Jscrambler Solution for Education
Strengthening Biometric Protection with Jscrambler & Build38
Learn how Jscrambler and Build38 enabled a major KYC provider to expand its biometric authentication security from mobile app to web, providing users with a unified, frictionless, and highly secure experience across all devices.
A London-based identity verification provider and one of Europe’s leading biometric vendors partnered with Build38 and Jscrambler to deliver advanced, cross-platform protection against digital fraud. By securing their unique approach to passwordless authentication—which verifies users without storing any biometric data—they successfully mitigated the risk of unauthorized account access. This collaboration enabled the company to expand its biometric authentication security from mobile app to web, providing users with a unified, frictionless, and highly secure experience across all devices. Our provider delivers a passwordless, multi-factor authentication approach that relies on biometric verification while safeguarding user privacy by storing no biometric data. This solution helps mitigate unauthorized account access and streamlines secure authentication across various devices.
The company had previously partnered with Build38 to protect its mobile SDK against video injection attacks, in line with CEN standards. It then sought to implement comparable safeguards for its web channel, where threats like synthetic or replayed video streams could undermine liveness verification mechanisms.
The organization detected two distinct attack vectors targeting its web SDK: crafted video injection and virtual camera bypass.
Having already trusted Build38 to secure its mobile SDK against video injection and reverse-engineering attacks, the team sought to extend the same certified level of protection to its web SDK
The objective was to create a unified, cross-platform defense that could withstand sophisticated fraud techniques while maintaining an effortless user experience. To achieve this, the company selected Jscrambler’s Code Integrity to shield its JavaScript code from runtime manipulation, DOM tampering, and reverse engineering.
Build38 and Jscrambler partnered on a proof-of-concept (PoC) during which real-world attack scenarios were simulated to evaluate the solution. To counter these threats, Jscrambler deployed its anti-DOM tampering and anti-monkey patching capabilities and Code Integrity protection features. The PoC focused on two primary objectives: performance and code security. The implementation needed to operate seamlessly, preserving the user experience while effectively defending the application against simulated attacks. Jscrambler’s library met both requirements, protecting the code without compromising speed, which ultimately led the organization to move forward with a full license.
“We jumped on a call with the Jscrambler team and got very good guidance about what we needed to do. It was easy to set up, easy to fine-tune when it needed fine-tuning, and that was it. Then we let it run”
Development Lead at the Identity Verification Platform
By combining the strengths of Build38 and Jscrambler, the identity verification company achieved a comprehensive, end-to-end security solution. Build38 provides protection for the mobile application, while Jscrambler’s Code Integrity technology secures the web SDK with runtime protection, making it resilient to tampering.
By implementing Jscrambler, Marriott Vacations Worldwide achieved:
Marriott Vacations Worldwide Secures the Browser with Jscrambler
Marriott Vacations Worldwide (MVW) enhances visibility and control over its client-side environment after meeting the PCI DSS requirements 6.4.3 and 11.6.1 with Jscrambler’s Webpage Integrity (WPI).
Marriott Vacations Worldwide is a global vacation company that offers vacation ownership, exchange, rental, and resort and property management, along with related businesses, products, and services. The company has a diverse portfolio that includes seven vacation ownership brands. It also includes exchange networks and membership programs, as well as management of other resorts and lodging properties.
As a large, digitally driven organization operating in a highly regulated environment, Marriott Vacations Worldwide faces increasing pressure to protect customer data, especially credit card data, across complex web environments, particularly in the browser. Like many enterprise organizations, MVW relies on numerous third-party scripts and marketing tags to deliver personalized experiences and optimize performance. However, this growing client-side ecosystem introduces visibility and control challenges, such as shadow IT and unvetted third-party vendor scripts introduced by marketing and sales teams.
The scale of the scope challenge to discover all the payment pages became especially clear during their internal discovery work: “We did a complete inventory of our web-based payment pages that accept credit cards. That was not an easy task to accomplish. Full disclosure, it took 9 months here for us to discover every single web-based page where we accept credit cards. That kind of just talks to the complexity of the organization.” The core challenge wasn’t simply tracking scripts; it was maintaining continuous visibility and control across a large, evolving digital footprint with a small team managing compliance for multiple entities simultaneously.
The MVW team was aware of PCI DSS requirements 6.4.3 and 11.6.1 early on and used the on-ramp period to identify a solution. MVW’s websites are highly dynamic, with marketing sites frequently updated, and marketing and sales teams often perform site refreshes outside of IT. The team needed a solution that directly met 6.4.3 and 11.6.1, which ruled out options like a CDN or a combination of CSP and SRI due to the required learning curve and manual effort. After evaluating various approaches, MVW selected Jscrambler’s Webpage Integrity (WPI) product to meet the requirements 6.4.3 and 11.6.1 and improve third-party script control in its browser environment.
