Runtime Application Self-Protection

ekGuard

A software development kit that embeds inside the banking app and monitors the device and runtime environment in real time. When a threat is detected, the session is suspended automatically — before any fraudulent action can complete. Live at UAE’s 3rd largest bank.
What Happens When a Threat Is Detected

Automatic Response

The SDK suspends the banking session automatically — before the fraudster can act. The customer sees a generic security prompt. The bank’s fraud team receives an alert. No human decision is required in real time. No customer data is exfiltrated. The threat is neutralised at the point of detection.

CBUAE Notice 3057

Regulatory Alignment

Explicitly requires that banking sessions be suspended when malware or screen-sharing is detected. The RASP SDK implements this requirement precisely. Banks deploying RASP SDK are compliant with this mandate. Banks that do not deploy a runtime protection solution are not.

What RASP SDK Detects

Device-level threats

Rooted and jailbroken devices — manufacturer security removed; banking app protection undermined

Emulators and device farms — industrial-scale account takeover attempts blocked at the device level

Remote access tools (RATs) — fraudsters controlling the device in real time, invisibly to the customer

Banking malware and trojans — credential theft and OTP interception at the device level

App-level threats

Overlay attacks — fake screens placed on top of the banking app to steal credentials

App tampering and reverse engineering — security controls stripped, vulnerabilities exposed

Runtime injection — transaction values or account numbers altered mid-session

Screen capture and screenshot attacks — session data exfiltrated without the customer’s knowledge

Fake and repackaged banking apps — counterfeit apps distributed to harvest credentials at scale

Integration Notes

Integration

The RASP SDK is distributed as a native library for iOS and Android. It embeds directly into the banking app as part of the build process — no server-side changes required. Typical deployment timeline: 4–6 weeks. Integrates with ekShield for automatic session suspension on malware detection.

Live Deployment

Proven in Production

RASP SDK is live at UAE’s 3rd largest bank, protecting the mobile and online banking experience for 2M+ digital customers. Ektar continues to expand threat detection capabilities in active collaboration with this anchor client.

Get Started Today

Talk to us about ekGuard

This page explains the problem, what the regulation requires, and how Ektar solves it.

Contact Us

If you have any questions we would love to hear from you. You can contact us by filling out the form below.

Join Us