Need: All

Strengthening Biometric Protection with Jscrambler & Build38

Strengthening Biometric Protection with Jscrambler & Build38
Learn how Jscrambler and Build38 enabled a major KYC provider to expand its biometric authentication security from mobile app to web, providing users with a unified, frictionless, and highly secure experience across all devices.

Overview

A London-based identity verification provider and one of Europe’s leading biometric vendors partnered with Build38 and Jscrambler to deliver advanced, cross-platform protection against digital fraud. By securing their unique approach to passwordless authentication—which verifies users without storing any biometric data—they successfully mitigated the risk of unauthorized account access. This collaboration enabled the company to expand its biometric authentication security from mobile app to web, providing users with a unified, frictionless, and highly secure experience across all devices. Our provider delivers a passwordless, multi-factor authentication approach that relies on biometric verification while safeguarding user privacy by storing no biometric data. This solution helps mitigate unauthorized account access and streamlines secure authentication across various devices.

Challenge

The company had previously partnered with Build38 to protect its mobile SDK against video injection attacks, in line with CEN standards. It then sought to implement comparable safeguards for its web channel, where threats like synthetic or replayed video streams could undermine liveness verification mechanisms.

The organization detected two distinct attack vectors targeting its web SDK: crafted video injection and virtual camera bypass.

Solution

Having already trusted Build38 to secure its mobile SDK against video injection and reverse-engineering attacks, the team sought to extend the same certified level of protection to its web SDK

The objective was to create a unified, cross-platform defense that could withstand sophisticated fraud techniques while maintaining an effortless user experience. To achieve this, the company selected Jscrambler’s Code Integrity to shield its JavaScript code from runtime manipulation, DOM tampering, and reverse engineering.

Build38 and Jscrambler partnered on a proof-of-concept (PoC) during which real-world attack scenarios were simulated to evaluate the solution. To counter these threats, Jscrambler deployed its anti-DOM tampering and anti-monkey patching capabilities and Code Integrity protection features. The PoC focused on two primary objectives: performance and code security. The implementation needed to operate seamlessly, preserving the user experience while effectively defending the application against simulated attacks. Jscrambler’s library met both requirements, protecting the code without compromising speed, which ultimately led the organization to move forward with a full license.

“We jumped on a call with the Jscrambler team and got very good guidance about what we needed to do. It was easy to set up, easy to fine-tune when it needed fine-tuning, and that was it. Then we let it run”
Development Lead at the Identity Verification Platform

Top Jscrambler Features and Capabilities

  • Unified Client-Side Protection
  • Reliable-at-Scale Performance
  • Mitigation of SDK Security Risks

Results

By combining the strengths of Build38 and Jscrambler, the identity verification company achieved a comprehensive, end-to-end security solution. Build38 provides protection for the mobile application, while Jscrambler’s Code Integrity technology secures the web SDK with runtime protection, making it resilient to tampering.

By implementing Jscrambler, Marriott Vacations Worldwide achieved:

  • Evidence of Compliance
    Compliance with PCI DSS 6.4.3 & 11.6.1, ease of demonstrating/providing evidence of compliance
  • Full Client-Side Protection
    Platform leveraged by other internal teams outside of PCI Compliance
  • Visibility & Control
    Enhanced visibility & control over all payment pages across all brands
  • Improved Risk Posture
    Improved risk posture through real-time script monitoring and header integrity validation

Marriott Vacations Worldwide Secures the Browser with Jscrambler

Marriott Vacations Worldwide Secures the Browser with Jscrambler
Marriott Vacations Worldwide (MVW) enhances visibility and control over its client-side environment after meeting the PCI DSS requirements 6.4.3 and 11.6.1 with Jscrambler’s Webpage Integrity (WPI).

Overview

Marriott Vacations Worldwide is a global vacation company that offers vacation ownership, exchange, rental, and resort and property management, along with related businesses, products, and services. The company has a diverse portfolio that includes seven vacation ownership brands. It also includes exchange networks and membership programs, as well as management of other resorts and lodging properties.

Challenge

As a large, digitally driven organization operating in a highly regulated environment, Marriott Vacations Worldwide faces increasing pressure to protect customer data, especially credit card data, across complex web environments, particularly in the browser. Like many enterprise organizations, MVW relies on numerous third-party scripts and marketing tags to deliver personalized experiences and optimize performance. However, this growing client-side ecosystem introduces visibility and control challenges, such as shadow IT and unvetted third-party vendor scripts introduced by marketing and sales teams.

