- Confirm all API data is validated through a proper external function. - Confirm X.509 certificates are thoroughly validated (valid for the domain, CA signed & trusted, not expired, not revoked) for remote APIs.