Strengthening Authentication, Fraud Prevention and Risk Governance Become Top Priorities for Philippine Banks

To strengthen fraud prevention, the Bangko Sentral ng Pilipinas (BSP), under Circular No. 1213, requires institutions to adopt enhanced authentication methods in place of SMS and email OTPs, while also strengthening automated fraud management systems. According to BSP Circular No. 1213, issued in May 2025, the central bank requires BSP-supervised financial institutions to replace SMS- and email-based OTPs with stronger authentication methods such as biometrics, behavioural authentication, adaptive authentication, or passwordless authentication by 25 June 2026. In addition, the circular sets out specific requirements for strengthening automated fraud monitoring. This directive applies to banks and e-wallet operators with average online transaction revenues of more than PHP 75 million per month, including most commercial banks, digital banks, cooperative banks, and rural banks. Banks that fail to comply must reimburse customers for funds lost due to fraud.  1. Authentication and Compliance Requirements  Circular 1213 requires institutions to move away from authentication mechanisms that can be shared with or intercepted by third parties. SMS and email OTPs fall under this definition. By 30 June 2026, high-risk transactions and critical account changes must use phishing-resistant, device-bound alternatives, such as server-side biometrics authenticated against templates stored by the bank, or FIDO2/WebAuthn passkeys with device authentication. OTPs may only be used to confirm ownership of a registered mobile phone number. Biometrics  BSP requires financial institutions to adopt server-side biometric authentication, where customer identity is verified within the bank’s secure backend system based on biometric templates stored on the bank’s server. The use of biometrics is expected to reduce the risks of account takeover, device compromise, spoofing, and unauthorized changes to authentication credentials. FIDO2 Passkey  FIDO2/WebAuthn is a passwordless authentication standard designated by BSP as a mandatory solution for high-risk transactions and critical account changes, which must use phishing-resistant and device-bound alternatives. Smart OTP  As mentioned above, Smart OTP is used for one purpose only: confirming ownership of a registered mobile phone number. It must not be used for transaction authentication. This is an important distinction that banks should note to avoid confusion with traditional OTPs. 2. Fraud Prevention and Management Requirements  In addition to strong authentication methods, Circular 1213 also requires financial and banking institutions to strengthen their proactive fraud monitoring and detection capabilities by identifying suspicious transactions, unfamiliar devices, and abnormal customer behaviour before financial losses occur. Accordingly, fraud management systems must operate in real time and be capable of: BSP emphasizes that batch processing or end-of-day reconciliation does not meet this standard.  3. AI-Powered Strong Authentication and Fraud Prevention Solutions from Savyint   With extensive experience working with and supporting financial institutions, SAVYINT provides a security and fraud prevention solution suite that supports compliance with AFASA and BSP Circulars 1213, 1214, and 1215. The solution suite is built around four pillars: strong and passwordless authentication; AI-powered fraud management; security, data encryption, and application protection; and risk management and compliance with local and international regulatory requirements. It ensures end-to-end protection across the entire customer journey, from registration, login, and transaction authentication to post-transaction monitoring. Key differentiators of the SAVYINT solution suite include:  In particular, Savyint’s solution suite supports compliance with regulatory requirements in multiple countries, including the Philippines, such as AFASA and BSP Circulars 1213-1215; Vietnam, such as Circulars 50, 64, and 77 of the State Bank of Vietnam; and Singapore, such as MAS requirements. It also aligns with international security standards including FIDO2, PSD2/PSD3, eIDAS, GDPR, PCI DSS,… Connect with our experts today to quickly achieve compliance with AFASA and BSP Circulars 1213-1215.

