-

Approov Integration and Alliance Partner Program Secures APIs for Unified, End-to-End Protection of Mobile App User Data and Business Logic

Integrations with AWS, Microsoft Azure, Cloudflare, Fortinet, Kong, TIBCO, NGINX, FingerprintJS, hCaptcha, Google reCAPTCHA, Google SafetyNet, Apple DeviceCheck Help Secure Sensitive Data Against the “Achilles heel” of App Security presented by the use of mobile apps.

SAN JOSE, Calif. & EDINBURGH, Scotland--(BUSINESS WIRE)--Approov, creators of advanced API threat protection solutions, today introduced the Approov Alliance and Integration Program to ensure that the critical elements of comprehensive mobile app API protection are rigorously tested and work together harmoniously and seamlessly to avoid both data leakage and exposure of the app’s core logic.

"API security is critical to protecting the confidentiality, integrity, and availability of your data but today the market is fragmented and customers need products to work together to get the protection they need,” said Alissa Knight, partner of Knight Ink. “The mobile app and client attestation provided by Approov is a crucial element and the new alliance program gives customers assurance that it works seamlessly with other security solutions to protect APIs.”

Mobile apps, by their nature, expose a potential “Achilles heel” in application security. A mobile app and its APIs expose API Keys, business logic, and other data that can be used to successfully attack that API using a script or modified mobile app. The deployment of mobile apps can present a comprehensive “tool kit for hackers” who are targeting APIs. Even with extensive shift-left security initiatives in place, this ability to exploit APIs can never be completely eliminated and they must be shielded at run-time.

Approov’s approach blocks these and other mobile app attack vectors, such as Man-in-the-middle attacks. Approov blocks any access to the API from anything other than unmodified, genuine versions of the app, effectively preventing any vulnerabilities in an app or its API from being exploited, protecting both apps under development and apps in production.

The Approov Integration and Alliance Partner program ensures that each component in the application security ecosystem works seamlessly with Approov, in order to make it easy for customers to deploy a comprehensive solution for API security that optimizes user experience while thwarting malicious API access attempts. Approov invites vendors with complementary solutions to sign up here to the program.

Approov Technology Integrations :

Approov already has tried and tested integrations with a number of security vendors:

  • Identity and Access Management: Approov works with any products which support standards for authorization, authentication and identity management, such as OAuth2 and OpenID Connect (OIC).
  • WAF and API Management Gateways: Approov integrates easily with any backend environment: QuickStart guides are available for 10 commonly used environments. However, an emerging best practice is to unify security layers by having a single control point where application security policies are enforced. Approov supports this through integrations with back-end security platforms including Fortinet’s Fortiweb WAF, which allows Approov mobile attestation to be integrated into Fortiweb security rules. Similarly, Approov’s integration with API Gateways such as Kong, TIBCO/Mashery and NGINX PLUS, adds the Approov assurance that APIs can only be accessed by genuine instances of your mobile app.
  • Cloud Services: Integration of Approov with Amazon API Gateway and the Microsoft Azure API Management allows the Approov mobile app and client environment attestation checks to be enforced at the gateway to ensure comprehensive and consistent security for cloud-native APIs.
  • Browser based API access: It is a best-practice to isolate and have dedicated APIs to serve mobile apps in order to optimize performance and lock down access using app attestation and client validation. However, some mobile-first customers also allow browser-based access to the same APIs which service their mobile apps. To provide a single common validation method for mobile apps and browser-based access, Approov integrations include FingerprintJS, hCaptcha and reCaptcha. These solutions evaluate whether a browser access is by a human or a bot, and integration with Approov enables a single, common authorization method for both the web and mobile API channels in order to validate legitimate access.
  • Mobile development framework integration: Approov ensures ease of deployment through integration with Android native and iOS native app development frameworks, as well as major cross-platform frameworks such as Flutter, React Native, NativeScript, Ionic, Cordova, and Xamarin.
  • Client integrity: Apple DeviceCheck allows developers to set and track states on (anonymized) iOS devices and Google SafetyNet evaluates whether an android device has been rooted or otherwise compromised. Integration of both with Approov ensures that DeviceCheck and SafetyNet validation can be incorporated into the powerful security policy framework which is part of the Approov service. This provides granularity of control, consistency and simplicity of implementation across both platforms and ensures compromised device access can always be blocked without creating false negatives.

