LCode Technologies
APP SECURITY

D-Secure Mobile App Security

Comprehensive mobile application security spanning binary, network, transport, authentication, and storage layers.

An advanced mobile app security suite designed to protect application binaries, secure network connections, encrypt transport layers, and ensure secure authentication and storage.

D-Secure Mobile App Security

D-Secure Mobile App Security

Code

Tampering

Jailbreak

Detection

End-to-end

Encryption

SSL

Pinning

OVERVIEW

What is D-Secure Mobile App Security?

D-Secure is LCode Technologies' mobile app security suite for banking apps. It provides runtime application self-protection (RASP) across five layers: application binary (code tampering, reverse engineering, jailbreak, root and debugger detection), network connectivity (SSL pinning, compromised Wi-Fi detection), transport (end-to-end encryption, MITM and replay attack handling), authentication and secure storage.

LaunchedPart of LCode's 2018–2025 releases (Mobile RASP)

Who it's for

  • Banks and financial institutions running customer-facing mobile banking apps
  • Teams that need protection against tampering, rooted or jailbroken devices and man-in-the-middle attacks

CAPABILITIES

What D-Secure Mobile App Security can do

01

Code tampering access control & Analysis and Reverse Engineering prevention

02

Jailbreak and Debugger Detection Controls

03

Compromised device and Wi-Fi network detection

04

Root Access and Remote Access controls

05

Malware infections detection & Third party libraries validation

06

Device binding and Session handling

MODULES & APIS

01

Code tampering access control

02

Analysis and Reverse Engineering

03

Jailbreak Detection Controls

04

Debugger Detection Controls

05

Certificate Pinning Controls

06

Session handling

07

Apps downloaded from third-party sources

08

Third party libraries validation

09

Compromised device security

10

Potentially dangerous Android apps validation

11

Root Access controls

12

Malware infections detection

13

Remote Access controls

14

Device binding

KEY FACTS

D-Secure Mobile App Security at a glance

Key facts about D-Secure Mobile App Security
SpecificationDetail
Security layersApplication binary, network connectivity, transport, authentication, storage
Device checksJailbreak, root, debugger, malware, compromised device, remote access
NetworkSSL / certificate pinning, compromised Wi-Fi detection
TransportEnd-to-end encryption, MITM and replay attack handling
Device bindingYes, with session handling
LaunchedPart of LCode's 2018–2025 releases (Mobile RASP)
LCode company certificationsISO 9001:2015 · ISO 27001:2022 · PCI SLC (Secure Software Lifecycle)

COMPARISONS

D-Secure Mobile App Security: comparisons and reference tables

D-Secure security layers mapped to OWASP Mobile Top 10 (2024)
D-Secure layerD-Secure controlsOWASP Mobile Top 10 (2024) risk addressed
Application binary securityCode tampering access control; analysis and reverse engineering; jailbreak, root and debugger detection; malware infection detection; apps from third-party sources; compromised device securityM7: Insufficient Binary Protections [1]
Application binary security (libraries)Third-party libraries validationM2: Inadequate Supply Chain Security [1]
Network connectivity securityEndpoint verification with SSL pinning; compromised Wi-Fi network detectionM5: Insecure Communication [1]
Transport layer securityCryptography; end-to-end encryption; MITM handling; replay attack handlingM5: Insecure Communication; M10: Insufficient Cryptography [1]
Application authentication securitySecure authentication; cryptography (encryption/decryption)M3: Insecure Authentication/Authorization; M10: Insufficient Cryptography [1]
Storage layer securitySecure data storage; encryption in transfer of dataM9: Insecure Data Storage [1]

The mapping shows which OWASP risk category each D-Secure layer is designed to address. It is not an OWASP certification or a claim of complete coverage. Numbers in brackets refer to the sources at the end of this page.

FAQ

D-Secure Mobile App Security: frequently asked questions

What does D-Secure protect a mobile banking app against?

D-Secure covers code tampering, reverse engineering, jailbroken and rooted devices, debuggers, remote access, malware infections, apps downloaded from third-party sources, potentially dangerous Android apps, compromised devices and Wi-Fi networks, and man-in-the-middle (MITM) and replay attacks.

Does D-Secure support SSL or certificate pinning?

Yes. D-Secure includes certificate pinning controls in its application binary layer and endpoint verification through SSL pinning in its network connectivity layer.

How does D-Secure protect data in transit and at rest?

The transport layer applies cryptography, end-to-end encryption and MITM and replay attack handling. The storage layer provides secure data storage and encryption of data in transfer.

Does D-Secure bind the app to a customer's device?

Yes. Device binding and session handling are part of D-Secure's application binary security controls.

What is RASP?

Runtime application self-protection (RASP) is security built into an app that detects and responds to attacks while the app runs. The OWASP Mobile Application Security Verification Standard (MASVS) lists RASP, alongside obfuscation, anti-debugging and anti-tampering, as a defence-in-depth measure against reverse engineering and client-side attacks.

Which OWASP Mobile Top 10 risks do D-Secure's layers address?

Mapped to the OWASP Mobile Top 10 (2024): application binary security addresses M7 (Insufficient Binary Protections), and its third-party library validation relates to M2 (Inadequate Supply Chain Security); network connectivity and transport security address M5 (Insecure Communication); transport and authentication cryptography relate to M10 (Insufficient Cryptography); authentication security addresses M3 (Insecure Authentication/Authorization); and storage security addresses M9 (Insecure Data Storage).

FURTHER READING

Learn the concepts behind D-Secure Mobile App Security

GuideMobile banking app security and RASP explainedRead the guide →

REFERENCES

Sources cited on this page

  1. OWASP Mobile Top 10 2024: Final Release, OWASP Foundation
  2. MASVS-RESILIENCE: Resilience Against Reverse Engineering and Tampering, OWASP Mobile Application Security (MAS) project