The scale of the scope challenge to discover all the payment pages became especially clear during their internal discovery work: “We did a complete inventory of our web-based payment pages that accept credit cards. That was not an easy task to accomplish. Full disclosure, it took 9 months here for us to discover every single web-based page where we accept credit cards. That kind of just talks to the complexity of the organization.” The core challenge wasn’t simply tracking scripts; it was maintaining continuous visibility and control across a large, evolving digital footprint with a small team managing compliance for multiple entities simultaneously.

Solution

The MVW team was aware of PCI DSS requirements 6.4.3 and 11.6.1 early on and used the on-ramp period to identify a solution. MVW’s websites are highly dynamic, with marketing sites frequently updated, and marketing and sales teams often perform site refreshes outside of IT. The team needed a solution that directly met 6.4.3 and 11.6.1, which ruled out options like a CDN or a combination of CSP and SRI due to the required learning curve and manual effort. After evaluating various approaches, MVW selected Jscrambler’s Webpage Integrity (WPI) product to meet the requirements 6.4.3 and 11.6.1 and improve third-party script control in its browser environment.

By automating client-side monitoring, the solution eliminated the need for manual oversight and significantly reduced operational burden. Its seamless integration with the SIEM provided effective visibility without generating excessive alerts. The intuitive UI also made it easy to manage approvals and push business justifications directly to stakeholders, streamlining governance across teams. TJ mentioned that the solution included what he called a “panic button” feature that allows certain third-party scripts to be instantly cut off from data access without impacting performance. Essentially, the Jscrambler platform provides granular control over third-party scripts, enabling MVW to restrict access to sensitive data while still allowing third-party services to function as intended.

TJ noted that, given the organization’s complexity, the journey was not easy. However, the Jscrambler team made the whole process smooth and pain-free: “Early on, it was a pleasure to work with Jscrambler. Jscrambler really stepped up for us. We have more than 15 unique codebases. It was difficult, but it worked out well for us.”

“We haven’t found anything else out there in the market today that provides all of the benefits from the length of time Jscrambler’s been at this to the ease of use of this solution, and directly meeting the PCI requirements.”
TJ Goldsmith

PCI Compliance Program Director at Marriott Vacations Worldwide

Top Jscrambler Features and Capabilities

  • Granular control over third-party scripts
  • Intuitive UI and minimal learning curve
  • Low-noise alerting

Results

Marriott Vacations Worldwide achieved full compliance with PCI DSS v4 requirements 6.4.3 and 11.6.1 ahead of the enforcement deadline. As TJ shared, “We were 100% compliant before we needed to be.”

By implementing Jscrambler, Marriott Vacations Worldwide achieved:

  • Evidence of Compliance
    Compliance with PCI DSS 6.4.3 & 11.6.1, ease of demonstrating/providing evidence of compliance
  • Visibility & Control
    Enhanced visibility & control over all payment pages across all brands
  • Full Client-Side Protection
    Platform leveraged by other internal teams outside of PCI Compliance
  • Improved Risk Posture
    Improved risk posture through real-time script monitoring and header integrity validation

For Marriott Vacations Worldwide, client-side protection was not simply about checking a compliance box. It was about protecting 160 card data flows across six distinct entities, managing dynamic marketing environments, reducing operational burden, and preserving brand trust. With Jscrambler, MVW implemented a solution that did all that while keeping a lean compliance team efficient.

Powtoon Protects its Core IP and Competitive Advantage with Jscrambler

Powtoon Protects Its Core IP and Competitive Advantage with Jscrambler
Powtoon, a leading visual communication platform, chose Jscrambler to protect its valuable digital assets and stay ahead of the fierce competition.

Overview

Powtoon is a leading video and visual communication platform that was launched in 2012. Powtoon’s mission is to empower individuals, teams, and companies to achieve measurable results by transforming communications into visual experiences that get their audience to care, connect, and act.

Powtoon adds a spark of awesomeness to everyday communications, turning content into substance people want to watch and engage with.

Challenge

For the first 5-7 years of Powtoon’s existence, their e-learning video product was flash-based. However, with the rise of JavaScript, the need to protect their source code arose. With the launch of their HTML5 product, the Powtoon team realized they didn’t want to lose their competitive edge by putting their unprotected source code out there for everyone to see and copy.

Powtoon’s CTO and Co-Founder insisted the team invested in finding and using the best JavaScript protection he could find at the time.

Powtoon needed a solution to protect its core code at runtime and safeguard its digital assets from reverse engineering and IP theft, which would allow it to stay ahead in a competitive market.

Solution

Before choosing Jscrambler, the Powtoon team looked at open-source solutions and found Jscrambler to be the most comprehensive client-side solution with best-of-breed features.