By automating client-side monitoring, the solution eliminated the need for manual oversight and significantly reduced operational burden. Its seamless integration with the SIEM provided effective visibility without generating excessive alerts. The intuitive UI also made it easy to manage approvals and push business justifications directly to stakeholders, streamlining governance across teams. TJ mentioned that the solution included what he called a “panic button” feature that allows certain third-party scripts to be instantly cut off from data access without impacting performance. Essentially, the Jscrambler platform provides granular control over third-party scripts, enabling MVW to restrict access to sensitive data while still allowing third-party services to function as intended.
TJ noted that, given the organization’s complexity, the journey was not easy. However, the Jscrambler team made the whole process smooth and pain-free: “Early on, it was a pleasure to work with Jscrambler. Jscrambler really stepped up for us. We have more than 15 unique codebases. It was difficult, but it worked out well for us.”
“We haven’t found anything else out there in the market today that provides all of the benefits from the length of time Jscrambler’s been at this to the ease of use of this solution, and directly meeting the PCI requirements.”
TJ GoldsmithPCI Compliance Program Director at Marriott Vacations Worldwide
Marriott Vacations Worldwide achieved full compliance with PCI DSS v4 requirements 6.4.3 and 11.6.1 ahead of the enforcement deadline. As TJ shared, “We were 100% compliant before we needed to be.”
By implementing Jscrambler, Marriott Vacations Worldwide achieved:
For Marriott Vacations Worldwide, client-side protection was not simply about checking a compliance box. It was about protecting 160 card data flows across six distinct entities, managing dynamic marketing environments, reducing operational burden, and preserving brand trust. With Jscrambler, MVW implemented a solution that did all that while keeping a lean compliance team efficient.
MeDirect Protects its Source Code with Jscrambler
Code Integrity’s multi-layer protection significantly reduced the attack surface of MeDirect’s banking application, making it much harder for potential attackers to understand the logic behind the app.
MeDirect is a pan-European digital banking company founded in 2004 and Malta’s third-largest banking group in terms of total assets. MeDirect focuses on WealthTech and specialized mortgage lending. It offers different tools and services to help customers manage their money from over 850 funds, 400 ETFs, and 3,000 stocks. MeDirect has over 106,000 customers and is expanding globally. Their vision is to provide a convenient way for people to manage and control their finances.
MeDirect was concerned about users accessing the code built with NativeScript. This represented a security risk as their source code could easily be reverse-engineered. MeDirect tried some obfuscation techniques to hide its code but quickly understood it wasn’t enough to ensure its security.
When choosing the best solution to protect their web application, MeDirect prioritized the ease of integration and the effectiveness of JavaScript protection. MeDirect was also worried about impacting the performance of their application – they wanted to guarantee that the new security solution would not have any performance impact.
MeDirect focused on the benefits of polymorphic JavaScript Obfuscation, which transforms source code into a new version that is extremely hard to understand and reverse engineer while keeping its original functionality. This security layer also includes Jscrambler’s Code Hardening feature, which provides up-to-date protection against all reverse-engineering tools and techniques.
MeDirect’s team conducted several tests to check the threat resistance level and security effectiveness, including Penetration Tests, Vulnerability Scanning, and Code Reviews. This set of mechanisms was used to measure the ability of the code to resist different types of threats, such as code injection, data theft, and unauthorized access.
“Jscrambler fulfilled the entire checklist of the application security worries we had.”
Chris PortelliChief Technology Officer at MeDirect
MeDirect’s team encountered no issues when implementing Jscrambler. They started with the base mobile template first and integrated Code Integrity in minutes as it slid easily into their CI/CD pipeline.
MeDirect had an extensive checklist of critical needs that Jscrambler managed to satisfy by providing in-depth protection of their app source code.
Powtoon Protects Its Core IP and Competitive Advantage with Jscrambler
Powtoon, a leading visual communication platform, chose Jscrambler to protect its valuable digital assets and stay ahead of the fierce competition.
Powtoon is a leading video and visual communication platform that was launched in 2012. Powtoon’s mission is to empower individuals, teams, and companies to achieve measurable results by transforming communications into visual experiences that get their audience to care, connect, and act.
Powtoon adds a spark of awesomeness to everyday communications, turning content into substance people want to watch and engage with.