Top 6 Benefits of Zero Trust Security Architecture 

As cyberattacks become increasingly sophisticated, traditional security models such as firewalls, VPNs, or trusted internal networks are no longer sufficient to protect modern enterprises. Zero Trust Architecture has emerged as a critical approach in today’s cybersecurity landscape, helping organizations strengthen protection across users, devices, applications, data, and digital transactions.  What is Zero Trust Architecture?  Zero Trust Architecture is a modern security model built on the principle of “never trust, always verify.” It is designed for today’s complex, distributed, and increasingly cloud-based IT environments.  Unlike traditional security models, Zero Trust requires every access request to be continuously verified, whether it originates from inside or outside the organization.  Zero Trust Architecture typically combines multiple security technologies, including:  Key Benefits of Zero Trust Security Architecture  Implementing Zero Trust can bring significant benefits to enterprises and organizations, including:  1. Strengthening Comprehensive Security Against Advanced Threats  Zero Trust helps organizations defend against threats such as ransomware, phishing, compromised accounts, and insider risks.  By enforcing least-privilege access and continuous verification, businesses can significantly reduce the risk of attackers exploiting exposed credentials to access sensitive systems and data.  2. Reducing the Risk of Data Breaches  Since every access request must be verified, attackers cannot easily reach sensitive data even if they manage to compromise an account or device.  This helps limit unauthorized access, reduce lateral movement within the system, and minimize the potential impact of security incidents.  3. Improving Monitoring and Incident Detection  Zero Trust enables organizations to monitor user behavior, devices, applications, and access activities in real time.  With stronger visibility across the digital environment, businesses can detect unusual activities earlier, respond to risks more quickly, and improve their overall incident response capability.  4. Supporting Remote Work, Cloud, and Hybrid Infrastructure  With Zero Trust, users can securely access enterprise resources from anywhere, as long as their identity, device, and access permissions are properly verified.  This is especially valuable for remote and hybrid work models, where employees may access corporate systems from different locations, networks, and personal devices.  5. Enhancing Regulatory Compliance  Zero Trust provides a unified governance framework for enforcing security policies, authenticating users, managing access rights, and maintaining activity logs.  This allows organizations to better meet data protection and information security requirements in highly regulated sectors such as finance, banking, healthcare, telecommunications, and government.  6. Optimizing Long-Term Security Costs  While Zero Trust implementation may require initial investment, it can help optimize security costs in the long run.  By consolidating security controls, reducing the likelihood of data breaches, and limiting damage when incidents occur, Zero Trust helps organizations build a more sustainable and cost-effective cybersecurity strategy.  A Comprehensive Zero Trust-Based Security and Fraud Prevention Solution for BFSI Organizations  With deep experience in the Finance and Banking sector and a proven track record of implementing projects for major banks, SAVYINT introducs e a comprehensive security and fraud prevention solution built on Zero Trust Architecture.  Aligned with the core pillars of modern Zero Trust, SAVYINT’ solution enables end-to-end protection across users, devices, applications, data, and digital transactions: + Identity verification and user access control + Establish device trust + Real-time application protection with RASP+ + API security and third-party connectivity + Consent management and personal data protection + AI/ML integration, transaction risk assessment, and real-time fraud prevention + Automated compliance reporting + Support compliance with Vietnamese regulations, including Circular 50, Circular 64, Circular 77 of the State Bank of Vietnam, Decree 356, the Data Protection Law, and the Cybersecurity Law,…; international standards such as eIDAS, GDPR, and PCI-DSS…; and regional regulations such as Malaysia’s PDPA and RMiT, and the Philippines’ AFASA and BSP 1213–1215… Connect with SAVYINT experts today to take the lead in enterprise-wide security and fraud prevention! Read more: Zero Trust – A Next-Gen Security Architecture for Vietnamese Banks Amid Increasingly Stringent Regulations

Zero Trust – A Next-Gen Security Architecture for Vietnamese Banks Amid Increasingly Stringent Regulations

Zero Trust – A Next-Generation Security Architecture for Vietnamese Banks Amid Increasingly Stringent Regulations