Powtoon started using Jscrambler’s Code Integrity from the very beginning, so their product never went live unprotected at any stage. The polymorphic JavaScript obfuscation was one the biggest factors in choosing Jscrambler as it proved to be very comprehensive and customizable. Additionally, the variety of runtime protections was deemed helpful.

The Powtoon team also enjoyed using Code Integrity’s dashboard and web interface which they preferred instead of having to use some kind of command line tools that they would need to integrate in a complicated way into their build. However, the biggest deal breaker for Powtoon was the performance aspect. They strived to balance the performance of a very complex application with the need to protect it.

“With Jscrambler, we wanted to protect our competitive advantage. We weren’t the first HTML5 product in the market, but we were the only one that was already an established brand. And we didn’t want to risk it as we were already subject to copycats. Some clones were almost identical to us and they were stealing our graphical assets, which are much more difficult to protect.”
Sven Hoffmann, CTO and Co-Founder at Powtoon

“You do not go for the heaviest protection because it just doesn’t fly with our performance requirements. So you look for the right ratio of reasonable price and a reasonable level of protection with a minimal performance impact. That’s what we got with Jscrambler.”
Sven Hoffmann

CTO and Co-Founder at Powtoon

Top Jscrambler Features and Capabilities

  • State-of-the-art first-party JavaScript obfuscation
  • Smooth integration into the existing CI/CD pipeline
  • Minimal impact on website performance

Results

Powtoon’s platform is protected from IP theft and code tampering. Jscrambler provided a comprehensive first-party code protection solution with a minimal performance impact. The Powtoon team is happy with the solution Jscrambler offers, as well as with customer support and the stress-free relationship.

Scentbird Ensures Customer Trust with the Jscrambler PCI DSS solution

Scentbird Ensures Customer Trust with the Jscrambler PCI DSS solution
Scentbird takes a proactive approach to PCI DSS v4 compliance and protects its payment page with Jscrambler’s compliance solution.

Overview

Scentbird is a subscription service for perfumes, colognes, candles, and car fresheners. Scentbird was founded in NYC in early 2013 and established as a subscription business in 2014. Scentbird enables its users to choose and receive a supply of sample designer fragrances monthly before buying them. It has grown to have more than 700,000 active subscribers.

Challenge

Scentbird has been developing its e-commerce subscription platform in-house. That came with handling many things, including security and compliance and working with multiple payment providers. One of the things that were being asked from one of the payment providers was to be PCI DSS compliant. Aside from that, it was essential for Scentbird to ensure that its audience could trust Scentbird with its data. Andrei Rebrov, CTO & Co-Founder at Scentbird, shares, “The customers should safely leave their credit card information on our website. If people think something is wrong, they will feel unsafe, and there will be no conversion. And if there’s no conversion, there is no revenue.” The Scentbird team realized that with the upcoming change in PCI DSS, they needed a proper way to comply with the specific requirements 6.4.3 and 11.6.1.

The team’s most important question was what was going on with the customer data. Traditional cookie consent management platforms didn’t track who interacted with which form, the changes inside the scripts, or what kind of data was being transmitted outside.

Scentbird mission is to give users fragrance recommendations and personalizations. So, Scentbird has to collect information about the customer and share this information with marketing platforms to fuel personalization. So, it was essential to achieve a balance between the information they gathered, how they treated it, and how they controlled the third-party scripts on their website. They needed a solution to help them control third-party scripts without spending too much time tending to minor changes.

Solution

The Scentbird team first examined several cookie consent management tools that offered PCI DSS compliance. However, they didn’t provide a proper solution and couldn’t answer any specific PCI DSS questions. Another category of solutions they looked at were big enterprise platforms (CDNs, WAFs) that would cost a lot of money and would have you undergo a rigorous integration process. Moreover, Andrei, Scentbird’s Co-Founder, noted that while the major platforms often release features aligned with their general protection offerings, they do not delve deeply into specific matters like PCI DSS v4 compliance.

It was clear to the Scentbird team what they needed to do. Andrei notes, “The Jscrambler team explained how the integration would work, how to prepare for the audit, how to view the rest of the inventory, how notifications about specific changes would be received, how those changes would be reflected, and how we should respond. I appreciate this in a partner—they provided a clear protocol and outlined exactly what I needed to do. I had no additional questions and felt confident about using the product properly.” Andrei shares that it was quite easy to implement the solution, and there were no major obstacles.

