EktarLayer 02 securedBook a demo

Layer 02 — App & Device Protection · ekProtect

Attest the device. Read the behaviour. Kill the session.

ekProtect embeds in the banking app. It attests device and app integrity, detects malware, overlay attacks, rooted devices, and remote access tools in real time, and suspends the session automatically when a threat is found. Behavioural analysis distinguishes legitimate users from malware at runtime, and ML-driven per-transaction risk decisioning turns signals from every layer into a real-time risk score. CBUAE-mandated.

ekProtect · runtime stateIllustrative
12Session risk score
App & device attestationPass
Overlay attackBlocked
Remote access toolSuspended
Rooted deviceDenied
Signals from every layer feed one score, per transaction
DetectsMalware · Overlays · Root · RATs
ResponseAutomatic session suspension
MandateCBUAE
Attestation & detection

What ekProtect detects and stops

01

Device & app attestation

Confirms the app is genuine and unmodified, and the device is in a state the bank can trust.

02

Malware and overlay attacks

Detects injection and fake screens drawn over the real app, from inside the app itself.

03

Rooted and jailbroken devices

Compromised operating systems are identified before a session is trusted.

04

Remote access tools (RATs)

Detects sessions being driven remotely while the customer watches.

05

Automatic session suspension

When a threat is found the session is suspended automatically — no manual review in the path.

06

Behavioural analysis at runtime

Distinguishes legitimate users from malware by how the session behaves, not just what it declares.

Risk decisioning

One risk score, per transaction.

ML-driven per-transaction risk decisioning ingests signals from every security layer — authentication, device, and document — and returns a real-time risk score the bank can act on.

Inputs

Authentication, device, and document signals

Every layer a bank deploys makes the score more accurate.

Output

A real-time score, per transaction

Decisioned in the transaction path, not after the fact.

See ekProtect catch a live threat.