Skip to content
Case studies

Transaction signing moved onto the phone.

An SDK a bank drops into the app it already has, so the approval step runs on the customer's own device.

Client withheld under NDA

Challenge

Banks are retiring SMS one-time codes as the way a customer approves a payment. The replacement had to run on the device and stay bound to the exact payment.

What we built

  • An ECDSA P-256 key generated on-device and held in the Secure Enclave or Keystore with StrongBox. The key never leaves the phone.
  • Push and QR approval: the customer reads the payment detail, then signs with biometrics.
  • PSD2 dynamic linking, so the signature covers the amount and the payee.
  • Device integrity and anti-tamper checks before a signing request is accepted.
  • An embeddable SDK, so the bank ships the flow without rebuilding its app.

Outcome

The customer approves a payment in the app, with a key that cannot leave the phone. The signature the bank gets back names the amount and the payee it covers.

Capabilities

  • SCA
  • Secure Enclave
  • ECDSA P-256
  • PSD2 dynamic linking
  • Mobile SDK

Describe your challenge.

Early idea or system already in production. Both are worth a conversation.

  • Built and run by our senior team.
  • Confidential from the first call, NDA as standard.

We couldn't send your message.

Your message is still in the form. Try again, or send it to [email protected] instead.


Open email draft

Message sent.

Thank you. We'll reply within one business day.


Prefer email?

[email protected]