“So what starts as a list of around 60 different scripts and pixels and sort of interactions with a third party, might be the list of 100 more with the dependencies. And then when you start looking at the scripts for the past 30 days, you will see a huge list with one script that has changed the version every other day. It’s a minor change, but it’s very annoying.”
Andrei Rebrov

CTO & Co-Founder at Scentbird

“I didn’t want to spend a lot of time having someone on my team manage this. So, I was looking for something I could implement once to ensure we are protected. If something new comes up, the team will reach out to notify me about changes and any actions I need to take, allowing us to focus on what we do best: selling fragrances.”
Andrei Rebrov

CTO & Co-Founder at Scentbird

Top Jscrambler Features and Capabilities

  • PCI DSS v4 compliance status with the Jscrambler Agent
  • Convenient alert mechanisms for PCI DSS compliance
  • Ease of use and quick implementation

Results

Scentbird became PCI DSS-compliant in early 2024, well ahead of the 2025 deadline and earlier than many e-commerce companies. When asked why Scentbird chose Jscrambler, Andrei mentioned the delivery of what they needed to be PCI DSS-compliant, quick implementation, and the quality of the Jscrambler team’s support.

Securing One of the Biggest E-Commerce Websites with Jscrambler

Securing One of the Biggest E-Commerce Websites with Jscrambler
In a landscape where cyber threats are constantly evolving, the Fortune 500 Retail Company’s success with Jscrambler serves as a testament to the efficacy of dedicated client-side protection.

Overview

Established in the 1960s, this client is an iconic American brand boasting four flagship labels. The company recently also expanded its portfolio. As a Fortune 500 company, the company’s commitment to innovation extends beyond the retail industry, delving into the digital realm with a strong online presence and a high-traffic e-commerce platform.

Challenge

In the past decade, the client’s e-commerce traffic has soared, paralleling the rise in online shopping. However, this increase also attracted more frequent and more sophisticated cyber threats. The company witnessed a surge in malicious scripts targeting customer data through various methods, including keylogging, card skimming, and credential hijacking. Confronted with this escalating threat, the client sought robust client-side security solutions to shield its web applications.

The retailer’s broad digital exposure, especially during peak shopping periods like Black Friday, left them vulnerable to attack vectors like JavaScript data exfiltration and script hijacking. To counter these threats, the client required a system that provided comprehensive control to mitigate these kinds of attacks. Additionally, their collaborations with third-party vendors necessitated a security tool that could precisely regulate the data accessible to these third-party tags.

Solution

The retailer sought the right solution to secure its client-side applications against the evolving threat landscape. For an e-commerce platform of their scale, they needed more than just the basics.

The retailer required a security solution that would continue to monitor their website just as effectively in real-time and take appropriate automated action against threats, regardless of traffic volume. Flexibility was equally crucial, especially the ability to restrict data access through form fencing and to oversee all data points on their site comprehensively. Moreover, swift response times were imperative, as the retailer’s success hinged on transforming website visits into sales through an exceptional user experience.

The client’s criteria extended to adaptability and enduring protection. After a thorough evaluation, the retailer identified Jscrambler as the sole contender to meet all of their stringent criteria. Jscrambler’s R&D continuously monitors emerging threats, ensuring the platform evolves to effectively react to the ever-changing cyber threat environment.

As the final deal clincher, Jscrambler gave the retailer a security tool fully focused on client protection. The team already had security tools in their arsenal but didn’t want to rely solely on default security features or add-ons to existing solutions. They believed strongly in a clear separation of responsibilities and were specifically looking for a platform that focused solely on client-side protection, independent of their web application firewall, tag manager, and other existing tools.

“With the kind of traffic we see, data protection for JavaScript, the ability to stop data exfiltration, and field-level protection for sensitive information like credit card details and PII are just the beginning. We also need a solution that can scale up and continue to perform optimally as our business grows. This is absolutely critical.”
Director of Product Security at the Fortune 500 Retail Company

“With Jscrambler, we can maintain the level of security that is critical to running a multinational business and preserving our customer’s trust. The unique layer of security it adds is definitely an integral part of our defense strategy. I’d highly recommend Jscrambler to any other business with a full-blown e-commerce platform that hosts millions of customers daily.”
Director of Product Security at the Fortune 500 Retail Company

Top Jscrambler Features and Capabilities

  • Comprehensive client-side protection
  • Real-time threat mitigation
  • Real-time alerts and reporting

Results

Adopting Jscrambler has provided the retailer with several benefits. Protection from Magecart and skimming risks is crucial for e-commerce platforms, and having Jscrambler covering them on this front helps the client breathe a little easier. They know that sensitive data is protected from exfiltration and hijacking when customers shop on the retailer’s website and that banking and PCI information will remain secure.

