Guardsquare Reports

Mobile Developer Protects Sensitive KYC Systems | Guardsquare

Written by Jason Cortlund - Technical Marketing Writer | Aug 4, 2026, 3:26:50 PM
Guardsquare secures partnerships with banking, finance, and government
COMPANY DETAILS
Industry

Software

Privately / Publicly Owned

Private

Employees

11-50

Customer Since

2025

Challenges

  • Phishing-assisted reverse engineering and tampering attacks on both their APK and SDK mobile app products for banks, financial services, and government clients
  • Malicious injection of falsified inputs (e.g. deepfaked video) to pass KYC image checks
  • Emulators to spoof behavioral checks for legitimate users/devices

Solutions

  • Core Platform (DexGuard for Android and iXGuard for iOS)

The Company

This technology developer based in Central Asia creates mobile solutions for Know Your Customer (KYC), optical character recognition (OCR), and anti-fraud systems. With customers in banking, finance, and government services, the organization currently serves more than 20 clients with between three and four million total end users. Their advanced KYC capabilities use artificial intelligence (AI) and machine learning (ML) for comparative facial recognition and liveness detection (i.e., is the system camera seeing a real live human customer versus a maliciously spoofed/deepfaked image feed). They offer these solutions as either a standalone mobile application or as an SDK that can be integrated within a customer’s mobile app.

 

The Challenge

Providing user verification for organizations in banking, insurance, retail, and government brings a high degree of risk. A successful fraud attack can lead to direct financial losses, theft of services, or exposure of private user information. The specific security challenges these developers were facing included:

  • Reverse engineering attacks to understand their code and analyze app functionality
  • Injection attacks that substitute falsified image or biometric inputs (e.g., “face spoofing” via a deep-faked video)
  • Emulator attacks that simulate the behavior of a legitimate mobile device or user

The company’s CEO explained, “First, we try to avoid reverse engineering. If bad guys figure out how our mobile app works, then they can make injections to get past our image verification checks.” The main source of attacks they were experiencing came from emulators that can automatically mimic responses from legitimate users and mobile devices.

“For us, security is a main priority because many banking clients rely on our solutions for onboarding. For example, if you want to open a new bank account or credit card, the institution uses our system to identify people.”

— CEO, Central Asian Mobile Solutions Developer

He also noted that threat actors would often combine these techniques with some form of sophisticated social engineering (like phishing messages) to help initiate or complete a fraud attack against their mobile app end users.

They had previously tried protecting their mobile apps with different free products for code obfuscation with inadequate results and no accountability from the security solution provider. As the CEO noted, “If it's free, then they're not responsible for anything.”

Another critical issue they were having was finding a security solution that could protect not only their APK products but also the SDK for their stand-alone mobile application. This is an important part of how they serve customers. As the company’s CEO explains, “For example, banks have their own applications and they use our SDK for onboarding new customers.” The highest level of mobile app security was essential for protecting these transactions and maintaining the trust of both their customers and end users.

“We have a special case where we needed obfuscation that would work for our SDKs, and we found a solution in Guardsquare.”

— CEO, Central Asian Mobile Solutions Developer

The Solution

The company’s implementation team started exploring best-of-breed mobile app security with specific focus on code obfuscation, encryption, and runtime protections. They soon narrowed their focus on Guardsquare based on the capabilities offered by DexGuard mobile app protection. Simultaneously, a key customer asked them to acquire a Guardsquare license based on their own independent investigations. 

“It was very interesting. Our implementation group started doing research and found Guardsquare was one of the best companies for mobile application protection. At the same time, a government customer called me and said, ‘Can you buy DexGuard because I saw that it's the best in the world.’  So we both did our research and we connected on Guardsquare.”

—  CEO, Central Asian Mobile Solutions Developer

The company contacted Guardsquare with an inquiry, and within two weeks an initial deal was signed. When asked what made for such a seamless evaluation process, the CEO said “Two things. First, we checked the documentation and technical descriptions about the products. It all looked clear. The second one is that the onboarding process was very good. Our account manager described everything very clearly. We understood that this is exactly what we needed.”

The Result

The company’s implementation team used Guardsquare’s guided workflow to configure mobile app protection for their APK solution and manual configuration for the more complex task of protecting the SDK of their stand-alone app. Guardsquare’s technical support team was available to assist throughout that process as needed.

“Previously, when we tried to use different security products, it was hard to communicate with technical support. With Guardsquare, it's easy to communicate. We just submit a ticket  and they always answer. The support has been really good.”

“We had attacks before, because it was only one level of security. Now that our solutions are more fully protected, everything is okay.”

— CEO, Central Asian Mobile Solutions Developer

After a full year of positive results, the company recently renewed an expanded license for Guardsquare’s platform for both Android and iOS versions of their SDK. In addition to continuing with mobile app protection, they also want to start using the platform’s scanning capabilities to gain the combined benefits of Guardsquare testing and protection.

“We will continue our license and try more Guardsquare platform capabilities. Specifically, we’re interested in testing because right now we are paying money for pentests and it's not so cheap.”

— CEO, Central Asian Mobile Solutions Developer

Ready to see how Guardsquare can address your mobile app security needs?

Guardsquare offers the most complete approach to mobile application security on the market, delivering the highest level of protection, without compromise. Guardsquare provides enhanced mobile application security that integrates seamlessly across the full development cycle, from mobile app security testing and code hardening to real-time threat detection and API security.

More than 1,000 customers worldwide across all major industries rely on Guardsquare to help them identify security risks and protect their mobile applications and SDKs against reverse engineering and tampering in the ever-evolving threat landscape. Learn more at www.guardsquare.com