Company Logo
Bring chip-and-PIN level protection to your digital channels – as a developer-friendly SDK or a ready-to-brand white-label app. KOBIL Legacy turns every smartphone into a high-assurance virtual smartcard, so you can secure logins and approve high-value transactions with rock-solid, PKI-based digital signatures.

Virtual Smartcard Security for Every Login & Transaction

hero-bg-phone
Tile Panel

What is KOBIL Legacy?

KOBIL Legacy is a high-security authentication and transaction-signing platform for organizations that cannot afford to get security wrong – banks, fintechs, insurers, public services, critical infrastructure, and any business dealing with sensitive data or money.

At its core, KOBIL Legacy provides:

PKI-based multi-factor authentication (MFA) for logins

PKI-based multi-factor authentication (MFA) for logins

Virtual smartcard technology bound to the user's device

Virtual smartcard technology bound to the user's device

Strong transaction approval using digital signatures

Strong transaction approval using digital signatures

A hardened, zero-trust secure channel between app and server

A hardened, zero-trust secure channel between app and server

You can use KOBIL Legacy in two ways:

SDK

Embed security directly
into your own mobile app.

SDK preview

White-label app

Launch a branded "Secure Authenticator" app for logins and transaction approvals across all your channels.

White-label app preview

The Core Idea: A Virtual Smartcard in Your User's Pocket

Instead of plastic smartcards, card readers or SMS PINs, KOBIL Legacy creates a virtual smartcard inside the user's device:

icon

The user is securely bound to a specific device (device binding).

icon

A unique key pair is generated and stored in a secure environment (e.g. Secure Enclave / Trusted Execution Environment).

icon

Each login or transaction is cryptographically signed by that key, representing the user’s digital signature.

smartcardimage

For the end-user, it feels effortless:

Face ID / fingerprint / device PIN + a single tap to approve.

Under the hood, you get bank-grade cryptography and non-repudiation.

phone-background
Product
Two Products,
One Security Engine
KOBIL Legacy SDK
Secure Your Own AppIntegrate our SDK into your existing mobile app to turn it into a high-security channel.
Strong app protection mobile

Strong app protection

  • Root / jailbreak detection
  • Emulator & debug detection
  • Runtime integrity checks & anti-tampering
  • Certificate pinning & mutual TLS
Secure app login mobile

Secure app login

  • MFA with biometrics + device binding + PKI signature
  • Passwordless login options
  • Step-up authentication for high-risk actions
Transaction signing mobile

Transaction signing

  • Approve payments, transfers, card transactions
  • Sign sensitive actions (new device, limits, beneficiaries)
  • Fine-grained policies (amount, currency, risk score…)

Developer-friendly

Native SDKs for iOS and Android

Native SDKs for iOS and Android

Clear APIs for enrollment, authentication, signing, device lifecycle

Clear APIs for enrollment, authentication, signing, device lifecycle

Easy integration with existing IAM / CIAM / core banking systems

Easy integration with existing IAM / CIAM / core banking systems

Built for modern standards: OAuth 2.0, OpenID Connect, SAML, and more.

Built for modern standards: OAuth 2.0, OpenID Connect, SAML, and more.

KOBIL Legacy White-Label App
Your Branded AuthenticatorNo app yet or want to keep security separate? Use our white-label app as a standalone "Secure Authenticator":
Approve web login mobile

Approve web logins

  • User enters username on web / legacy app
  • Push notification goes to the KOBIL Legacy App
  • User confirms with biometrics, you get a signed assertion
Confirm online & card payments Mobile

Confirm online & card payments

  • Approve credit card payments with a digital signature
  • Strong Customer Authentication (SCA) for EU-style regulatory requirements
Authorize access to other apps mobile

Authorize access to other apps

  • Use the app as a central security hub for multiple services
  • One authenticator for all your portals, apps and legacy systems
How It Works
Simple for Users,
Brutal for Attackers
Enrollment & Device Binding

Enrollment & Device Binding

  • User installs the app (your app with SDK or white-label app).
  • Identity is verified once (e.g. via core banking, eID, KYC system).
  • A device-bound key pair is generated and tied to that user.
  • The server knows: this user = this device = this key.
Secure Login

Secure Login

  • User logs in to your web, mobile or desktop channel.
  • Alongside credentials / biometrics, the app performs a silent digital signature in the background.
  • Your backend verifies the signature and device binding.
  • Result: multi-factor authentication without friction.
Transaction Signing

