EktarSystems liveBook a demo
DeployedUAE's 3rd largest bank
ContractedOman's 3rd largest bank
Aligned withCBUAE · RBI · SAMA · FIDO Member
The attack surface

Six ways into a banking app. Ektar closes all six.

Mobile apps, internet banking portals, and payment APIs created an attack surface fraudsters can probe from anywhere, at scale, at near-zero cost. These are the vectors we shut down.

SMS OTP interception

The most exploited authentication method — banned or restricted in five markets.

Closed by ekShield & ekBind

Overlay attacks

A fake screen drawn over the real app captures credentials in place.

Closed by ekProtect

Rooted devices & RATs

Remote access tools drive the session while the customer watches.

Closed by ekProtect

Malware in the app

Runtime injection and tampering inside an otherwise trusted app.

Closed by ekProtect

Forged documents

Salary certificates, statements and letters altered after issuance.

Closed by ekSign

Deepfakes & synthetic IDs

AI-generated identities and documents — up 1,210% in 2025.

Closed by Closed across all three layers

The three layers

Three security challenges. Three proven solutions.

Every solution addresses a distinct layer of fraud risk in banking's digital channels. They work independently and share a common signal layer that makes each one more accurate when deployed together.

Layer 01ekShield · ekBind

Device-bound authentication, bound to a verified SIM

Replace SMS OTP with phishing-resistant, device-bound authentication across every channel — mobile, web, call centre, ATM, and 3DS. ekBind adds SIM binding via Silent Network Authentication and Reverse SMS, so a swapped SIM is caught before a transaction proceeds. Compliant with CBUAE, RBI, SAMA, BSP, and MAS mandates.

Open →

Layer 02ekProtect

Attestation, runtime defence and behavioural risk

Attest device and app integrity, detect malware, overlay attacks, rooted devices, and remote access tools — from inside the banking app — and suspend the session automatically when a threat is found. Behavioural analysis and ML-driven per-transaction risk decisioning turn every signal into a real-time score. CBUAE-mandated.

Open →

Layer 03ekSign

In-channel signing with cryptographic proof

Customers sign inside the banking app or on a bank-branded page, authenticated by the MFA they already use. Each signature is bound to a SHA-256 fingerprint of the document and chained across signatories, so any later alteration fails verification — and the bank keeps the record.

Open →

Shared signal layer

all three layers feed one signal layer — each product becomes more accurate with every other product a bank deploys.

Cryptographic proof

Signed at issuance. Verified in milliseconds.

Every document a bank issues is signed with an ECDSA key pair at the moment of creation. Alter one character and the signature no longer matches — tampering stops being a judgement call and becomes arithmetic.

SignIssuing system calls one API; ECDSA P-256 signature bound to the document's exact contents.
SealA QR seal carries the signature and verification endpoint; no change to the document workflow.
VerifyAny party scans the seal; authenticity returns in milliseconds — no login, no portal, no callback to the bank.

Salary certificate · signed

sha256 9c4e·f17b·a208·31dd
sig r/s 3f9a·c2e1

Signature valid
Our products

Five products. One signal layer.

Each can be deployed independently or as part of an integrated platform. All share a common signal layer that compounds in value with every product a bank deploys.

ekShield

Authentication

Device-bound, phishing-resistant authentication across mobile, web, call centre, ATM, and 3DS. White-labelled and live at UAE's 3rd largest bank.

Learn more →

ekProtect

Attest & behavioural risk

Embeds in the banking app. Attests device and app integrity, detects malware, overlays, rooted devices and RATs, suspends sessions on detection, and scores risk per transaction.

Learn more →

ekBind

SIM binding

SIM binding via Silent Network Authentication and Reverse SMS. Catches SIM swap, port-out, and device change before a transaction proceeds.

Learn more →

ekSign

Document integrity

In-channel signing authenticated by the bank's own MFA, plus ECDSA signing and a SHA-256 seal that makes tampering detectable. The bank owns the journey and the audit trail.

Learn more →

ekSell

Distribution

Connect banks to retail ecosystems — employers, fintechs, retailers — for cost-effective digital product distribution. Ektar's founding platform.

Learn more →
Regulatory tailwinds

Regulators are ordering the upgrade.

Across the GCC, South Asia, and Southeast Asia, regulators have banned SMS OTP, mandated passkeys, and required real-time malware detection. Every bank in these markets needs what Ektar builds — and many have a hard deadline to decide.

UAECBUAE Notice 3057. SMS OTP and email OTP banned. In-app verification, passkeys, and biometrics mandated. Real-time malware session suspension required.

Saudi ArabiaSAMA Counter-Fraud Framework. FIDO2 device-bound credentials mandated. Real-time fraud monitoring required. Penalties up to SAR 5M per breach.

IndiaRBI Authentication Directions 2025. Sole reliance on SMS OTP banned for high-risk transactions. Real-time risk-based authentication mandatory per transaction.

SingaporeMAS/ABS Directive. SMS OTP phased out for all retail bank digital token users.

PhilippinesBSP Circular 1213. Direct prohibition on SMS/email OTP for high-risk banking transactions.

MalaysiaBNM RMiT 2026. Device binding, adaptive MFA, and risk-based authentication mandated for all licensed banks.

The problem

Banking fraud has changed. Most defences haven't.

The tools most banks rely on were built for a different era. The threat has moved on.

Data / 01

~$485B

Banking fraud losses (2023)

Part of $1.03 trillion in total consumer scam losses globally. Card fraud alone: $33.4B.

Data / 02

+1,210%

AI-enabled fraud (2025)

Deepfakes, synthetic identities, AI-generated documents. Traditional defences cannot keep pace.

Data / 03

93%

Still using SMS OTP

The most exploited authentication method — now banned or restricted across UAE, India, Saudi Arabia, Philippines, and Singapore.

Every bank in these markets has a deadline. Let's talk about yours.