For the first 5-7 years of Powtoon’s existence, their e-learning video product was flash-based. However, with the rise of JavaScript, the need to protect their source code arose. With the launch of their HTML5 product, the Powtoon team realized they didn’t want to lose their competitive edge by putting their unprotected source code out there for everyone to see and copy.
Powtoon’s CTO and Co-Founder insisted the team invested in finding and using the best JavaScript protection he could find at the time.
Powtoon needed a solution to protect its core code at runtime and safeguard its digital assets from reverse engineering and IP theft, which would allow it to stay ahead in a competitive market.
Before choosing Jscrambler, the Powtoon team looked at open-source solutions and found Jscrambler to be the most comprehensive client-side solution with best-of-breed features.
Powtoon started using Jscrambler’s Code Integrity from the very beginning, so their product never went live unprotected at any stage. The polymorphic JavaScript obfuscation was one the biggest factors in choosing Jscrambler as it proved to be very comprehensive and customizable. Additionally, the variety of runtime protections was deemed helpful.
The Powtoon team also enjoyed using Code Integrity’s dashboard and web interface which they preferred instead of having to use some kind of command line tools that they would need to integrate in a complicated way into their build. However, the biggest deal breaker for Powtoon was the performance aspect. They strived to balance the performance of a very complex application with the need to protect it.
“With Jscrambler, we wanted to protect our competitive advantage. We weren’t the first HTML5 product in the market, but we were the only one that was already an established brand. And we didn’t want to risk it as we were already subject to copycats. Some clones were almost identical to us and they were stealing our graphical assets, which are much more difficult to protect.”
Sven Hoffmann, CTO and Co-Founder at Powtoon
“You do not go for the heaviest protection because it just doesn’t fly with our performance requirements. So you look for the right ratio of reasonable price and a reasonable level of protection with a minimal performance impact. That’s what we got with Jscrambler.”
Sven HoffmannCTO and Co-Founder at Powtoon
Powtoon’s platform is protected from IP theft and code tampering. Jscrambler provided a comprehensive first-party code protection solution with a minimal performance impact. The Powtoon team is happy with the solution Jscrambler offers, as well as with customer support and the stress-free relationship.
Scentbird Ensures Customer Trust with the Jscrambler PCI DSS solution
Scentbird takes a proactive approach to PCI DSS v4 compliance and protects its payment page with Jscrambler’s compliance solution.
Scentbird is a subscription service for perfumes, colognes, candles, and car fresheners. Scentbird was founded in NYC in early 2013 and established as a subscription business in 2014. Scentbird enables its users to choose and receive a supply of sample designer fragrances monthly before buying them. It has grown to have more than 700,000 active subscribers.
Scentbird has been developing its e-commerce subscription platform in-house. That came with handling many things, including security and compliance and working with multiple payment providers. One of the things that were being asked from one of the payment providers was to be PCI DSS compliant. Aside from that, it was essential for Scentbird to ensure that its audience could trust Scentbird with its data. Andrei Rebrov, CTO & Co-Founder at Scentbird, shares, “The customers should safely leave their credit card information on our website. If people think something is wrong, they will feel unsafe, and there will be no conversion. And if there’s no conversion, there is no revenue.” The Scentbird team realized that with the upcoming change in PCI DSS, they needed a proper way to comply with the specific requirements 6.4.3 and 11.6.1.
The team’s most important question was what was going on with the customer data. Traditional cookie consent management platforms didn’t track who interacted with which form, the changes inside the scripts, or what kind of data was being transmitted outside.
Scentbird mission is to give users fragrance recommendations and personalizations. So, Scentbird has to collect information about the customer and share this information with marketing platforms to fuel personalization. So, it was essential to achieve a balance between the information they gathered, how they treated it, and how they controlled the third-party scripts on their website. They needed a solution to help them control third-party scripts without spending too much time tending to minor changes.
The Scentbird team first examined several cookie consent management tools that offered PCI DSS compliance. However, they didn’t provide a proper solution and couldn’t answer any specific PCI DSS questions. Another category of solutions they looked at were big enterprise platforms (CDNs, WAFs) that would cost a lot of money and would have you undergo a rigorous integration process. Moreover, Andrei, Scentbird’s Co-Founder, noted that while the major platforms often release features aligned with their general protection offerings, they do not delve deeply into specific matters like PCI DSS v4 compliance.
