Empower your mobile app to operate safely in untrusted environments without interrupting the end-user experience
Strengthen your app’s resistance to intrusion, tampering, reverse-engineering, and malware.
Serve more customers – even on jailbroken or rooted devices – while reducing risk.
Automate app shielding via integrations with your dev teams’ favorite CI/CD tools.
Fortify your app against the latest mobile threats without hindering deployment frequency or speed.
Add strong data protection controls to support compliance with regulations such as PSD2, GDPR, and more.
Financial institutions trust OneSpan to detect and mitigate even the most sophisticated attacks
OneSpan Mobile Security Suite proactively manages the real threat of sophisticated malware with app shielding and runtime application self-protection (RASP) to effectively detect and stop malicious activities before they do damage.
Protect users from the latest mobile threats without getting in the way
Financial institutions lack visibility into the security status of their customers’ mobile devices. The OneSpan application shielding solution protects a mobile banking app from the inside out. It allows the app to securely operate even in potentially hostile environments, such as jailbroken or rooted iOS and Android devices – and only deny service when absolutely necessary.
Embed multi-layered application security to thwart malware and impede malicious actors
Insulate your mobile app against more mobile threats and make integration easier with OneSpan App Shielding.
Thwart mobile banking Trojans that use overlay attacks, keyloggers, screenreaders, code injection, and other techniques. Detect and react to tools used by attackers, such as:
Demonstrate due diligence in mitigating mobile threats with rigorous security
On-the-fly mobile app security to accommodate even the most demanding release schedules
Some of the largest banks and financial institutions in the world count on OneSpan App Shielding to meet their rigorous mobile app security requirements without slowing their app releases.
Whether a team of developers deploys two or hundreds of mobile apps, studies show that building mobile app protection into the app development process is a challenge for providers.
Learn how OneSpan App Shielding can apply the most advanced security available to every mobile app release in mere minutes.
Easily plug in application shielding to your DevOps pipeline
We have mobile app security controls and policies into your DevOps practices (i.e., DevSecOps) with automation to accelerate app delivery through integrations with Jenkins, Gradle, and other popular tools that automate and accelerate app building, testing, and deployment.
Mobile Application Shielding Features
Next-generation Code Obfuscation
Binary code protection performed post-compile, making it extremely difficult for attackers to exploit application code via reverse-engineering.
Repackaging Prevention
Detecting whether an attacker or hacker has duplicated the app source code and injected malicious functionality into it. If repackaging is detected, application shielding will render the corrupted app inoperable.
Secure Local Storage
Encrypt and obfuscate encryption keys and secrets such as dynamic API keys within the app. The fully self-contained, independent of platform protections and whitebox-backed secure local storage adds an extra layer of security and protect PII, session tokens and keys even on jailbroken or rooted devices.
Secure Application ROM
Keep your fixed app secrets such as fixed static API keys and certificates safe. Data will only be decrypted when used by the application.
Anti-keylogging and Screen-reading
Mobile banking Trojans and other malware will attempt to log a user’s keystrokes or steal information displayed on app screens. If application shielding detects such activity, it can react in real time to interrupt it.
A Variety of Real-time Responses
App shielding reactions are configurable and can include blocking the execution of injected code, alerting administrators, feeding fraud prevention tools, or terminating the app.
Visibility for furtner analysis
Application shielding provides contextual data about the security status of the client side that fraud prevention tools can ingest and combine with other inputs to make better risk decisions about a transaction, login or other user action. This results in an optimal user experience without compromising the security.
Overlay Detection and Prevention
Mobile banking Trojans will overlay apps with a malicious window, mimicking a legitimate log-in screen to steal banking credentials. By detecting that the shielded app has been pushed to the background, app shielding can terminate the app before theft can occur.
Jailbreaking/Root Detection
Jailbreaking or rooting a device disables default security controls within iOS and Android. Advanced jailbreak/root detection offers visibility that can help in risk decisions rather than denying service outright.
Debugger and Emulator Detection
Detecting and blocking debuggers, emulators, and other tools leveraged by malicious actors in their attempts to exploit a mobile app further mitigates the risks of reverse-engineering or interference with a mobile app as it executes.
Hooking Detection and Interception
By detecting and countering malware with hooking capabilities or hooking frameworks, such as Frida, app shielding maintains a tamper-resistant runtime and terminates the app before hooking can occur.