Approov
Security and Compliance of the Approov Solution
Pages
6
Time to read
18 mins
Publication
Language
English
Pages
6
Time to read
18 mins
Publication
Language
English
This white paper describes the security aspects of the Approov solution and outlines best practices for integrating the solution into an organization's security and compliance framework. It is intended for security and compliance teams as part of the Approov evaluation process. The document details the overall architecture of the Approov solution, including the use of the Approov CLI tool for app registration and the integration of the Approov SDK into mobile applications. It explains the integrity measurement process, which involves communication between the SDK and the Approov cloud service to ensure secure runtime delivery of API keys and tokens. The paper also discusses the protection mechanisms employed within the SDK, such as obfuscated native code and runtime address integration, to prevent spoofing and tampering. Additionally, it covers user authentication and authorization processes, communication security, and data protection measures, emphasizing that no personally identifiable information is stored by Approov.