EktarDevice & app securedBook a demo

ekProtect · Protect the Device & App

Attest the device. Read the behaviour. Kill the session.

ekProtect embeds in the banking app. It attests device and app integrity, detects overlay attacks, malware, rooted devices, and remote access tools in real time, and suspends the session automatically when a threat is found. Every signal feeds into your risk decisioning — your existing system, or ekRules.

ekProtect · runtime stateIllustrative

→ Feeding ekRules

App & device attestationPass
Overlay attackBlocked
Remote access toolSuspended
Rooted deviceDenied
Every detection here is sent to ekRules, alongside the user and device surfaces.
Capabilities

What ekProtect detects and stops

01

Device & app attestation

Confirms the app is genuine and unmodified, and the device is in a state the bank can trust.

02

Overlay attacks & basic malware detection

Detects fake screens drawn over the real app and flags malicious code running alongside it, from inside the app itself.

03

Rooted and jailbroken devices

Compromised operating systems are identified before a session is trusted.

04

Remote access tools (RATs)

Detects sessions being driven remotely while the customer watches.

05

Automatic session suspension

When a threat is found the session is suspended automatically — no manual review in the path.

Full malware tracking, elimination, and behavioural analysis run on ekPulse — see how →

Feeding the decision

One signal, wherever your decisioning lives

ekProtect's device and app signals feed straight into your risk decisioning — plugging into the fraud and risk system you already run, or into ekRules if you'd rather bring every layer under one engine.

Inputs

User, device, and app signals

Every layer the bank deploys.

Output

One real-time decision, made by your risk engine — existing system or ekRules

Decisioned in the transaction path, not after the fact.

See ekProtect catch a live threat.