Vietnam’s financial and banking sector is entering a phase of significantly tightened requirements for security, data protection, and fraud prevention. From Circular 50, Circular 77, and Circular 64 issued by the State Bank of Vietnam, to the Personal Data Protection Law, Decree 356, and the Cybersecurity Law 2025, financial institutions are no longer required to simply have security systems – they must prove that these systems are reliable, secure, and capable of real-time risk control. Over the past five years, regulations in Vietnam’s financial and banking sector have clearly shifted – from system-level security requirements to comprehensive control and enhanced protection across the entire digital customer journey. Notably, since 2024, the Vietnamese government has introduced a series of policies to strengthen information security, data protection, and cybersecurity. Online Service Security Circular 50/2024/TT-NHNN establishes a comprehensive foundation for securing online banking services, covering customer authentication, transaction data protection, and responsibilities for guiding users about risks. However, the real tightening comes with Circular 77/2025/TT-NHNN, which amends Circular 50 and takes effect from March 1, 2026. Accordingly, financial institutions must place strong emphasis on endpoint security (Mobile Apps). Mobile banking applications are required to automatically log out or stop functioning if detecting: rooted/jailbroken devices, emulators, debuggers, etc. Server systems must implement version control mechanisms, prevent users from downgrading versions, and ensure software is protected against the top 10 common vulnerabilities (OWASP). Stronger identity verification is required in high-risk scenarios, mandating biometric authentication combined with high-level verification when customers change identity documents or authentication methods. Circular 64/2024/TT-NHNN sets strict technical standards for open system connectivity architecture, requiring data structures using JSON or XML via REST APIs. APIs must be digitally signed (JWS) and encrypted. It also mandates identity and access management between banks, customers, and third parties (TPPs) based on OAuth 2.0 standards. Personal Data Protection The Personal Data Protection Law No. 91/2025/QH15, effective from January 1, 2026, marks a significant milestone in privacy protection in Vietnam. The law requires technical controls embedded directly into system architecture, including mandatory encryption/decryption of sensitive data, implementation of data anonymization processes to prevent re-identification, and compulsory impact assessments for data processing and cross-border data transfers. Systems involving Big Data, AI, Blockchain, and Cloud must integrate appropriate security measures with strict access controls. Additionally, the law requires the establishment of identity governance mechanisms based on user consent, with features allowing customers to monitor, view, modify, or withdraw their consent. Decree 356/2025/NĐ-CP, which guides the implementation of the law and replaces Decree 13/2023, establishes a robust technical and legal “barrier,” requiring organizations to implement dual verification mechanisms in personal data processing. Systems must support verifiable consent logging (e.g., OTP, voice recordings, SMS). Access to sensitive data requires strong authentication methods, at minimum multi-factor authentication (MFA), combining passwords with OTP, digital signature devices, or biometrics. These requirements exceed the capabilities of most existing identity and access management systems. Cybersecurity The Cybersecurity Law 2025, effective July 1, 2026, establishes a framework for protecting information systems based on five risk levels. It clearly defines the responsibility of online service providers to verify user information during digital account registration and secure user account data. This compels financial institutions to treat digital security as a core capability rather than a supporting technical function. Zero Trust Architecture Zero Trust is a modern security architecture based on the principle “Never trust, always verify,” designed for complex and distributed systems. Instead of inherently trusting users or devices within the network, Zero Trust continuously verifies five key pillars: user identity, devices, networks, applications, and data. Every access request must be authenticated, authorized, and continuously monitored. This model enforces strict control over identity, device posture, applications, data, and user behavior in real time. The three core principles of Zero Trust include: By applying these principles, Zero Trust helps organizations reduce cyberattack risks, limit lateral movement within systems, and protect digital assets across cloud, mobile, IoT, and remote working environments. Comprehensive Security and Fraud Prevention Solution for Banks With extensive experience in the financial and banking sector, Savyint introduces a comprehensive security and fraud prevention solution based on Zero Trust architecture. This solution enables financial institutions to comply with stringent legal requirements both domestically and internationally while addressing key challenges including user authentication, device and application protection, API security, consent management, fraud prevention, transaction risk control, and compliance: Beyond compliance with Vietnamese regulations, Savyint’s security and fraud prevention solutions also strictly adhere to international standards such as eIDAS, GDPR, PCI-DSS, as well as regional regulations in countries like Malaysia (PDPA, RMiT) and the Philippines (AFASA, BSP 1213-1215). Connect with Savyint experts today to ensure secure operations and full compliance with both domestic and international regulations.