“As we have seen in recent high-profile breaches involving Peloton and Experian, threat actors are actively working to dissect mobile apps in order to mount successful attacks on APIs,” said Approov CEO David Stewart. “Approov integrations simplify mobile security for customers by ensuring that the required security capabilities for mobile can seamlessly be integrated with the other essential elements of a security solution, bringing an important new level of security to existing and future mobile applications.”

Approov recently launched Release 2.7 of the Approov API Shielding platform, enabling companies of all sizes to adopt leading-edge, affordable API cybersecurity protections for mobile-based applications, including production apps.

The Approov platform is deployed by connected car companies BMW and Sixt, the European eCommerce platform Deindeal, the healthcare app developer MV, the financial services platform Papara, and other security-minded organizations whose applications are a primary customer conduit.

About Approov

Approov solutions help stop API abuse at the edge, and prevent security breaches in mobile channels. With more businesses moving to digitalization and future-ready services that utilize mobile API connections, securing those connections properly can get overlooked or not fully implemented for all possible threats, exposing organizations and their users to breaches, fraud, denial of service, and other forms of API abuse.

Approov API Threat Protection provides a multi-factor, end-to-end mobile API security solution that complements identity management, endpoint, and device protection to lock-down proper API usage. It ensures that only safe and approved apps running in safe environments can successfully and securely access an organization’s APIs, and turns away unauthorized accesses by attacker scripting, bots and fake or tampered apps. https://www.approov.io/

Contacts

Dan Chmielewski
Madison Alexander PR, Inc.
714-832-8716
C: 949-231-2965
dchm@madisonalexanderpr.com

Approov


Release Summary
Approov Integration and Alliance Partner Program Secures APIs for Unified, End-to-End Protection of Mobile App User Data and Business Logic
Release Versions

Contacts

Dan Chmielewski
Madison Alexander PR, Inc.
714-832-8716
C: 949-231-2965
dchm@madisonalexanderpr.com

More News From Approov

Approov Turbocharges Global Security: Cloudflare Argo Smart Routing Halves Latency for Next-Gen Mobile Attestation

EDINBURGH, Scotland--(BUSINESS WIRE)--Approov, a leading provider of mobile app and API security solutions, today announced significant strategic expansion of its global network infrastructure, positioning its unique cloud-based mobile app and device attestation platform as the essential defense against rapidly evolving AI-based API threats. This expansion includes the deployment of Cloudflare's Argo Smart Routing technology across its multi-cloud network, which is supported by Amazon Web Servi...

Approov Launches Next Generation Attestation to Secure Mobile Apps Against Threats from AI and Meet New EU Regulations

EDINBURGH, Scotland--(BUSINESS WIRE)--Approov, the leader in mobile API security, today announced the launch of Approov 3.5, a significant platform update designed to protect businesses and their customers from a new wave of mobile threats. The release directly addresses security challenges posed by regulations like the EU’s Digital Markets Act (DMA) and the rise of sophisticated AI-driven attacks. The mobile landscape is changing dramatically. New rules are opening up app distribution beyond t...

Approov Closes £5M Series A Funding to Redefine Mobile App Security for the AI Era in Round Led by Maven Capital Partners

EDINBURGH, Scotland & PALO ALTO, Calif.--(BUSINESS WIRE)--Approov Limited, a leading innovator in mobile app and API security, has successfully closed a £5 million (US$ 6.7 million) Series A funding round. The investment, spearheaded by the Investment Fund for Scotland, managed by Maven Capital Partners (“Maven”), also saw participation from Souter Investments, and existing investors Lanza techVentures and Scottish Enterprise. This funding milestone enables Approov to bolster its Research &...
Back to Newsroom