DIGITAL SECURITY FOR BANKING
Digital Security Engineered for Banking Channels
Authentication
App & Device Protection
Document Fraud Prevention
THE PROBLEM
Banking fraud has changed. Most defences haven't.
When customers log into their banking app, they expect branch-level security. But mobile apps, internet banking portals, and payment APIs have created a fundamentally different attack surface — one that fraudsters can probe from anywhere, at scale, and at near-zero cost. The tools most banks rely on were built for a different era. The threat has moved on.
~$485B
Banking Fraud Losses (2023)
+1,210%
AI-Enabled Fraud (2025)
93%
Still Using SMS OTP
SOLUTIONS
Three security challenges. Three proven solutions.
Every solution addresses a distinct layer of fraud risk in banking’s digital channels. They work independently — and share a common signal layer that makes each one more accurate when deployed together.
Authentication
Replace SMS OTP with phishing-resistant, device-bound authentication across every channel — mobile, web, call centre, ATM, and 3DS. Compliant with CBUAE, RBI, SAMA, BSP, and MAS mandates.
App & Device Protection
Document Fraud Prevention
OUR PRODUCTS
The Products that Power Each Solution.
ekShield
ekVerify
ekSell
RASP SDK
Fraud & Risk Engine
Regulatory Tailwinds
Regulators are ordering the upgrade.
cross the GCC, South Asia, and Southeast Asia, regulators have banned SMS OTP, mandated passkeys, and required real-time malware detection. Every bank in these markets needs what Ektar builds — and many have a hard deadline to decide.
-
Saudi Arabia — SAMA Counter-Fraud Framework
FIDO2 device-bound credentials mandated. Real-time fraud monitoring required. Penalties up to SAR 5M per breach.
-
UAE — CBUAE Notice 3057
SMS OTP and email OTP banned. In-app verification, passkeys, and biometrics mandated. Real-time malware session suspension required.
-
Singapore — MAS/ABS Directive
SMS OTP phased out for all retail bank digital token users.
-
India — RBI Authentication Directions 2025
Sole reliance on SMS OTP banned for high-risk transactions. Real-time risk-based authentication mandatory per transaction.
-
Malaysia — BNM RMiT 2026
Device binding, adaptive MFA, and risk-based authentication mandated for all licensed banks.
-
Philippines — BSP Circular 1213
Direct prohibition on SMS/email OTP for high-risk banking transactions.
AI AT EKTAR
AI is not just in our products. It's in how we build them.
AI in our products
ekVerify uses AI-assisted fraud pattern detection. RASP SDK uses behavioural analysis to distinguish legitimate users from malware at runtime. The Fraud & Risk Engine will be ML-driven at its core — per-transaction risk decisioning across all signal layers.
AI in how we build
Our engineering teams use AI-assisted development practices to accelerate delivery and maintain high code quality — with human engineers accountable for every design decision, security control, and integration point.
OUR STORY
We think like bankers. We build like technologists.
Ektar was founded in 2022 by three experienced ex-bankers. We build digital security solutions for banking’s digital channels — and we have lived inside the institutions we now serve, which means we understand the operational constraints, compliance requirements, and procurement realities that shape how banks actually adopt technology.
Our products are live. Our clients are some of the largest banks in the region. Our roadmap is defined by where the fraud threat and the regulatory landscape are going next.
Our Vision
To make banking safer, smarter, and more trustworthy — for every bank, every channel, and every customer — until trust is no longer something people hope for, but something they simply expect from the banks they rely on each and every day.
Our Mission
We build digital security products that close the three layers of vulnerability in banking’s digital channels — protecting every device, every app, and every user interaction — so banks can serve their customers with confidence.