FlippingBook Ensures its Code is Protected from Tampering and Reverse Engineering

FlippingBook Ensures its Code is Protected from Tampering and Reverse Engineering
Jscrambler protects a specific, state-of-the-art component of FlippingBook’s web application to shield it from IP theft and copying.

Overview

FlippingBook offers a suite of powerful products for creating, sharing, and managing digital documents online. The company helps businesses improve communication with their audience through engaging digital documents.

FlippingBook’s technology takes plain PDFs to the next level, making them interactive, easy to share as links, and trackable. Companies across various use cases and industries boost audience engagement with their content, deliver their message in a better format, and understand how their documents perform, making informed decisions to enhance their marketing or sales strategy.

Challenge

In the Digital Marketing industry where FlippingBook operates, there’s fierce competition and a constant need to stay innovative. A successful feature can attract the unwanted attention of competitors, so protecting the technology behind it is vital to remain at the top of the field.

Before implementing Jscrambler’s Code Integrity, FlippingBook’s team used basic security measures, which left their code vulnerable to theft. To protect their intellectual property, they decided to look for a strong, reliable, and advanced-level outsourced solution.

Solution

FlippingBook found Jscrambler through a simple Google search while exploring various JavaScript security solutions. Jscrambler’s extensive set of features, combined with positive feedback from other users, made it clear that it was a reliable choice that would give FlippingBook the level of protection they needed without impacting the performance of their platform. Jscrambler’s focus on comprehensive security, especially protecting intellectual property in web apps, led the team to believe it was the right fit for FlippingBook.

Tim shares, ‘We were looking for a solution that would provide an advanced level of protection against code theft and copying. At the same time, it had to be efficient enough not to interfere with the performance of our own application. Plus, a straightforward CLI integration was a must, and Jscrambler covered that need as well.’ In addition to the seamless CLI integration and trustworthy code protection, FlippingBook’s team appreciates that Jscrambler doesn’t require constant maintenance, so they can focus on internal workflows and innovations while the Code Integrity product keeps their code secure in the background.

“Several years ago, we discovered that our code had been copied by a third party, and we knew we needed to take serious action. Our research indicated that JavaScript obfuscation would be an effective measure to protect our code from such incidents in the future.”
Tim Akhmetvaleev

Head of Sales at FlippingBook

“Our main objective for implementing Code Integrity was to prevent any future code theft attempts and secure the unique, state-of-the-art components of our technology that differentiate us in the market. By using Jscrambler, we wanted to create a robust line of defense around our code, ensuring that it couldn’t be copied or reverse-engineered.”
Tim Akhmetvaleev

Head of Sales at FlippingBook

Top Jscrambler Features and Capabilities

  • Advanced protection through code obfuscation
  • Convenient CLI integration
  • Reliable and responsive customer support

Results

The Code Integrity product gives FlippingBook a competitive edge. By keeping FlippingBook’s code secure from the prying eye of third-party tools, Jscrambler maintains FlippingBook’s image as the innovator and front-runner in the market of digital flipbooks.

Thus, their unique flipbook tech remains unmatched in its sophistication and authenticity compared to other tools out there.

How Bionano Genomics Increased Compliance with Regulations Using Jscrambler

Bionano Increases Compliance with Regulations Using Jscrambler
Jscrambler provided Bionano with the most resilient JavaScript protection and satisfied the regulatory requirements for code protection.

Overview

Bionano is a biotechnology company specializing in genome mapping and analysis and can enable researchers and clinicians to reveal answers to challenging questions in biology and medicine. Bionano’s mission is to transform how the world sees the genome through optical genome mapping (OGM) solutions, diagnostic services, and software. Bionano also offers an industry-leading, platform-agnostic genome analysis software solution and nucleic acid extraction and purification solutions using proprietary isotachophoresis (ITP) technology.

Challenge

Each time Bionano engages in an enterprise-level clinical environment, they are subjected to a rigorous security audit. By interacting with many security organizations globally, they gained an in-depth understanding of what these security organizations expected.

Bionano chose Node.js as its visualization platform as it facilitated reaching the widest audience of users (macOS, PC, and Linux). It also provided an extensive array of visualization tools such as D3js, ThreeJS, and ChartJS that allow the creation of rich interactive genomic maps for customers to explore. Bionano software is free to encourage the use of Saphyr-generated data. Anyone can download and start their own Bionano Access Server. Bionano needed a way to protect their downloaded client and server-side JavaScript logic to satisfy multiple security regulations

Solution

The Bionano system itself is designed not to hold protected private information (PPI), so the company did not face significant liability to be concerned with. However, as an extra precaution and to be as compliant as possible, the company understood the need for JavaScript code protection. In search of the optimal solution, Bionano tested some JavaScript obfuscation solutions but found out that these could be easily reversed or debugged. Jscrambler was the only solution that passed all their tests and which they could not reverse.

