When health tracking drives real-world financial rewards, API security is non-negotiable. ⌚🏃♂️ Vitality rewards members for logging workouts, step counts, and heart rates. But with cash-value perks on the line, mobile APIs quickly become high-value targets for bots, scripts, and spoofed data. By partnering with Approov, Vitality Group Inc. deployed dynamic Zero-Trust Mobile App Attestation to ensure: ✅ Every request comes from a genuine, untampered app instance ✅ Backend APIs are shielded from credential stuffing and automated bots ✅ Health data stays private across iOS, Android, and watchOS Read the full case study: Vitality Success Story (https://hubs.ly/Q04zfzNy0) #APISecurity #MobileSecurity #DigitalHealth #Cybersecurity #ZeroTrust #InsurTech #mobilehealth
Approov Mobile Security
Software Development
Edinburgh, Scotland, UK 5,029 followers
Zero-Trust for Mobile Apps and APIs - iOS, Android and HarmonyOS
About us
Approov delivers cloud-native mobile app security trusted by global leaders in eCommerce, finance, healthcare, gaming, and the connected vehicle ecosystem. Our patented mobile runtime integrity and API protection technology ensures that only genuine, untampered mobile apps can access your backend services—unified seamlessly across iOS and Android. As mobile apps have become the front door to digital business, they are increasingly targeted by automated attacks, reverse engineering, and API abuse. Approov brings a cloud-native Zero Trust approach to mobile app security, continuously verifying the integrity of each app instance and device before granting API access. We secure the entire mobile-to-cloud channel—protecting your APIs from scripts, bots, repackaged apps, and emulators in real time. Our platform provides: Dynamic, runtime attestation with zero false positives Just-in-time delivery of API secrets, certificates, and tokens Built-in Runtime Application Self-Protection (RASP) for enhanced on-device defense End-to-end telemetry and visibility from app to API By embedding lightweight SDKs in your apps and using a cloud-native attestation service, Approov gives security, DevOps, and compliance teams centralized control over a distributed mobile threat surface—without slowing innovation. Founded as CriticalBlue in Edinburgh, Scotland, with U.S. operations in Palo Alto, California, Approov launched its mobile API protection platform in 2017 after years of R&D in binary analysis, runtime integrity, and secure system performance. Our roots in deep systems engineering have evolved into a platform that powers security for millions of users globally. Approov is redefining mobile app security for the cloud-native era. 🔗 Learn more at www.approov.io
- Website
-
http://approov.com/
External link for Approov Mobile Security
- Industry
- Software Development
- Company size
- 11-50 employees
- Headquarters
- Edinburgh, Scotland, UK
- Type
- Privately Held
- Founded
- 2001
- Specialties
- Anti-bot protection for mobile, API protection, Bot Detection & Mitigation, DDoS Protection, Mobile API Security, Mobile Security, Cybersecurity, App attestation, RASP, and Runtime Application Self Protection
Employees at Approov Mobile Security
Locations
-
Primary
Get directions
Scotiabank House
6 South Charlotte Street
Edinburgh, Scotland, UK EH24AW, GB
-
Get directions
165 University Ave
Suite 200
Palo Alto, California 94301, US
Updates
-
🔒 Next-Gen Mobile Security: Approov Mobile Security x Edinburgh Napier University As GenAI accelerates automated attacks, static security controls are no longer enough to safeguard mobile ecosystems. We’re excited to partner with Edinburgh Napier University on a 30-month Knowledge Transfer Partnership (KTP), co-funded by Innovate UK. Key Highlights: ▪️️ Top-Rated Vision: Earned the highest rating in Innovate UK’s competitive assessment round. ▪️ Red vs. Blue Strategy: Specialized researchers will continuously build advanced cryptographic defenses (Blue) while stress-testing against real-world threat vectors (Red). ▪️ Advancing Digital Trust: Combining mobile API protection with ENU’s Academic Centre of Excellence to stay ahead of rogue AI agents and automated threats. 📖 Read the full story: Next-Gen Smartphone Security: ENU and Approov's Groundbreaking KTP #MobileSecurity #APISecurity #CyberSecurity #AppDefense #InnovateUK #TechPartnership