Biometrics, Smart OTP, Smart Token, Passkey/FIDO2: Passwordless Authentication for Stronger Financial Fraud Prevention

Biometrics, Smart OTP, Smart Token, PasskeyFIDO2 Passwordless Authentication for Stronger Financial Fraud Prevention

As digital banking and mobile banking make payments and account management more convenient, financial fraud is also increasing at a rapid pace. Technologies such as biometrics, Smart OTP, Smart Token, and Passkey/FIDO2 are emerging as next-generation authentication methods. These passwordless authentication technologies help banks and financial institutions strengthen transaction security while significantly improving fraud prevention. Traditional authentication methods are no longer secure enough For many years, banking transactions have mainly relied on traditional authentication methods such as passwords, SMS OTP, and security questions. However, these methods are increasingly showing critical security weaknesses:  In response, financial regulators around the world are tightening requirements for strong authentication and encouraging banks and financial institutions to adopt more secure authentication technologies. Some notable regulations include:  These regulations clearly reflect a global trend: passwordless authentication methods such as biometrics, Smart OTP, and Smart Token are becoming the new standard for financial security. Why are biometrics, Smart OTP, and Smart Token more secure than traditional authentication? Smart OTP  Smart OTP has become a widely adopted authentication method in digital banking. Unlike SMS OTP, Smart OTP is generated directly inside the banking application, tied to the user’s device and protected by cryptographic keys. Key advantages of Smart OTP: As a result, Smart OTP provides a critical additional security layer to protect digital banking transactions. Smart Token  Alongside Smart OTP, Smart Token is another strong authentication method widely used by banks for high-value transactions. Smart Tokens can exist in different forms: Unlike standard OTP mechanisms, Smart Tokens use cryptographic algorithms to generate dynamic authentication codes tied to specific transactions. This provides several security benefits:  Because of their strong security capabilities, Smart Tokens are often deployed as an additional authentication layer in electronic banking systems. Biometrics  Biometric authentication verifies a user based on biological or behavioral characteristics. Common biometric technologies used in digital banking include: Unlike passwords or OTP codes, biometric traits are unique to each individual and extremely difficult to replicate or forge, ensuring that the person performing the transaction is truly the legitimate account holder. Another major advantage of biometrics is user convenience. Customers no longer need to remember passwords or wait for OTP codes. A simple fingerprint scan or facial recognition can authenticate a transaction instantly. A growing trend in fraud prevention is behavioral biometrics. Instead of relying on physical traits, this technology analyzes how users interact with their devices, such as: Typing speed, Screen swipe patterns, App usage behavior,…Users do not need to perform any additional authentication step, yet the system can still detect suspicious behavior in real time. Passkey / FIDO2  Another rapidly growing passwordless authentication trend is Passkey/FIDO2. A passkey is a FIDO-based credential that allows users to sign in to apps and websites using the same method they use to unlock their devices – biometrics, PIN, or device pattern – without entering a username, password, or additional authentication factors. Passkey/FIDO2 offers extremely strong protection against phishing and credential theft because: A passkey works only with the specific domain or website where it was registered. If users visit a phishing or fake website, the passkey simply will not work. Passkeys are device-bound credentials, meaning authentication requires the registered device and user verification (biometrics or PIN). In the digital banking era, security is no longer just a technical defense layer – it has become a core foundation for building digital trust between financial institutions and their customers. The combination of biometrics, Smart OTP, device-based authentication, and modern technologies such as Passkey/FIDO2 is paving the way for more secure authentication models, stronger fraud prevention, and seamless user experiences. If your bank or financial institution is looking for modern passwordless authentication solutions, from biometrics, Smart OTP, Smart Token, and Passkey/FIDO2 to AI-powered behavioral analytics and fraud detection. Connect with Savyint’s experts today to explore how we can support your digital security transformation. Read more:

SAVYINT Supports BAC A BANK in Upgrading Passwordless Authentication in Compliance with Circular 50/2024/TT-NHNN and Circular 77/2025/TT-NHNN (Vietnam)

SAVYINT successfully implemented passwordless authentications for BAC A BANK, including SmartOTP, Smart Token. The project enables the bank to fully comply with Circular 50/2024/TT-NHNN and Circular 77/2025/TT-NHNN issued by the State Bank of Vietnam while strengthening transaction security and reinforcing customer trust. Overview – Industry: Banking & Financial Services – Project: Deployment of passwordless authentication including SmartOTP, Smart Token for retail and corporate customers– Timeline: 2025  1. BAC A BANK and the Challenge of Complying with Circular 50/2024/TT-NHNN and Circular 77/2025/TT-NHNN  Established in 1994, BAC A BANK currently operates 138 transaction offices across major cities and provinces in Vietnam. In 2024, the bank ranked among the Top 5 banks with the largest foreign exchange transaction volume in Vietnam.  In 2024, the State Bank of Vietnam issued Circular 50/2024/TT-NHNN on security and safety requirements for providing online banking services, which officially came into effect on January 1, 2025. The regulation introduces several key requirements, particularly: In 2025, the State Bank of Vietnam continued to enhance the regulatory framework by issuing Circular 77/2025/TT-NHNN, which will take effect on March 1, 2026. This circular amends and supplements several provisions of Circular 50 to further strengthen security and risk management requirements for online banking services. As a result, BAC A BANK needed to upgrade its authentication infrastructure to comply with the new regulations while ensuring secure and reliable electronic transaction authentication for both retail and corporate banking customers. 2. SAVYINT’s Solution  As a global technology company specializing in Secure Payment, Digital Trust, and Open Banking, SAVYINT delivered a comprehensive electronic transaction authentication solution such as SmartOTP and Smart Token. The solution is designed in alignment with the regulatory requirements of Circular 50 and can be seamlessly integrated into the bank’s Internet Banking and Mobile Banking ecosystem, supporting both retail and corporate customers. 2.1. System Architecture  The advanced authentication system implemented by SAVYINT includes two main components:  2.2. User Groups    2.3. Models  The system supports two primary authentication flows:  2.4. Key Use Cases   a. SmartOTP and Smart Token Service Activation & Management  b. Transaction Authentication using SmartOTP, Smart Token The solution also supports Web-to-App authentication and App-based authentication, ensuring flexibility in service usage. c. Multi-Level Transaction Approval  d. PIN Management and Security Protection  e. Support Features and User Convenience  3. Results    Following the successful deployment of SAVYINT’s passwordless authentication solution, BAC A BANK fully met the requirements of Circular 50/2024/TT-NHNN and Circular 77/2025/TT-NHNN issued by the State Bank of Vietnam. The solution is consistently applied across both retail and corporate banking services.  By implementing advanced and passwordless authentication methods such as SmartOTP, Smart Token, BAC A BANK achieved several key benefits: This strategic upgrade enables BAC A BANK to strengthen digital trust and enhance its competitiveness in the evolving digital finance landscape.

