API authentication, rate limiting, input validation, CORS policies, and automated security testing for REST/GraphQL.