-
🚀 We’re heading to Cloudflare Connect 2026! As a Gold Sponsor, Team Approov will be in San Francisco to talk all things mobile app security and API protection. Mobile apps are increasingly targeted by automated API attacks, reverse engineering, and abuse. Protecting your backend APIs starts with knowing what’s actually connecting to them. 📍 Moscone West, San Francisco 📅 October 19–22, 2026 🎯 Booth #717 Stop by Booth #717 to: 🔹 Meet the Approov team 🔹 See a live demo 🔹 Learn how cryptographic proof of app authenticity can help protect your mobile APIs Want dedicated time with our team? Book a meeting in advance: https://hubs.ly/Q04yM-fw0 See you in San Francisco! 👋 #CloudflareConnect #MobileSecurity #APISecurity #AppSec #Cybersecurity #Approov
-
🚗🔒 Connected vehicle security is evolving fast—and so are the threats targeting automotive APIs. We’re excited to participate the 2026 Auto-ISAC Cybersecurity Summit in Novi, Michigan! Don’t miss our session with Mark Mazur: 🎙️ Beyond Authentication: Securing Connected Vehicle APIs in the Age of AI 📅 October 8, 2026 | 1:30–2:00 PM EST 📍 Vibe Credit Union Showplace, Novi, MI 🗓️ Summit: October 6–9 Mark will explore the evolving security threat landscape for connected vehicle APIs, highlighting common attack vectors such as app cloning, reverse engineering, and AI-driven exploits, along with recommended defensive measures. Will you be at Auto-ISAC? We’d love to connect! Schedule a 1-on-1 discussion with the Approov team during the summit: https://hubs.ly/Q04yMD5l0 #AutoISAC #AutomotiveCybersecurity #ConnectedVehicles #APISecurity #AI #DevSecOps #MobileAppSecurity@
-
-
We're delighted to be partnering with Prof Bill Buchanan OBE FRSE and the team at Edinburgh Napier University on this Knowledge Transfer Partnership. Bringing together #EdNapier's world-class research and Approov Mobile Security's industry expertise gives us an amazing opportunity to build next-gen red and blue team defenses, which is especially critical as AI creates new security challenges. Huge thanks to Innovate UK and the Scottish Centre of Excellence in Digital Trust and Distributed Ledger Technology for making this collaboration possible.
🔐 | A new partnership between #EdNapier and mobile cybersecurity firm Approov Mobile Security will aim to improve smartphone security. The Edinburgh-based company has agreed a Knowledge Transfer Partnership (KTP) with ENU, which will include the recruitment of two cyber security researchers, co-funded by Innovate UK. Over the course of 30 months, Approov and Edinburgh Napier will work together to create innovative defence mechanisms and an offensive test bed – known in cyber security as ‘blue team’ and ‘red team’. The project, which received the highest rating in Innovate UK’s assessment for this funding round, will involve the ENU-hosted Scottish Centre of Excellence in Digital Trust and Distributed Ledger Technology. Full story ➡️ https://lnkd.in/efws6XQt #MustBeNapier | Edinburgh Napier University's SCEBE | East of Scotland KTP Centre | Edinburgh Napier Research, Innovation and Enterprise
-
-
By 2027, autonomous AI agents are projected to outnumber human web users. As we enter the Agentic Web, simply blocking automated traffic is no longer an option—the key is separating good bots from bad bots. However, while organizations pour budget into WAFs to manage web endpoints, attackers are pivoting straight to mobile APIs using emulators, repackaged binaries, and spoofed traffic. In my latest article, "Good Bot, Bad Bot: Securing Your APIs in the Era of Agentic AI," I explore: 🔹 Why web bot management fails in mobile environments 🔹 How shifting to deterministic cryptographic proof eliminates mobile API blind spots 🔹 How combining Approov's runtime attestation with your WAF creates a true Zero Trust defense Stop relying on static API keys and web behavioral checks to protect mobile backends. Read the full article below! 👇 #APISecurity #AgenticAI #ZeroTrust #Cybersecurity #AppSecurity #bots #WAF
-