This implementation of Jscrambler was greatly derived from the need to comply with several different regulatory requirements. In the specific case of Bionano, the regulations that apply to their clinical customers vary depending on their local principalities. Some regulations, like ISO 27001 and 27002, specifically require source code protections, while others have more general data protection and/or encryption requirements.

Jscrambler does not solve all of Bionano’s security concerns, but it provides what the company needs to protect the source code enough to satisfy all regulations in that regard. Then, there’s also the matter of protecting intellectual property. Bionano’s system provides comprehensive genomic variation data for review.

“Jscrambler was the only product we found that could not be cracked.”
Scott Way

Director of High-Performance Computing and Genome Visualization at Bionano

“We needed our Node.js application protected to satisfy multiple data protection regulations in customer clinical environments. Jscrambler did that for us, and it was easy to incorporate into our tech landscape.”
Scott Way

Director of High-Performance Computing and Genome Visualization at Bionano

Top Jscrambler Features and Capabilities

  • Resilient JavaScript obfuscation
  • Built-in protection against reverse-engineering tools
  • Anti-tampering and antidebugging capabilities

Results

Thanks to the source code protection provided by Jscrambler, Bionano now obfuscates its code and can prevent debugging. This allows them to satisfy the security concerns of their clinical customers and continue using the platform that gave them the best value.

Jscrambler Helps Neobanks Protect JavaScript

How Neobanks Strengthen Client-Side Security with Jscrambler
Several of the world’s leading neobanks and challenger banks turned to Jscrambler to strengthen the security of their web applications as digital channels became central to customer experience and revenue growth. Operating in highly regulated environments and handling sensitive financial data at scale, these institutions needed to protect their client-side JavaScript from reverse engineering,
tampering, and logic abuse.

Overview

Neobanks defy traditional banking by betting everything on digital and delivering customer-centric services for payments and money management. Today, over 90% of consumer interactions with banks are digital. Neobanks typically release new features more frequently, often every few weeks, while traditional banks tend to take several months to bring similar innovations to market. As a result, user satisfaction ratings for neobanks in the US (63%) are higher than those of traditional banks (55%).

Neobanks’ technological flexibility stems from investing in cloud-based infrastructure and advanced web and mobile applications built with modern JavaScript frameworks such as React Native. With this approach, they cut product development cost and time, paving the way for rapid iteration and innovation. This is greatly aided by relying on third-party integrations rather than developing every piece of code in-house. In software development, pursuing agility and speed often means widening security gaps. Despite JavaScript’s numerous advantages, neobanks must be aware that client-side JavaScript is exposed and can be used to launch attacks, including intellectual property theft, code tampering, application abuse, and data exfiltration. Unless protected with an enterprise-grade solution, this exposed JavaScript poses a key business threat.

Challenge

In recent years, several neobanks from North and South America, Europe, and Asia have approached Jscrambler due to significant security challenges. With web and mobile apps built with JavaScript — and a strong adoption of cross-platform frameworks for mobile development like React Native and Ionic — security teams understood early on that client-side logic would pose a significant security risk. There was a high likelihood of having to run sensitive logic on the client-side, so it became paramount to ensure that this logic would be concealed using the most potent and resilient technology available today. It was also mandatory to ensure that automated reverse-engineering tools would always fail to reverse the concealed code, while making it extremely unfeasible for attackers to achieve it manually. As these neobanks’ apps would handle sensitive services, another key challenge was ensuring that malicious actors couldn’t tamper with the code. JavaScript had to react in runtime to mitigate these attacks. And since both the web and mobile apps would handle sensitive data, such as credentials, personally identifiable information, and financial details, an additional pre-eminent requirement was to ensure that JavaScript couldn’t serve as a gateway for attackers to steal user data.

With each neobank offering multiple applications to their end customers, it was also essential to ensure that JavaScript protection would integrate seamlessly with their CI/CD and integration testing. Finally, in such a heavily regulated sector, another significant challenge was achieving compliance with regulations such as PSD2, NIST, the PCI DSS requirements 6.4.3 and 11.6.1, and specific requirements for operation like those of Bank of Brazil, for example, with a special focus on client-side attacks.

Solution

To meet the highest standards for JavaScript protection, these neobanks sought a holistic solution that would fit their processes and scale. Jscrambler presented a mature, proven client-side security product suite that, like noobanks themselves, is defined by continuous innovation.