It was clear to the Scentbird team what they needed to do. Andrei notes, “The Jscrambler team explained how the integration would work, how to prepare for the audit, how to view the rest of the inventory, how notifications about specific changes would be received, how those changes would be reflected, and how we should respond. I appreciate this in a partner—they provided a clear protocol and outlined exactly what I needed to do. I had no additional questions and felt confident about using the product properly.” Andrei shares that it was quite easy to implement the solution, and there were no major obstacles.
“So what starts as a list of around 60 different scripts and pixels and sort of interactions with a third party, might be the list of 100 more with the dependencies. And then when you start looking at the scripts for the past 30 days, you will see a huge list with one script that has changed the version every other day. It’s a minor change, but it’s very annoying.”
Andrei RebrovCTO & Co-Founder at Scentbird
“I didn’t want to spend a lot of time having someone on my team manage this. So, I was looking for something I could implement once to ensure we are protected. If something new comes up, the team will reach out to notify me about changes and any actions I need to take, allowing us to focus on what we do best: selling fragrances.”
Andrei RebrovCTO & Co-Founder at Scentbird
Scentbird became PCI DSS-compliant in early 2024, well ahead of the 2025 deadline and earlier than many e-commerce companies. When asked why Scentbird chose Jscrambler, Andrei mentioned the delivery of what they needed to be PCI DSS-compliant, quick implementation, and the quality of the Jscrambler team’s support.
Securing One of the Biggest E-Commerce Websites with Jscrambler
In a landscape where cyber threats are constantly evolving, the Fortune 500 Retail Company’s success with Jscrambler serves as a testament to the efficacy of dedicated client-side protection.
Established in the 1960s, this client is an iconic American brand boasting four flagship labels. The company recently also expanded its portfolio. As a Fortune 500 company, the company’s commitment to innovation extends beyond the retail industry, delving into the digital realm with a strong online presence and a high-traffic e-commerce platform.
In the past decade, the client’s e-commerce traffic has soared, paralleling the rise in online shopping. However, this increase also attracted more frequent and more sophisticated cyber threats. The company witnessed a surge in malicious scripts targeting customer data through various methods, including keylogging, card skimming, and credential hijacking. Confronted with this escalating threat, the client sought robust client-side security solutions to shield its web applications.
The retailer’s broad digital exposure, especially during peak shopping periods like Black Friday, left them vulnerable to attack vectors like JavaScript data exfiltration and script hijacking. To counter these threats, the client required a system that provided comprehensive control to mitigate these kinds of attacks. Additionally, their collaborations with third-party vendors necessitated a security tool that could precisely regulate the data accessible to these third-party tags.
The retailer sought the right solution to secure its client-side applications against the evolving threat landscape. For an e-commerce platform of their scale, they needed more than just the basics.
The retailer required a security solution that would continue to monitor their website just as effectively in real-time and take appropriate automated action against threats, regardless of traffic volume. Flexibility was equally crucial, especially the ability to restrict data access through form fencing and to oversee all data points on their site comprehensively. Moreover, swift response times were imperative, as the retailer’s success hinged on transforming website visits into sales through an exceptional user experience.
The client’s criteria extended to adaptability and enduring protection. After a thorough evaluation, the retailer identified Jscrambler as the sole contender to meet all of their stringent criteria. Jscrambler’s R&D continuously monitors emerging threats, ensuring the platform evolves to effectively react to the ever-changing cyber threat environment.
As the final deal clincher, Jscrambler gave the retailer a security tool fully focused on client protection. The team already had security tools in their arsenal but didn’t want to rely solely on default security features or add-ons to existing solutions. They believed strongly in a clear separation of responsibilities and were specifically looking for a platform that focused solely on client-side protection, independent of their web application firewall, tag manager, and other existing tools.
“With the kind of traffic we see, data protection for JavaScript, the ability to stop data exfiltration, and field-level protection for sensitive information like credit card details and PII are just the beginning. We also need a solution that can scale up and continue to perform optimally as our business grows. This is absolutely critical.”
Director of Product Security at the Fortune 500 Retail Company
“With Jscrambler, we can maintain the level of security that is critical to running a multinational business and preserving our customer’s trust. The unique layer of security it adds is definitely an integral part of our defense strategy. I’d highly recommend Jscrambler to any other business with a full-blown e-commerce platform that hosts millions of customers daily.”
Director of Product Security at the Fortune 500 Retail Company
Adopting Jscrambler has provided the retailer with several benefits. Protection from Magecart and skimming risks is crucial for e-commerce platforms, and having Jscrambler covering them on this front helps the client breathe a little easier. They know that sensitive data is protected from exfiltration and hijacking when customers shop on the retailer’s website and that banking and PCI information will remain secure.