in front of any GraphQL API. It understands the request, protects the origin, enforces policy and shows you exactly how the API is being used.

One container. One upstream.

Works with the GraphQL API you already have.

No schema rewrite and no resolver changes to get started. Rainbow is designed to sit in front of APIs built with Django, Strawberry, Graphene, Apollo Server, Yoga, Hasura or another GraphQL server.

ClientApp / service
RainbowAnalyse · classify · protect · observe
OriginGraphQL API
upstream: https://api.internal/graphql
schema: ./schema.graphql
mode: protect   command: rainbow start

The product promise

Secure any GraphQL API.

GraphQL is expressive by design. One HTTP request can ask for deeply nested data, repeat fields through aliases, fan out across large lists or request work that is expensive for the origin. A conventional gateway sees a request to POST /graphql. Rainbow is designed to understand the operation inside it before that operation reaches your server.

01 · Simple

One container. One upstream.

Put it in front of an existing API and start in observe mode. Keep your current GraphQL framework and application architecture.

02 · Secure

GraphQL-aware protection.

Evaluate operations, fields, arguments, identity and cost together. Apply controls before a costly or disallowed operation reaches the origin.

03 · Powerful

See what the API is doing.

Understand operations, fields, clients, schemas, performance, errors and blocked traffic rather than counting requests to one endpoint.

Three engines

A request, understood in context.

Rainbow combines the network request with the GraphQL operation and the schema it runs against. That context turns generic gateway rules into controls that reflect what a request actually asks the API to do.

Traffic

HTTP, TLS, client, IP address, identity and headers: who is connecting, from where and under what transport conditions.

GraphQL

Operation, fields, arguments, fragments, aliases, depth, breadth and complexity: what the client is asking the API to do.

Schema

Type relationships, field sensitivity, expected cost, permissions and historical behaviour: what those requested fields mean in this API.

Rainbow Shield · security engine

See the shape of abuse.

Rainbow Shield is the GraphQL-native protection layer. It inspects request structure alongside conventional gateway signals, so policy can respond to the work a request implies.

GraphQL-specific abuse

  • Depth and breadth attacks
  • Alias, fragment and batch amplification
  • Huge variable payloads and malformed GraphQL
  • Query complexity and list/cardinality amplification
  • Introspection and field enumeration
  • Expensive or repeated mutations
  • Abnormal operation shapes
  • Abusive subscriptions
  • Excessive response size

Gateway controls

  • JWT validation, OIDC and JWKS
  • API keys and IP filtering
  • CORS and header policy
  • Request size and timeouts
  • Circuit breakers and retries
  • TLS and mutual TLS
  • Conventional rate limiting

A GraphQL-native budget

Count the work, not just the requests.

Request counts treat every operation as equal. Rainbow's cost model estimates the work in an operation, including field weights and list size, so a budget can reflect what the API is being asked to do.

50,000 GraphQL cost units / minute / consumer

100 cheap viewer queries, but 3 fullAccountHistory operations / minute

Query.customer.transactions costs 20 × requested page size

The dashboard brings together operation volume, p95 latency, average cost, depth, field count, list amplification and risk. For example, a high-cost account history operation can show its observed latency and a recommendation to limit anonymous clients while allowing a higher budget to an internal support role.

Illustrative dashboard · sample figures

Observe → Learn → Protect

Start without guessing the limits.

Teams rarely know the right depth, cost or alias limits on day one. Rainbow is designed to begin in observe mode, learn normal traffic and prepare a policy people can review before protection is enabled.

Step 1

Observe

Learn normal operation shapes, clients, fields and cost ranges without blocking requests.

Step 2

Learn

Surface unusual patterns and prepare recommendations from observed use.

Step 3

Protect

Review the recommended policy, make adjustments and enable enforcement when ready.

Example after an observation period

Typical query depth
2–7 · 99.9th percentile 9

Fields per operation
3–62

Observed operation cost
1–210

Known clients / operations
14 / 187

A reviewable policy might recommend

  • Maximum depth: 12
  • Maximum aliases: 20
  • Maximum batch size: 5
  • Anonymous maximum cost: 150
  • Authenticated maximum cost: 500
  • Block introspection except CI and internal networks
  • Require trusted documents for mobile production

Illustrative sample only

GraphQL analytics

Know what is happening inside the endpoint.

A count of requests to POST /graphql says little about what is happening. Rainbow's analytics are organized around the parts of the graph that teams operate and change.

Operations
Fields
Consumers
Schemas
Errors
Performance
Cost
Security
  • Which fields are actually used, and by whom?
  • Who still calls a deprecated field?
  • Which operation became slower this week?
  • Which mobile version still queries legacyCustomer?
  • Which client accounts for the most API cost?
  • Which fields are most expensive?
  • Which operations are being blocked?
  • What changed after a schema release?
  • Which publicly reachable fields have no legitimate use?

Operation fingerprints can connect repeated requests to the same logical operation and help analytics stay useful even when request variables differ. The longer-term direction includes historical field usage, schema history, deprecation insight, security recommendations and change impact.

Schema Firewall

Add policy without changing your application schema.

