/ 2 0 2 5 5 The security and dependability of cloud services depend on safeguarding the API. Weak interfaces and API security issues can threaten confidentiality, integrity, availability, and accountability. APIs are often the most vulnerable part of the system, usually accessible through the public Internet. Threat modelling for applications and systems is vital in the Software Development Life Cycle (SDLC). Conduct security-oriented code reviews, security scans, and penetration testing.