ACCELERATE AFASA & BSP CIRCULAR NO. 1213 COMPLIANCE WITH SAVYINT 

ACCELERATE AFASA & BSP CIRCULAR NO. 1213 COMPLIANCE WITH SAVYINT 

AFASA and BSP Circular No. 1213 are fundamentally reshaping the security architecture of the Philippine financial sector. With the compliance deadline fast approaching, banks and financial institutions must act decisively to meet mandatory regulatory requirements. In June 2025, Bangko Sentral ng Pilipinas (BSP) issued Circular No. 1213, amending the IT Risk Management framework to formally implement Section 6 of the Anti-Financial Account Scamming Act (AFASA). This marks a structural transformation in how financial institutions across the Philippines approach cybersecurity and fraud prevention. Circular 1213 applies to all BSP-supervised entities, including banks, fintech companies, payment service providers, and lending institutions. The regulation focuses on:  Notably, before June 2026, , financial institutions are required to eliminate SMS OTP for high-risk transactions and transition to more secure, phishing-resistant, device-bound authentication methods. Understanding the regulatory and operational challenges faced by banks and financial institutions, Savyint delivers an integrated security and fraud prevention platform aligned with AFASA and BSP Circulars 1213 – 1215. The solution is built around four core pillars: Cyber Security & App Protection, SCA/MFA Identity, AI-Driven Fraud Management (FMS), and Risk Management & Compliance, protecting the entire customer journey – from onboarding and login to authentication, transaction execution, and post-transaction monitoring. Savyint’s Key Advantages:   Savyint’s integrated platform complies with both international and local security standards and regulations, including: Philippines (AFASA, BSP 1213–1215), Vietnam (Circulars 50, 64, 77/NHNN), Singapore (MAS), as well as FIDO2, PSD2/PSD3, eIDAS, GDPR, and PCI DSS. Connect with our experts today to accelerate your compliance with AFASA and BSP Circulars 1213–1215. 

From AFASA to BSP Circulars 1213 – 1215: SAVYINT Partners with Philippine Banks to Strengthen Security and Fight Digital Fraud 

From AFASA to BSP Circulars 1213–1215 Savyint Partners with Philippine Banks to Strengthen Security and Fight Digital Fraud

