Transaction signing moved onto the phone.
An SDK a bank drops into the app it already has, so the approval step runs on the customer's own device.
Client withheld under NDA
Challenge
Banks are retiring SMS one-time codes as the way a customer approves a payment. The replacement had to run on the device and stay bound to the exact payment.
What we built
- An ECDSA P-256 key generated on-device and held in the Secure Enclave or Keystore with StrongBox. The key never leaves the phone.
- Push and QR approval: the customer reads the payment detail, then signs with biometrics.
- PSD2 dynamic linking, so the signature covers the amount and the payee.
- Device integrity and anti-tamper checks before a signing request is accepted.
- An embeddable SDK, so the bank ships the flow without rebuilding its app.
Outcome
The customer approves a payment in the app, with a key that cannot leave the phone. The signature the bank gets back names the amount and the payee it covers.
Capabilities
- SCA
- Secure Enclave
- ECDSA P-256
- PSD2 dynamic linking
- Mobile SDK
Related work
Payments & banking
SEPA Instant on ISO 20022, signed and schema-valid.
Full ISO 20022 message lifecycle with digital signing and schema validation on a high-availability backbone.
- ISO 20022
- SEPA Instant
- HA
Payments & banking
A US prepaid card program, issued and orchestrated.
Cardholder experience plus a BFF orchestrating a card-issuing core, Mastercard tokenization, Apple/Google Pay and real-time KYC.
- Cards
- Tokenization
- KYC
Payments & banking
Reconciliation across four jurisdictions, automated.
Configurable workflow automation with CAMT / ISO 20022 reconciliation and multi-jurisdiction VAT and interest across four countries.
- Reconciliation
- CAMT
- Workflow
Describe your challenge.
Early idea or system already in production. Both are worth a conversation.
- Built and run by our senior team.
- Confidential from the first call, NDA as standard.
Prefer email?
[email protected]