Promon Shield for Web™ closes the front-end to back-end security gap without any code changes and deploys transparently alongside existing security controls to quickly enhance protections. Remove the attack surface, conceal business logic, and ensure only trusted access with a defense-in-depth approach that operates transparently and seamlessly within your security stack and application architecture.
Your app will run inside a Trusted Runtime Environment (TRE) in the browser, with its code concealed and its logic protected. Continuous attestation establishes that the client is the app you published, is untampered, and is not being inspected by bad actors. Only then will your web app provide access to sensitive data to clients that prove integrity. Every session. Every endpoint. Fully encrypted. Fully protected.
Validate client integrity and encrypt app code inside a Trusted Runtime Environment (TRE)
Conceal endpoints so attackers cannot target them directly
Ensure only genuine, untampered, trusted clients can access critical backend services while encrypting and obfuscating sensitive data end-to-end
Book a meeting
Discover what's possible with Promon Shield for Web™.
Why Promon Shield for Web™: leave nothing in attackers’ reach.
Secure the front-end
Shield for Web dynamically establishes a trusted environment within the browser and encrypts app code to mitigate client-side risks such as malicious scripts and keyloggers.
Validate client integrity and create a Trusted Runtime Environment (TRE) within the client browser
Encrypt everything delivered to the trusted browser, including app code, data, session state
Ensure transparent operation with existing security stacks
Protect the back-end
Shield for Web conceals endpoints and ensures all communication is protected in transit to prevent attackers from bypassing security controls by targeting endpoints directly.
Conceal API endpoints with no code changes to the application
Employ unique per-session protection to prevent hijack and re-use
Mitigate probing, reconnaissance, bots, and automated threats
Remove the attack surface
Shield for Web applies security checks continuously, within a trusted runtime environment, and ensures only trusted clients can access back-end services, ensuring nothing is in attackers’ reach.
Continuous runtime checks including anti-tamper and anti-debug
Secure session binding between the trusted client runtime and protected back-end services
Mutual attestation and attacker deception
Transparent deployment and seamless security
Shield for Web easily integrates into existing security stacks and embeds protections dynamically to quickly enhance protection.
Easily integrates into existing application architectures
App shielding was delivered to Raiffeisenbank in only a couple of weeks. Most of the time was spent on user testing; the shielding took only a few hours.
Compliant and secure
Promon protects Raiffeisenbank's mobile app users against malware and threats related to operating system weaknesses. It also helped the bank stay PSD2 compliant.
Customer story
Why Raiffeisenbank is protecting its new app with Shield for Mobile
Shield for Web ensures everything delivered to the browser is protected. App code, sensitive data, and session state is encrypted without any changes to the application. Teams can mitigate malicious scripts and keyloggers while improving security posture alignment to compliance mandates.
No code and no complexity
Shield for Web requires no changes to the application architecture and can be deployed transparently within existing security stacks to enhance protections using a defense-in-depth approach.
Trusted Runtime Environment (TRE)
Shield for Web dynamically creates an isolated Trusted Runtime Environment (TRE) within the browser, then continuously checks for runtime threats such as tampering and debugging to ensure client integrity.
Removes the attack surface
Shield for Web makes everything invisible and untouchable to attackers by establishing a unique, encrypted channel between a trusted client and protected back-end service for every session. The trusted runtime environment and session binding is continuously validated to ensure only trusted clients can access back-end services.
Web app protection for any security stack
Security and risk management leaders
The risk surface has reached an untenable state and consequences for security incidents and non-compliance have material impact. With Shield for Web, leaders can now implement security consistently across web apps, mobile apps, and interconnected APIs.
Reduce risk by protecting your digital revenue streams and customer data
Improve operational efficiencies by quickly deploying into any security stack without friction or tedious fine tuning
Tighten alignment to increasingly stringent compliance mandates and evolving web security best practices
Security and DevSecOps teams
Offset sensitive data exposure and reduce fraud and abuse without adding unnecessary complexity to your development process or release cadence. Shield for Web deploys transparently to extend runtime protection to clients and deter API abuse from bots and automated attacks, ensuring only trusted access to critical services.
Deploy within any security stack and application architecture without code changes or client-side agents.
Gain continuous runtime protection within a Trusted Runtime Environment (TRE).
Ensure only trusted clients can access back-end services, especially critical business logic involving payments, sensitive data, and entitlements.
Compliance owners
Security mandates are becoming more stringent. Shield for Web enhances protections by mitigating malicious scripts and client-side attacks within the browser without any code changes, client-side agents, or plugins.
Deploy into any security stack to quickly enhance protections
Strengthen payment security within web apps and interconnected APIs
Ensure consistent protection across mobile, desktop, and web surfaces
Extend proven Promon protections to web apps
With Promon, your apps run inside a Trusted Runtime Environment (TRE), with code and logic protected. Our solutions ensure your apps only provide access to sensitive data to clients that prove integrity. Every session. Fully protected.
Explore how Promon Shield for Web™ protects apps across finance, gaming, streaming, healthcare, and more, delivering web app security for every industry.
Finance
Detect malicious scripts, prevent fraud and abuse, and strength alignment to compliance mandates.
Discover how Promon Shield for Web™ can protect your web apps that run in a browser you don’t control by extending the same protections in your mobile app to the client browser.
Promon Shield for Web™ extends proven protections to web-based apps to ensure only genuine, untampered clients can access sensitive services by validating client integrity, creating a Trusted Runtime Environment (TRE) in the browser, and establishing secure session binding and mutual attestation with server-side components. Everything delivered to the browser is protected, and APIs are concealed to prevent unauthorized access.
Does Shield for Web require code changes?
Shield for Web is deployed transparently and seamlessly through a reverse proxy. Teams can quickly enhance protections without code changes, browser agents, or plugins.
Is Shield for Web a replacement for Promon Verify?
No. Shield for Web compliments Shield for Mobile and Verify and enables security to be consistently applied across web apps, mobile apps, and APIs.
What can teams do with Shield for Web today?
Teams can use Shield for Web to extend proven protections to web-based apps and APIs, ensuring only trusted clients can access back-end services, especially for critical business logic involving payments, sensitive data, and entitlements.
Who is Shield for Web for?
Shield for Web is designed for security and risk management, development and DevSecOps, compliance, product teams and CISOs that need end-to-end web app protection at the speed of modern app delivery.
Can I deploy Shield for Web on-premises?
Yes, Shield for Web can be deployed on-premises to meet strict regulatory needs and keep sensitive data within your own environment.
What is a Trusted Runtime Environment (TRE)?
Your web apps run in a browser you don’t control.
With Shield for Web, your app runs inside a Trusted Runtime Environment (TRE) in the browser, with its code concealed and its logic protected while it runs. Continuous attestation establishes that the client is the app you published, is untampered, and is not being inspected by bad actors. Only then will your web apps provide access to sensitive data to clients that prove integrity.
What is the current availability of Shield for Web?
Promon Shield for Web™ is currently in Generally Availability.