Customer Story Type: Financial Services

MeDirect Protects its Source Code with Jscrambler

MeDirect Protects its Source Code with Jscrambler
Code Integrity’s multi-layer protection significantly reduced the attack surface of MeDirect’s banking application, making it much harder for potential attackers to understand the logic behind the app.

Overview

MeDirect is a pan-European digital banking company founded in 2004 and Malta’s third-largest banking group in terms of total assets. MeDirect focuses on WealthTech and specialized mortgage lending. It offers different tools and services to help customers manage their money from over 850 funds, 400 ETFs, and 3,000 stocks. MeDirect has over 106,000 customers and is expanding globally. Their vision is to provide a convenient way for people to manage and control their finances.

Challenge

MeDirect was concerned about users accessing the code built with NativeScript. This represented a security risk as their source code could easily be reverse-engineered. MeDirect tried some obfuscation techniques to hide its code but quickly understood it wasn’t enough to ensure its security.

When choosing the best solution to protect their web application, MeDirect prioritized the ease of integration and the effectiveness of JavaScript protection. MeDirect was also worried about impacting the performance of their application – they wanted to guarantee that the new security solution would not have any performance impact.

Solution

MeDirect focused on the benefits of polymorphic JavaScript Obfuscation, which transforms source code into a new version that is extremely hard to understand and reverse engineer while keeping its original functionality. This security layer also includes Jscrambler’s Code Hardening feature, which provides up-to-date protection against all reverse-engineering tools and techniques.

MeDirect’s team conducted several tests to check the threat resistance level and security effectiveness, including Penetration Tests, Vulnerability Scanning, and Code Reviews. This set of mechanisms was used to measure the ability of the code to resist different types of threats, such as code injection, data theft, and unauthorized access.

“Jscrambler fulfilled the entire checklist of the application security worries we had.”
Chris Portelli

Chief Technology Officer at MeDirect

Top Jscrambler Features and Capabilities

  • Polymorphic JavaScript obfuscation
  • Code hardening and self-defensive capabilities against tampering attempts
  • Minimal impact on performance and file size optimization

Results

MeDirect’s team encountered no issues when implementing Jscrambler. They started with the base mobile template first and integrated Code Integrity in minutes as it slid easily into their CI/CD pipeline.

MeDirect had an extensive checklist of critical needs that Jscrambler managed to satisfy by providing in-depth protection of their app source code.

Jscrambler Helps Neobanks Protect JavaScript

How Neobanks Strengthen Client-Side Security with Jscrambler
Several of the world’s leading neobanks and challenger banks turned to Jscrambler to strengthen the security of their web applications as digital channels became central to customer experience and revenue growth. Operating in highly regulated environments and handling sensitive financial data at scale, these institutions needed to protect their client-side JavaScript from reverse engineering,
tampering, and logic abuse.

Overview

Neobanks defy traditional banking by betting everything on digital and delivering customer-centric services for payments and money management. Today, over 90% of consumer interactions with banks are digital. Neobanks typically release new features more frequently, often every few weeks, while traditional banks tend to take several months to bring similar innovations to market. As a result, user satisfaction ratings for neobanks in the US (63%) are higher than those of traditional banks (55%).

Neobanks’ technological flexibility stems from investing in cloud-based infrastructure and advanced web and mobile applications built with modern JavaScript frameworks such as React Native. With this approach, they cut product development cost and time, paving the way for rapid iteration and innovation. This is greatly aided by relying on third-party integrations rather than developing every piece of code in-house. In software development, pursuing agility and speed often means widening security gaps. Despite JavaScript’s numerous advantages, neobanks must be aware that client-side JavaScript is exposed and can be used to launch attacks, including intellectual property theft, code tampering, application abuse, and data exfiltration. Unless protected with an enterprise-grade solution, this exposed JavaScript poses a key business threat.

Challenge

In recent years, several neobanks from North and South America, Europe, and Asia have approached Jscrambler due to significant security challenges. With web and mobile apps built with JavaScript — and a strong adoption of cross-platform frameworks for mobile development like React Native and Ionic — security teams understood early on that client-side logic would pose a significant security risk. There was a high likelihood of having to run sensitive logic on the client-side, so it became paramount to ensure that this logic would be concealed using the most potent and resilient technology available today. It was also mandatory to ensure that automated reverse-engineering tools would always fail to reverse the concealed code, while making it extremely unfeasible for attackers to achieve it manually. As these neobanks’ apps would handle sensitive services, another key challenge was ensuring that malicious actors couldn’t tamper with the code. JavaScript had to react in runtime to mitigate these attacks. And since both the web and mobile apps would handle sensitive data, such as credentials, personally identifiable information, and financial details, an additional pre-eminent requirement was to ensure that JavaScript couldn’t serve as a gateway for attackers to steal user data.

With each neobank offering multiple applications to their end customers, it was also essential to ensure that JavaScript protection would integrate seamlessly with their CI/CD and integration testing. Finally, in such a heavily regulated sector, another significant challenge was achieving compliance with regulations such as PSD2, NIST, the PCI DSS requirements 6.4.3 and 11.6.1, and specific requirements for operation like those of Bank of Brazil, for example, with a special focus on client-side attacks.

Solution

To meet the highest standards for JavaScript protection, these neobanks sought a holistic solution that would fit their processes and scale. Jscrambler presented a mature, proven client-side security product suite that, like noobanks themselves, is defined by continuous innovation.

The first step towards securing JavaScript was Jscrambler’s polymorphic obfuscation. With this critical security layer, all of the source code of neobanks’ apps was concealed beyond possible recognition. Jscrambler’s set of the most potent and resilient transformations was key to guaranteeing cutting-edge obfuscation. Its inherent polymorphism ensured that each new code deployment would be completely different—an extra line of defense against reverse-engineering attempts. For example, one of the banks had their fingerprinting script collect information from the session/browser, and wanted to protect it as it was exposed. Jscrambler provided the neobank with advanced polymorphic obfuscation to allow it to serve its fingerprinting script (practically unique) in each user session.

