SECURE SESSIONDLAB / SYSTEM BOOT
DLAB Distribution

Initialising secure environment

Secure connection Data integrity Ecosystem ready
ZERO TRUST ARCHITECTUREPROTECTED BY DESIGNDLAB DISTRIBUTION
Enterprise technology solutions across Southeast Asiasales@dlab-disti.com
← All solutions

Mobile App Runtime Protection

AuthKey MAPT

The agent detects. The backend decides. The app enforces.

AuthKey MAPT is a Mobile Application Protection Agent that brings SDK-first runtime application self-protection and zero-trust threat prevention to Android and iOS apps, with decoupled backend policy decisions and on-device enforcement.

The business challenge

Why organisations consider this solution.

Mobile apps operate on devices that may be rooted, jailbroken, instrumented, repackaged or connected through hostile networks. Static wrappers and client-only rules can be bypassed, create false positives and leave security teams without reliable runtime visibility.

Core capabilities

What AuthKey MAPT
helps you do.

01

Advanced RASP Engine

Detect emulators, root or jailbreak status, debugging, Frida instrumentation, runtime hooks, overlays and other hostile execution conditions.

02

Integrity & Anti-Tamper

Validate signing certificates, bundle or package identity, fingerprints and file hashes to identify modification, cloning and repackaging.

03

Hardware-Backed Attestation

Use Google Play Integrity and Apple App Attest signals to strengthen device and application trust decisions.

04

Decoupled Policy & Enforcement

Send signed risk evidence through protected communications to a backend policy engine, then return allow, monitor, step-up or block decisions for the app to enforce.

Reference architecture

See the actual
solution topology.

Embed a lightweight protection agent in the mobile app, collect tamper-resistant runtime evidence, let the backend select the policy response and enforce the decision on the device before a sensitive action completes. The diagram below shows the product's distinct operating model, data paths and enforcement or decision points.

Product-specific architectureAuthKey MAPT mobile protection architectureThe on-device agent detects, the backend decides and the mobile app enforces
Mobile app + MAPTSDK or no-code wrapperApp + device integrityRoot • tamper • signingRuntime signalsFrida • hooks • debuggerSecure evidenceHMAC + certificate pinningBackend risk engineVerify + score + policyHardware attestationPlay Integrity • App AttestRemote policyReport • warn • enforceDecision payloadAllow • monitor • step-up • blockApp enforcementBefore protected actionRisk signalsProtected transitPolicy decisionContinuous telemetry and remote response
Illustrative reference architecture — final design depends on the customer environment and vendor-supported integration pattern.

Example use cases

Apply the architecture
to a real scenario.

These examples explain the business purpose behind the architecture. Final scope, integrations and outcomes depend on your environment and implementation design.

01High-value transaction

Protect a RM10,000 mobile transfer

A banking app must confirm that the app, device, runtime and API channel remain trusted before releasing the transaction payload.

  1. 1Validate application signing and integrity
  2. 2Check device, runtime and network risk
  3. 3Ask the backend for an allow, step-up or block decision
Expected resultThe protected action proceeds only when the full mobile trust chain satisfies the current policy.
02App tampering

Stop a cloned or repackaged application

An attacker modifies the application package, injects tooling and re-signs it for distribution outside the legitimate channel.

  1. 1Compare signing, package and file-integrity evidence
  2. 2Report the tamper signals securely to the backend
  3. 3Return a policy decision and block the protected action
Expected resultA modified binary cannot continue sensitive operations merely by bypassing a local client check.
03Incident response

Tighten protection without an app release

A newly observed hooking technique requires stronger control, but waiting for an app-store update would leave customers exposed.

  1. 1Collect report-only telemetry to establish the baseline
  2. 2Change the backend action policy remotely
  3. 3Move selected actions to warning, step-up or block
Expected resultSecurity teams can respond quickly while keeping enforcement proportional to the affected action.

Delivery path

From requirement
to production value.

The exact architecture depends on your environment, but the solution typically follows this practical operating flow.

01

Integrate or wrap the app

Add MAPT through the Android, iOS or cross-platform SDK path, or use the no-code wrapping pipeline for an approved application binary.

02

Detect runtime risk

The on-device agent collects application integrity, device, runtime, network and hardware-attestation signals before a protected action completes.

03

Evaluate policy centrally

Signed telemetry is sent using HMAC and certificate pinning so the backend can verify evidence, calculate risk and select the current policy response.

04

Enforce and adapt

The app applies allow, monitor, step-up or block actions, while security teams can move from report-only baselining to full enforcement without relying on hard-coded client rules.

Typical use cases

Where it fits.

  • Protect high-value mobile banking transactions
  • Detect rooted, jailbroken or instrumented devices
  • Block cloned, modified or repackaged applications
  • Change runtime enforcement policy without an app update

Expected outcomes

What success looks like.

  • Continuous runtime protection for mobile apps
  • Backend-controlled decisions that are harder to bypass
  • Real-time mobile threat telemetry and reporting
  • Lower-friction staged enforcement and incident response

DLAB's role

Technology is only valuable
when it works in your environment.

DLAB helps customers evaluate the fit, define use cases, coordinate solution demonstrations and proofs of concept, plan deployment with the principal and local partners, and establish the support path for production.

Solution advisoryDemo & POCImplementation enablementRegional support
Arrange a solution workshop
Product information is based on the supplied AuthKey MAPT introduction and marketing materials dated 26 August 2026.Visit AuthKey MAPT official site