The first step towards securing JavaScript was Jscrambler’s polymorphic obfuscation. With this critical security layer, all of the source code of neobanks’ apps was concealed beyond possible recognition. Jscrambler’s set of the most potent and resilient transformations was key to guaranteeing cutting-edge obfuscation. Its inherent polymorphism ensured that each new code deployment would be completely different—an extra line of defense against reverse-engineering attempts. For example, one of the banks had their fingerprinting script collect information from the session/browser, and wanted to protect it as it was exposed. Jscrambler provided the neobank with advanced polymorphic obfuscation to allow it to serve its fingerprinting script (practically unique) in each user session.

Security teams implemented critical OWASP recommendations, including the OWASP Mobile Top 10, which highlights that “to prevent effective reverse engineering, you must use an obfuscation tool” and that “the app must be able to react appropriately at runtime to a code integrity violation.” At the same time, they ensured compliance with PSD2 mandates, including transaction monitoring and strong customer authentication, as well as PCI DSS v4 requirements to safeguard payment pages and credit card data from client-side tampering. In addition, they aligned their client-side security measures with NIST guidelines, strengthening code integrity, runtime protections, and risk management practices in line with industry-standard cybersecurity frameworks. Jscrambler mostly worked with Security Engineers at these banks who were well aware of the problem and the required steps for solving it. After the initial setup of the Jscrambler instance, it took on average 2 weeks and 2 meetings with Jscrambler’s engineers to integrate Jscrambler seamlessly into their CI/CD pipeline. From there, Jscrambler became an automated part of their application build process.

Top Jscrambler Features and Capabilities

  • Polymorphic obfuscation
  • Anti-Tampering
  • Compliance with financial regulations and standards

Results

Securing JavaScript code requires awareness of the threats posed by exposing important logic on the client-side. Neobanks have had this pain from the very start of the business, as their main assets depend on it. By opting for Jscrambler’s proven JavaScript protection technology, product teams met their primary requirement: integrating a code protection solution seamlessly into their CI/CD. Now, these neobanks deploy secure code to production, knowing that each build has a fresh set of the most potent and resilient JavaScript protection available today. Jscrambler helped neobanks rethink key and critical data management in the applications, moving keys into JavaScript and applying Jscrambler Code Integrity to protect them effectively.

Through advanced obfuscation techniques, anti-debugging protections, and tamper detection, the solution prevented key theft, code tampering, and reverse engineering, ensuring the web application remained protected even when running on the client side. For management, safeguarding their applications’ source code from reverse engineering and tampering translates into a clear competitive advantage. Investors also recognized the reduced liability associated with exposed JavaScript in neobanking; with Jscrambler, these banks strengthened their position in future funding rounds and earned the trust of millions of potential customers. In a results-driven industry, the outcome was unequivocal: 0 integration issues, 0 successful attacks on JavaScript code.

How Jscrambler Helps dotConnect Deliver Secure Banking Apps

How Jscrambler Helps dotConnect Deliver Secure Banking Apps
Jscrambler successfully protects and secures the source code of the banking applications.

Overview

dotConnect is a fintech with the vision to empower financial institutions to provide their clients with a platform that delivers an exceptional digital banking experience. Via cloud-native solution architecture that is built for scale and resilience, dotConnect allows banks to accelerate their digital transformation and automation journeys. This enables these banks to provide a modern, customer-focused digital experience, reduce operational service requirements, and achieve low and predictable operational costs while also guaranteeing flexible integration with new and legacy banking systems using a decoupled approach.

Challenge

Today, 73% of all consumer interactions with banks are done digitally. And when it comes to banking, security is a prime directive. When asked about the most important attributes when choosing a bank, 82% of consumers say, “ensures my transactions are safe/secure.” Being aware of how security is one of the key drivers in the ongoing banking digitalization, dotConnect wanted to ensure that they were developing secure banking apps. This meant covering every inch of the attack surface.

Regarding web and hybrid mobile banking apps, one key security challenge is protecting the JavaScript code, which can be targeted by reverse-engineering, tampering, and injection attempts. This layer of protection is essential to reduce exposure to data exfiltration and transaction fraud, which can originate from client-side attack vectors.

Solution

The answer to dotConnect’s challenges in terms of source code protection was the cutting-edge technology provided by Jscrambler. Both founders had previously used Jscrambler in a previous solution within the banking sector a few years ago. So, when embarking on this new venture, they revisited the market to compare vendors and found that Jscrambler was still the market-leading solution in this sector. Thus, it was the obvious choice. Because dotConnect had to ensure maximum protection of the JavaScript source code, its team decided to combine two of Jscrambler’s most effective clientside security layers: JavaScript Obfuscation and Self-Defending.