Security teams implemented critical OWASP recommendations, including the OWASP Mobile Top 10, which highlights that “to prevent effective reverse engineering, you must use an obfuscation tool” and that “the app must be able to react appropriately at runtime to a code integrity violation.” At the same time, they ensured compliance with PSD2 mandates, including transaction monitoring and strong customer authentication, as well as PCI DSS v4 requirements to safeguard payment pages and credit card data from client-side tampering. In addition, they aligned their client-side security measures with NIST guidelines, strengthening code integrity, runtime protections, and risk management practices in line with industry-standard cybersecurity frameworks. Jscrambler mostly worked with Security Engineers at these banks who were well aware of the problem and the required steps for solving it. After the initial setup of the Jscrambler instance, it took on average 2 weeks and 2 meetings with Jscrambler’s engineers to integrate Jscrambler seamlessly into their CI/CD pipeline. From there, Jscrambler became an automated part of their application build process.

Top Jscrambler Features and Capabilities

  • Polymorphic obfuscation
  • Anti-Tampering
  • Compliance with financial regulations and standards

Results

Securing JavaScript code requires awareness of the threats posed by exposing important logic on the client-side. Neobanks have had this pain from the very start of the business, as their main assets depend on it. By opting for Jscrambler’s proven JavaScript protection technology, product teams met their primary requirement: integrating a code protection solution seamlessly into their CI/CD. Now, these neobanks deploy secure code to production, knowing that each build has a fresh set of the most potent and resilient JavaScript protection available today. Jscrambler helped neobanks rethink key and critical data management in the applications, moving keys into JavaScript and applying Jscrambler Code Integrity to protect them effectively.

Through advanced obfuscation techniques, anti-debugging protections, and tamper detection, the solution prevented key theft, code tampering, and reverse engineering, ensuring the web application remained protected even when running on the client side. For management, safeguarding their applications’ source code from reverse engineering and tampering translates into a clear competitive advantage. Investors also recognized the reduced liability associated with exposed JavaScript in neobanking; with Jscrambler, these banks strengthened their position in future funding rounds and earned the trust of millions of potential customers. In a results-driven industry, the outcome was unequivocal: 0 integration issues, 0 successful attacks on JavaScript code.

How Jscrambler Helps dotConnect Deliver Secure Banking Apps

How Jscrambler Helps dotConnect Deliver Secure Banking Apps
Jscrambler successfully protects and secures the source code of the banking applications.

Overview

dotConnect is a fintech with the vision to empower financial institutions to provide their clients with a platform that delivers an exceptional digital banking experience. Via cloud-native solution architecture that is built for scale and resilience, dotConnect allows banks to accelerate their digital transformation and automation journeys. This enables these banks to provide a modern, customer-focused digital experience, reduce operational service requirements, and achieve low and predictable operational costs while also guaranteeing flexible integration with new and legacy banking systems using a decoupled approach.

Challenge

Today, 73% of all consumer interactions with banks are done digitally. And when it comes to banking, security is a prime directive. When asked about the most important attributes when choosing a bank, 82% of consumers say, “ensures my transactions are safe/secure.” Being aware of how security is one of the key drivers in the ongoing banking digitalization, dotConnect wanted to ensure that they were developing secure banking apps. This meant covering every inch of the attack surface.

Regarding web and hybrid mobile banking apps, one key security challenge is protecting the JavaScript code, which can be targeted by reverse-engineering, tampering, and injection attempts. This layer of protection is essential to reduce exposure to data exfiltration and transaction fraud, which can originate from client-side attack vectors.

Solution

The answer to dotConnect’s challenges in terms of source code protection was the cutting-edge technology provided by Jscrambler. Both founders had previously used Jscrambler in a previous solution within the banking sector a few years ago. So, when embarking on this new venture, they revisited the market to compare vendors and found that Jscrambler was still the market-leading solution in this sector. Thus, it was the obvious choice. Because dotConnect had to ensure maximum protection of the JavaScript source code, its team decided to combine two of Jscrambler’s most effective clientside security layers: JavaScript Obfuscation and Self-Defending.

Jscrambler’s Polymorphic JavaScript Obfuscation includes several different techniques that transform the original source code into a new version that is extremely hard to understand and reverse-engineer while keeping its original functionality. Included in this layer is Jscrambler’s Code Hardening feature, which provides up-to-date protection against all reverse-engineering tools and techniques.

dotConnect uses Jscrambler Self-Defending, a security layer that adds integrity checks and other runtime defenses that prevent attackers from debugging or tampering with the code. As such, if anyone tries to debug the protected banking app at runtime, the app will immediately break. Likewise, if an attacker tries to modify the code to dynamically understand its logic at runtime, the application will break to stop the attack. This advanced runtime protection reduces the attack surface to data exfiltration attacks by making it much harder for attackers to understand how the software works and plan/ automate these attacks

“When you have a financial product out in the public domain, you’re a prime target for attackers.”
Mohamed Gamil

CEO & Founder of dotConnect

“The protection layer that Jscrambler provides is very, very difficult to interpret, break, or bypass.”
Mohamed Gamil

CEO & Founder of dotConnect

Top Jscrambler Features and Capabilities

Polymorphic JavaScript Obfuscation
Self-Defending
Code Hardening

Results

dotConnect development team had no issues integrating Jscrambler into the CI build process, thanks to detailed documentation and support. One requirement of dotConnect was to pass their clients’ and their own strict penetration testing rounds. Jscrambler helped them achieve that by passing 5 penetration testing rounds.