Every product is an API
Mobile banking, card controls, account aggregation, instant transfers, onboarding with document capture: all of it is a public API with authorization logic per customer, per account and per consent. Broken object-level authorization is the finding that turns a bug into a data breach.