Jscrambler’s Polymorphic JavaScript Obfuscation includes several different techniques that transform the original source code into a new version that is extremely hard to understand and reverse-engineer while keeping its original functionality. Included in this layer is Jscrambler’s Code Hardening feature, which provides up-to-date protection against all reverse-engineering tools and techniques.

dotConnect uses Jscrambler Self-Defending, a security layer that adds integrity checks and other runtime defenses that prevent attackers from debugging or tampering with the code. As such, if anyone tries to debug the protected banking app at runtime, the app will immediately break. Likewise, if an attacker tries to modify the code to dynamically understand its logic at runtime, the application will break to stop the attack. This advanced runtime protection reduces the attack surface to data exfiltration attacks by making it much harder for attackers to understand how the software works and plan/ automate these attacks

“When you have a financial product out in the public domain, you’re a prime target for attackers.”
Mohamed Gamil

CEO & Founder of dotConnect

“The protection layer that Jscrambler provides is very, very difficult to interpret, break, or bypass.”
Mohamed Gamil

CEO & Founder of dotConnect

Top Jscrambler Features and Capabilities

Polymorphic JavaScript Obfuscation
Self-Defending
Code Hardening

Results

dotConnect development team had no issues integrating Jscrambler into the CI build process, thanks to detailed documentation and support. One requirement of dotConnect was to pass their clients’ and their own strict penetration testing rounds. Jscrambler helped them achieve that by passing 5 penetration testing rounds.

Top European Airline Ensures Stellar Client-Side Protection with Jscrambler

Top European Airline Ensures Stellar Client-Side Protection with Jscrambler
Jscrambler’s advanced script and form security protection ensures sensitive form data is protected and malicious scripts cannot load.

Overview

This European airline is a global leader in air transportation that operates an extensive flight network connecting Europe to the world through its hubs in European capitals. With over 70,000 dedicated employees and a commitment to diversity, the airline serves millions of passengers across 300 destinations in 120 countries. A large portion of these passengers uses the company’s websites and mobile apps to book flights, check in online, chat with customer service, and redeem loyalty points.

Challenge

The client’s decision to search for client-side protection technology was initially triggered by a credit card data breach at another airline.

Before implementing Jscrambler, the client relied on more traditional security processes that involved checklists and paperwork. However, this manual approach left room for vulnerabilities: “We had security people who could decompile libraries, but they were usually too busy to do it.”.

When the client’s team needed to go fast and add new scripts, innovation sometimes took priority, which meant they would find workarounds to circumvent the documentation-heavy process, leaving them potentially open to attack.

Solution

In search of a comprehensive JavaScript monitoring and protection solution, the client considered various factors, including features and cost. Jscrambler stood out as the only solution that met their security requirements.

The client was particularly impressed by Jscrambler’s Form Fencing feature, which offers fine-grained behavioral control over third-party tag access to form data based on high-level assumptions and user-defined rules. Unlike other solutions, Jscrambler allowed the airline to authorize or block scripts individually.

The company put Jscrambler’s Webpage Integrity solution to the test in multiple Magecart attack scenarios. They ran dozens of tests to see if the solution could detect if content was added, modified, or removed from pages illicitly (DOM tampering), if form events were poisoned, or if data was exfiltrated to a drop server. Jscrambler’s technology passed every single test with flying colors and outperformed all the other available solutions. Adding Jscrambler to a page had little to no impact on its performance.

“Other solutions allow you to monitor cross-site scripting or visit CSP policies, but that’s all they do. They won’t protect forms. They won’t ask, “Is this sensitive data? Yes or no?” For us, Jscrambler was the best platform because they do it all.”
Information Analyst and Product Owner Mobile at Top European Airline

“With most companies, you buy a product, you get support for one or two months, and then you’re on your own. But with Jscrambler, we meet regularly twice a month. We know when new features are coming, even if they haven’t been released yet because they’ll tell us about them on our call and ask us what we think. It’s a nice dialogue to have. You really feel the personal touch. Jscrambler’s customer support is definitely a big plus.”
Information Analyst and Product Owner Mobile at Top European Airline

Top Jscrambler Features and Capabilities

  • Full Visibility and Control
  • Form Fencing
  • PCI DSS Compliance

Results

With zero security incidents, increased efficiency, and peace of mind, Jscrambler has become an integral part of the airline’s strategy for maintaining the highest security standards in today’s evolving digital landscape. The client attests, “We sleep easier at night because we know that the people at Jscrambler are looking out for us and our clients.”