Protect the Device
A SIM swap, a rooted phone, or a hijacked session can undo even a strong login. These products prove it's still the customer's own device.
Device attestation
Verified continuously · no action needed
SIM swap and re-issue
A criminal takes over the customer's phone number.
Network layer
Hijacked sessions
A session continues on hardware it was never meant to.
Session layer
Rooted and jailbroken phones
The phone's own protections are disabled.
Platform layer
Overlay attacks
A fake screen drawn over the real app to capture credentials.
Runtime layer
Confirms the SIM is still the one the customer enrolled with, catching a swap or re-issue before a transaction goes through.
02ekProtectDevice integrityDetects rooted or jailbroken phones and platform-level tampering in real time.
03ekShieldAuthenticationAlso binds the login itself to the enrolled device, closing the gap a stolen credential alone can't get through.
One decision engine
Every signal from this page — a SIM check, a device-integrity read — feeds into ekRules alongside the user and app surfaces. One engine decides in real time: allow, verify further, or block.
Saudi Arabia. The SAMA framework mandates FIDO2 device-bound credentials, with penalties up to SAR 5 million per breach.
Malaysia. BNM RMiT 2026 mandates device binding for every licensed bank.