Advanced RASP Engine
Detect emulators, root or jailbreak status, debugging, Frida instrumentation, runtime hooks, overlays and other hostile execution conditions.

Initialising secure environment

Mobile App Runtime Protection
AuthKey MAPT is a Mobile Application Protection Agent that brings SDK-first runtime application self-protection and zero-trust threat prevention to Android and iOS apps, with decoupled backend policy decisions and on-device enforcement.
The business challenge
Mobile apps operate on devices that may be rooted, jailbroken, instrumented, repackaged or connected through hostile networks. Static wrappers and client-only rules can be bypassed, create false positives and leave security teams without reliable runtime visibility.
Core capabilities
Detect emulators, root or jailbreak status, debugging, Frida instrumentation, runtime hooks, overlays and other hostile execution conditions.
Validate signing certificates, bundle or package identity, fingerprints and file hashes to identify modification, cloning and repackaging.
Use Google Play Integrity and Apple App Attest signals to strengthen device and application trust decisions.
Send signed risk evidence through protected communications to a backend policy engine, then return allow, monitor, step-up or block decisions for the app to enforce.
Reference architecture
Embed a lightweight protection agent in the mobile app, collect tamper-resistant runtime evidence, let the backend select the policy response and enforce the decision on the device before a sensitive action completes. The diagram below shows the product's distinct operating model, data paths and enforcement or decision points.
Example use cases
These examples explain the business purpose behind the architecture. Final scope, integrations and outcomes depend on your environment and implementation design.
A banking app must confirm that the app, device, runtime and API channel remain trusted before releasing the transaction payload.
An attacker modifies the application package, injects tooling and re-signs it for distribution outside the legitimate channel.
A newly observed hooking technique requires stronger control, but waiting for an app-store update would leave customers exposed.
Delivery path
The exact architecture depends on your environment, but the solution typically follows this practical operating flow.
Add MAPT through the Android, iOS or cross-platform SDK path, or use the no-code wrapping pipeline for an approved application binary.
The on-device agent collects application integrity, device, runtime, network and hardware-attestation signals before a protected action completes.
Signed telemetry is sent using HMAC and certificate pinning so the backend can verify evidence, calculate risk and select the current policy response.
The app applies allow, monitor, step-up or block actions, while security teams can move from report-only baselining to full enforcement without relying on hard-coded client rules.
Typical use cases
Expected outcomes
DLAB's role
DLAB helps customers evaluate the fit, define use cases, coordinate solution demonstrations and proofs of concept, plan deployment with the principal and local partners, and establish the support path for production.
Arrange a solution workshop