Rainbow loads the GraphQL schema and pairs it with security metadata. Teams can declare field sensitivity, roles or cost limits in SDL or in a separate policy file. The gateway evaluates those rules before forwarding an operation.

type Customer {
  id: ID!
  name: String!

  bankAccount: BankAccount!
    @rainbow(role: "finance")

  nationalInsuranceNumber: String
    @rainbow(
      sensitive: true
      roles: ["support-tier-3"]
    )
}
fields:
  Customer.bankAccount:
    roles:
      - finance
  Customer.nationalInsuranceNumber:
    sensitive: true
    roles:
      - support-tier-3
  Query.search:
    max_cost: 100

A second boundary, not a replacement for authorization. Rainbow's gateway policy can reject disallowed operations before they reach the GraphQL server. Applications still need their own resolver-level authorization and data-access checks.

Proposed architecture

The data plane keeps working on its own.

The gateway keeps serving the customer's API if Rainbow's cloud control plane is unavailable or the customer's network is offline. Configuration and analytics can sync when possible; request handling stays close to the API.

Rainbow Control · optional cloud

Dashboard · policy · analytics · schema history · fleet configuration

Rainbow Edge

Gateway · policy · proxy

Rainbow Edge

Gateway · policy · proxy

Rainbow Edge

Gateway · policy · proxy

GraphQL API
GraphQL API
GraphQL API

Private by design

Local configuration and a self-hosted data plane are core to the direction. A private control plane and air-gapped deployment are enterprise roadmap options.

A focused gateway core

The gateway core is designed around predictable memory use, low latency, concurrency, streaming and WebSockets. Rust and Cloudflare's Pingora provide a strong foundation for a fast, reliable proxy layer.

Rainbow 1.0

From gateway to security platform.

Rainbow 1.0 brings together a fast, self-hosted GraphQL gateway and the security platform around it: request protection, operation analytics, schema intelligence and fleet-wide policy.

Rainbow 1.0

A complete GraphQL security platform

Gateway and GraphQL

  • GraphQL reverse proxy
  • Schema loading and introspection
  • Parsing and validation
  • Depth, breadth, alias and batch limits
  • Complexity and cost engine
  • Introspection controls
  • Trusted operations
  • Request and response limits

Identity and visibility

  • JWT / JWKS authentication
  • Per-client rate limiting
  • Per-operation cost limiting
  • Operation fingerprints
  • Prometheus metrics
  • OpenTelemetry
  • Observe and Protect modes

From gateway to security platform

  • Automatic policy recommendations
  • Schema drift detection and history
  • Field usage and deprecation intelligence
  • Cost budgets and field-level policy
  • Attack and anomaly detection
  • Sensitive-field labelling
  • Multiple GraphQL APIs and environments
  • Central policy control and audit trail
  • Subscriptions and distributed rate limits
  • Redis-backed counters and persisted queries
  • High-availability Helm deployment
  • AWS Marketplace distribution

Business model

Enterprise licensing. Flexible deployment.

Rainbow pairs a high-performance gateway with cloud analytics, policy management and fleet controls. Licensing is based on GraphQL operations analysed rather than gateway instances, so scaling out for redundancy does not increase the bill by itself.

Rainbow Cloud · paid

Operate together

Analytics, historical data, policy management, operation registry, security recommendations, multiple environments and team features.

Enterprise licensing

Control at scale

SSO / SAML, audit, advanced RBAC, private control plane, air-gapped use, support, compliance features and fleet management.

Indicative pricing

Cloud Developer£49–99 / month

Team£299–499 / month

Business£999+ / month

EnterpriseAnnual contract

The direction is generous operation allowances and a dramatically simpler entry point than buying a broad API security platform just to protect a GraphQL endpoint.

Deployment and licensing

Deploy with Docker or Helm. Enterprise licensing is available through Rainbow Cloud or AWS Marketplace, with ECS, EKS or Fargate container pricing, custom metering or contract licensing.

A clear first boundary

Rainbow focuses on securing GraphQL. No federation engine, schema composition, developer portal, GraphQL server, API monetisation, REST transformation or gateway, service mesh, AI gateway, database connectors or replacement for Cloudflare / AWS WAF in the initial product.

Positioning

A fragmented market leaves room for focus.

The GraphQL security market spans federation and graph lifecycle platforms, general API gateways adding GraphQL controls, traditional WAFs that may only partially parse GraphQL, and GraphQL-native security products.

Rainbow takes a focused position: it sits in front of an existing GraphQL API, understands the operation before forwarding it, and brings protection, cost policy and operation-level analytics together without requiring federation or a new application framework.

“Rainbow shouldn't make you configure GraphQL security. It should watch your traffic, understand it, and show you what safe looks like.”

Observe. Review the recommendation. Enable protection.

Rainbow · ASX Apps

Understand GraphQL. Protect what matters.

Rainbow is a focused, self-hosted GraphQL security gateway that brings operation awareness, cost controls and observability to existing APIs. Its traffic, operation and schema understanding creates a foundation for a broader GraphQL security platform.

Back to ASX Apps