1.8M Android apps scanned; AI-driven pipelines extracting hardcoded secrets in hours. The latest Anthropic threat report highlights how attackers used #Claude to automate APK decompilation, secret extraction with tools like #TruffleHog, and rapid credential routing. AI agents de-obfuscate code in seconds and scale static analysis exponentially. When mobile apps embed static API keys, tokens, or credentials directly in the codebase, automated tools will inevitably find them. To defend against AI-speed automated attacks, mobile security must shift toward a Zero Secrets Architecture. The core premise is straightforward: If a secret is not present in the app binary, on disk, or persistently in memory, it cannot be extracted. Key principles for engineering teams: - Deliver secrets dynamically at runtime to verified app instances on demand, then discard them; never persist credentials on the device. - Use runtime app attestation to cryptographically verify app integrity and device health before releasing sensitive payloads or API access tokens. - Issue short-lived, scope-limited tokens that expire quickly to render captured credentials useless to automated replay agents. - Eliminate hardcoded keys entirely so static APK decompilation yields nothing for automated scanners to harvest. AI agents can decompile millions of APKs in parallel, but they can't extract secrets that aren't there. A link to BleepingComputer's coverage of this story can be found in the first comment below.
-
🚨 Big moves in the mobile app market: The Coalition for App Fairness (backed by Spotify & Epic Games) is urging the UK’s CMA to immediately block Apple and Google from charging app store commissions until a fair framework is set. Their demands: - Freeze fees at zero until Apple & Google prove cost justification. - Accelerate timeline from months to days for direct-payment rules ("steering"). As mobile ecosystems open up, developers are taking direct control of payments and security. Will regulators grant these curbs? Full story on Sky News (https://hubs.ly/Q04x6qpr0). #TechNews #AppEconomy #Antitrust #CMA #Apple #Google #Spotify
-
🚀 How do you defend mobile apps when attackers start using autonomous AI agents? Traditional bot attacks follow predictable, static scripts. But modern AI-driven threats are dynamic—adapting instantly when hit with rate limits, rewriting scripts on the fly, and bypassing standard WAFs and behavioral analysis by seamlessly mimicking human traffic. We’re thrilled that our Field CTO, Mark Mazur, will be speaking at the upcoming OWASP LA September In Person Meetup! Mark will dive into how cryptographic proof of authenticity helps engineering and security teams lock down mobile apps and APIs against advanced AI agentic attacks. OWASP LA is a local chapter of the Open Worldwide Application Security Project, a global nonprofit dedicated to improving software security through free, open, and community-driven events. Team Approov is proud to sponsor this session and support the local LA AppSec community! 🛡️ Come grab a seat to join the discussion on the future of mobile API security. 👉 Register for free: https://luma.com/ik2qe9ji #Cybersecurity #AppSec #MobileSecurity #OWASP #APISecurity #LosAngelesTech #SoftwareEngineering #AIThreats
-
A recent Licel article by Ivan Kinash makes an important point: attestation is evidence—not a trust decision. Even hardware-backed, non-exportable keys can be abused when an attacker controls the application environment. But this raises a critical question: If the attacker has root, why make the trust decision on the device they control? Runtime hardening, #RASP, obfuscation, and virtual TEEs can raise attack costs—but they all run on the client. The stronger architectural approach is to: 🔹 Verify app integrity externally 🔹 Make the trust decision off-device 🔹 Issue short-lived, cryptographic tokens 🔹 Keep signing secrets out of the app 🔹 Bind API access to verified integrity The principle is simple: the device making the request should not be the source of the evidence used to trust it. Read the full article: “The Runtime Was Hardened. The TEE Was Virtual. The Attacker Had Root.” #TEE #APIsecurity #attestation