Appdome has customer identity protection for the mobile economy

Appdome, the provider of protection for mobile businesses, has announced IDAnchor, the industry’s first customer identity protection (CIP) solution for the mobile economy. 

IDAnchor fingerprints each release, installation, and device used to access, log in, and generate transactions in a mobile app. It combines this chain of trust with real-time threat signals to bring sign-in alerts and unrecognised device notifications to every mobile app in the world, creating perimeter defenses around identity verification (IDV), customer identity and access management (CIAM), as well as other services in mobile apps.

“Mobile brands have learned the hard way that successful authentication doesn’t mean there’s a trusted identity, engagement, or transaction in an app,” said Tom Tovar, Co-Creator of Appdome. 

“They also want the ability to tell when there’s unauthorised activity on an unrecognised device, application, or installation. IDAnchor solves all these challenges easily.” 

Customer identity protection (CIP) is the missing link needed to strengthen biometric authentication, CIAM, and IDV in mobile apps, Appdome said. CIP ensures that no part of the value chain – the mobile app, installation, or device – has been compromised or impersonated during login, authentication, engagement, or purchasing in mobile apps.

Mobile apps and identity products often assume the integrity of the mobile environment when creating, verifying, or using customer identities in mobile apps. However, fake or compromised devices, operating systems, and accounts, as well as malware-controlled sessions, can undermine signal fidelity from mobile environments. 

CIP monitors the source of each customer identity while it’s being used by the application, installation, device, or user. It can detect if any part of that value chain has been compromised or impersonated, or if there are any signs of on-device threat staging, manipulation, spyware, and other risks that can compromise biometric authentication, CIAM, IDV, ad attribution, and other processes in a mobile app. 

Unlike static and ephemeral device binding, IDAnchor creates a living, cryptographically-bound, tamper-resistant chain of trust that spans the entire mobile app lifecycle. IDAnchor fingerprints the mobile DevOps workspace and each app release, installation, device, and session to enable mobile brands to bind customer identity from the point of origin, through the distribution chain, to user acquisition and use in a mobile app.

Each IDAnchor fingerprint is securely stored and built to persist across device resets, app re-installs, operating system (OS) updates, and sophisticated evasion techniques, including device cloning, app spoofing, Trojan installations, and threats that target customer identity in mobile apps. 

Mobile brands can now offer their users the same powerful, real-time “Is this you?” sign-in alerts made famous across Apple and Google applications. Detect sign-ins or identity assertions from unrecognised devices, apps, or installs and trigger real-time responses like user-facing alerts, step-up authentication, or session blocks. From mobile banking to social, healthcare, and ride-sharing apps, Appdome makes it possible for every mobile brand to own the authorisation-to-operate (ATO) moment and protect users with confidence.

IDAnchor gives brands a dynamic way to know if the source of the identity assertion can be trusted and if the user’s device, instance and environment are real, the same, unaltered, and uncompromised before, during, and after calling any identity-based service,” said Avi Yehuda, Co-Creator and CTO of Appdome. 

IDAnchor combines real-time threat signals with the chain of trust to solve a wide range of mobile threats, including: 

- Deepfake attacks used on alternative or compromised devices. 

- Know your customer (KYC) fraud and fake account creation on synthetic, cloned, or altered mobile devices. 

- Install/re-install abuse for inflating ad campaign metrics. 

- Emulator farms that mimic real user engagement and devices. 

- Loyalty and referral abuse from Google Advertising ID/identifier for advertisers (GAID/IDFA) and device resets.

- Social engineering scams where users are tricked into installing Trojan versions of legitimate apps. 

- Geo-fraud carried out through location spoofing, fake GPS apps, virtual private networks (VPNs), Internet protocol (IP) cycling, and other techniques. GPS stands for the Global Positioning System. 

- Transaction and on-device fraud carried out by attackers using fake devices, synthetic identities, and stolen credentials.

“Without CIP, anyone or anything could successfully authenticate or engage inside an app,” said Chris Roeckl, Chief Product Officer at Appdome. 

“With IDAnchor, brands can detect the full range of fraud, ATOs, and scams and get the true device attributes being used in each session.” 

Key features include:

- DevOps workspace fingerprint: IDAnchor uses the DevOps environment to create a trusted root identifier for the mobile app. 

- App release fingerprint: Unique mobile app release IDs do not change or reset based on device or install. There is no user opt-out.

- App install fingerprint: Each mobile app installation ID resets on update or upgrade. There is no user opt-out.

- Mobile device fingerprint: IDAnchor creates a unique and immutable mobile device ID for Android and iOS devices. No resets are possible. There is no user opt-out.

- True device attributes: With each payload, IDAnchor provides the true device attributes for each mobile device. 

- Anti-device spoofing:Prevents modified or impersonated device attributes and bypassing probabilistic device identity systems. 

- Anti-vendor ID spoofing: Prevents tampering with or rotating unique device identifiers that attribution systems or apps rely on to track installs, users, and fraud. 

- Anti-advertiser ID cycling: Prevents attackers from rotating GAID/IDFA values to appear as unique users per fraud event. 

- Protects Google/Apple Advertising IDs: Monitors Google/Apple’s advertiser IDs for signs of manipulation, reuse, or substitution. 

IDAnchor manipulation detection: Sends threat data and telemetry if attackers target IDAnchor. 

- Threat signal intelligence: Send threat data and telemetry on 400+ attack vectors including deepfakes, device spoofing, device manipulation, remote code execution (RCE), remote access Trojan (RAT), automatic transfer system (ATS) malware, social engineering scams, IT scams, phishing, quishing (QR code phishing), smishing (SMS phishing), geo-fraud and other attacks.

"Identity is the new perimeter,” said Eric Newcomer, Analyst at Intellyx. 

“Customer identity protection is more important than ever, given the advances in AI deepfakes, the rise of identity spoofing, and the use of mobile devices as an attack vector. IDAnchor from Appdome strengthens the value of CIAM, IDV and ad attribution by tracking the true identity of the applications and devices connecting to enterprise services.”

Details

IDAnchor is available for all Android and iOS applications. Mobile brands can use and evaluate IDAnchor fingerprints in the app, via an on-premise server, or within a cloud service.

Comments

Popular posts from this blog

Fortinet enhances FortiRecon to align with CTEM framework

SentinelOne recognised as a 2025 Gartner Peer Insights Customers’ Choice for XDR

AWS: AI adoption grows 20% in Singapore