After ALLOW
The user authenticates. ApiDefender wraps protected APIs. Inquiry routes can stay on ATS Lite.
App Security · AppDefender.dev
Access-token validation, SSL pinning, ATS Lite and Full.
Umbrella for the ATS platform. Login + token is never enough. Per-route Lite or Full, transaction binding on payments, SSL pinning and pinning-over-VPN. MITM and token-in-body are rejected.
What it does
ApiDefender is the session and API layer after the launch gate. A login and an access token prove a session, not a clean device and not an honest request. ATS Lite covers routine reads. ATS Full binds money movement.
SSL pinning, including pin-over-VPN, blocks MITM. Token-in-body is rejected. Transaction binding ties a payment, UPI collect, IMPS, or BBPS confirmation to the enrolled device and the launch score.
If AppDefender already decided BLOCK, ApiDefender does not reopen the path. Super Admin sets Lite or Full per route on that Client’s isolated catalog. Production route changes need Checker review.
What it scores
How it runs
The user authenticates. ApiDefender wraps protected APIs. Inquiry routes can stay on ATS Lite.
ATS Full binds the transaction to device, SIM, and launch score. UPI, IMPS, NEFT, and BBPS pay use this path.
MITM, broken pin, and token-in-body fail closed. ThreatDesk records the action for that Client only.
Operators
Enables the environment and the default Lite / Full map. Does not mix Client catalogs.
Proposes route policy in Sandbox. Two checkers approve Production. No self-approval.
Other App Security modules
All modules