The rapid growth of digital banking, e-wallets, and online payments in the Philippines has led to a serious consequence – financial fraud is becoming increasingly sophisticated and more organized. Following the enactment of AFASA, the Bangko Sentral ng Pilipinas (BSP) continued to issue BSP Circulars 1213, 1214, and 1215, tightening the responsibilities of financial institutions and imposing stricter requirements for user authentication, fraud management, and data protection.  About AFASA and BSP Circulars 1213, 1214, and 1215  Officially taking effect on June 25, 2025, the Anti-Financial Account Scamming Act (Republic Act No. 12010) was enacted by the Philippine government with the following core objectives:  One of the most important requirements under AFASA is the mandatory transition of authentication methods before June 2026. OTPs sent via SMS and email will no longer be accepted for high-risk transactions. Instead, more secure methods must be implemented, such as biometric authentication, passwordless authentication, and adaptive multi-factor authentication (MFA) based on risk levels.  AFASA marks a major shift in risk management thinking: account security is no longer just a technology choice – it is now a legal obligation.  BSP Circular 1213 – Focus on Fraud Management and Strong Authentication  Among the three circulars, BSP Circular 1213 is considered the technical backbone that brings AFASA into real operational practice.  This circular requires banks and financial institutions to:  BSP Circular 1213 clearly states that traditional authentication methods are no longer sufficient. Systems must understand user behavior patterns and detect fraud at the earliest stages – during login or even before a transaction is completed.  Read more: Philippines BSP Circular No. 1213 and Compliance Solutions for Financial Institutions BSP Circular 1214 – Enabling Data Sharing for Faster Fraud Response  BSP Circular 1214 addresses a major legal bottleneck related to accessing account data during fraud investigations. Its main goal is to create a fast-response mechanism to prevent funds from being completely withdrawn before authorities can intervene.  Under this regulation:  BSP Circular 1215 – Protecting Funds During Disputes  While Circular 1213 focuses on prevention and 1214 focuses on investigation, BSP Circular 1215 addresses what happens after an incident occurs. It allows financial institutions to protect customer funds during the investigation period, preventing money from “disappearing” within minutes.  Specifically, this circular:  Together, AFASA and BSP Circulars 1213, 1214, and 1215 are reshaping the digital financial security standards in the Philippines. Financial institutions now need not only compliance documentation but also a strong technology foundation capable of detecting, preventing, and responding to fraud in real time.  AFASA & BSP 1213, 1214, 1215 – Compliant Security Solutions from SAVYINT Savyint is a leading trusted service provider, ready to deliver authentication and payment security solutions that strictly comply with security standards and regulatory requirements under AFASA, BSP Circulars 1213, 1214, and 1215 issued by the Bangko Sentral ng Pilipinas (BSP), as well as the Philippine Open Banking framework and international regulations.  Savyint’s solution ecosystem is built around four key pillars: Risk Management & Compliance, Cybersecurity & Application Protection, SCA/MFA Identity, and the FMS AI Fraud Engine. Together, these components protect the entire customer journey – from registration, login, authentication, and transaction execution to post-transaction monitoring.  SAM Auth Server  SAM Auth Server is an all-in-one strong authentication solution designed for mobile payments and digital banking.  Built on a Zero Trust architecture and integrated with a FIPS 140-3 Level 3 certified Hardware Security Module (HSM), and ready for Post-Quantum Cryptography, SAM Auth Server supports a wide range of modern authentication methods, including: Biometric authentication, Smart OTP, Push Authentication, FIDO2 / Passkeys and Context-based authentication  It enables step-up authentication when risk levels increase, ensuring maximum protection for electronic transactions.  SAM FIDO2 Identity Server  SAM FIDO2 Identity Server is a passwordless identity and authentication platform based on FIDO2/WebAuthn standards. It eliminates password storage by replacing passwords with asymmetric key-based authentication securely stored on the user’s device.As a result, the system effectively protects against common attacks such as phishing, man-in-the-middle attacks, and credential stuffing.  SAM FIDO2 Identity Server fully meets Strong Customer Authentication (SCA) requirements under PSD2/PSD3 and complies with international standards for identity and data security.  SAVYINT Fraud Prevention & Risk Management  SAVYINT Fraud Prevention & Risk Management leverages AI and Machine Learning (ML) to help banks and financial institutions detect, assess, and prevent fraud across the entire user journey – from login behavior, device characteristics, and access context to transaction data. Key capabilities include:  RASP+  RASP+ protects mobile applications directly within the runtime environment, detecting and blocking attacks while the application is running. It can detect rooted or jailbroken devices, debugging attempts, code tampering, hooking techniques, memory manipulation and emulator-based attacks.   RASP+ integrates directly into mobile applications without affecting performance, ensuring strong protection without compromising user experience.  TrustShield  TrustShield is a mobile fraud prevention platform powered by device fingerprinting, behavioral analytics, and AI. It can identify devices without relying on cookies or advertising IDs, detect emulators, rooted or jailbroken devices, identify multi-device fraud patterns, analyze in-app user behavior, generate real-time risk scores and trigger adaptive authentication directly on mobile devices.   With a multi-layered architecture and seamless integration capabilities, Savyint’s security ecosystem delivers a comprehensive fraud prevention model – protecting devices, behavior, identity, and transactions simultaneously.  All solutions comply with AFASA, BSP Circulars 1213, 1214, 1215, and international standards such as FIDO2, PSD2/PSD3, eIDAS, GDPR, and PCI DSS. This allows fast deployment on existing infrastructure while achieving the highest level of security.  Connect with Savyint’s experts today to implement and optimize your security solutions – and be fully prepared to meet AFASA and BSP requirements within just 3 months!