Transaction Signing

  • A payment or critical action is started (e.g. transfer, card payment, contract signing).
  • KOBIL Legacy sends a human-readable transaction summary to the app (amount, account, merchant, risk info).
  • User confirms with biometrics / PIN.
  • The app signs the exact transaction details with the device's private key.
  • Your backend verifies the signature and ensures transaction integrity (what you see is what you sign).
SECURITY ARCHITECTURE

Zero Trust by Design

KOBIL Legacy is built like a paranoid security engineer would design their dream stack:

Dashed line top
PKI-based digital signatures
Zero-trust secure channel
Device & app integrity
Dynamic risk & policy engine
Cloud or On-Premise
Security Architecture
Dashed line bottom
  • Strong asymmetric cryptography
  • Crypto-agile design for future algorithms
Tile Panel
Compliance & Regulatory Alignment
KOBIL Legacy is designed to sit right in the middle of the most demanding regulatory environments and help you tick the right boxes without killing your UX.

EU payments & open banking

  • Built for PSD2 requirements, including SCA, dynamic transaction linking, and secure communication.
  • Architected to be PSD3- and PSR-ready, so you can evolve with the upcoming EU payments framework instead of constantly patching your security stack.

Digital identity & electronic signatures

  • Aligned with eIDAS / eIDAS 2.0 principles for trustworthy digital identities and electronic signatures.
  • Supports architectures aiming at advanced electronic signature-grade assurance and non-repudiation through strong cryptographic proof and auditable logs.

Data protection & privacy

  • Privacy by design and data minimisation principles consistent with GDPR.
  • No need to expose or store unnecessary personal data on the device.
  • Flexible deployment options (including EU-only data residency and on-premise) to fit your data protection strategy.

Security standards & best practices

  • Built against industry best practices such as OWASP MAS/ASVS for mobile and application security.
  • Crypto design aligned with NIST recommendations and crypto-agile to adopt post-quantum schemes when needed.
  • Can be integrated into ISO 27001-certified environments and with FIPS 140-3 validated HSMs or key management systems.

Cards & payment ecosystems

  • Fits cleanly into PCI DSS-compliant architectures by keeping cardholder data out of KOBIL Legacy and focusing purely on authentication and transaction approval.
  • Helps you implement SCA-compliant and regulator-friendly flows for card payments, account access and high-risk operations.
Key Benefits for Your Organization

Massively reduced fraud

Strong cryptographic binding between user, device, and transaction raises the bar for attackers dramatically.

Regulatory-ready security

Designed to support compliance with strict financial-sector and data-protection requirements (e.g. strong customer authentication, secure approvals, auditability).

Better UX than SMS & TAN lists

No codes, no paper, no separate hardware. Just tap and approve.

Fast time-to-market

SDK: add strong security to your existing app in weeks, not years. White-label app: launch a fully branded authenticator without building from scratch.

Protects your brand

Users feel the difference between "yet another password" and a serious, modern, secure experience.
USE CASES
Typical Use Cases
Tile Panel
Tile Panel
usecase-card1
hover-img
Retail & private bankingSecure mobile & web banking, transfers, card payments
usecase-card1
hover-img
Fintech & walletsProtect digital wallets, P2P transfers, crypto transactions
usecase-card1
hover-img
Corporate banking & treasuryHigh-value approvals, multi-signatory flows
usecase-card1
hover-img
InsuranceSecure applications, personal data workflows
usecase-card1
hover-img
Public sector / e-GovernmentSecure citizen login and digital approvals
usecase-card1
hover-img
Enterprise SSO & critical appsStep-up MFA for admin consoles and sensitive systems
Tile Panel
Why KOBIL Legacy
Because you want
more than
"yet another MFA app".

You want:

  • Virtual smartcard security without the plastic.
  • PKI-grade digital signatures without user friction.
  • A zero-trust secure channel baked into every session.
  • A product built for high-stakes industries, not just generic logins.

KOBIL Legacy is where brutal high-tech security meets clean, modern user experience.

Company Logo
Virtual Smartcard Security for Every Login & Transaction
KOBIL Logo
ProductHow It WorksSecurityUse Cases
© 2025 KOBIL. All Rights Reserved.
KOBIL - legacy