The best mobile RASP solution is the one that covers your threats, proves its result to your backend, and fits how you run. Judge every vendor on the seven checks below, and test it on your own traffic before you sign.
We do not rank vendors here. Use these checks on every shortlist, including ours.
| Check | Ask the vendor | How NonaShield answers |
|---|---|---|
| 1. Runtime detections | Which attacks does it catch on the phone? | Root, Frida and Xposed hooking, emulators, debuggers, app repackaging, screen mirroring and accessibility abuse. |
| 2. Where the verdict is enforced | Is the decision made only in the app, which an attacker controls, or checked again on your servers? | Every request carries a cryptographic proof. The gateway and the backend each verify it independently and fail closed. |
| 3. Hardware-bound identity | Does a stolen token or a cloned app still work? | Keys are created in secure hardware (StrongBox, TEE, Secure Enclave) and cannot be copied to another phone. |
| 4. Behaviour and fraud scoring | Is it included, or a second contract? | Behaviour signals, a fraud graph, SIM-swap detection and a live risk score are part of the same stack. |
| 5. Evidence | What can you show an auditor or a disputing customer? | A signed, tamper-evident evidence bundle per event, which can be verified offline. |
| 6. Where it runs | Vendor cloud only, or your own cloud or data centre too? | SaaS, BYOC or on-premise. SaaS is live within 24 hours of the signed agreement. |
| 7. Price you can compare | Is it a fixed monthly price for a clear scope? | SaaS is a flat monthly price. See the cost page. |
Then add the one check that beats every brochure: run it on your own traffic. A 30-day shadow pilot records what would have been blocked or stepped up while your existing flow stays unchanged, so you compare vendors on results, not claims.
| Approach | What it does well | Where it stops |
|---|---|---|
| Code obfuscation | Makes the app harder to reverse engineer. | Does not detect an attack while the app is running. |
| Web application firewall | Filters malicious requests at the network edge. | Sees requests, not the phone that sent them. |
| Platform attestation alone | A signal from the operating system that the app and device look genuine. | One input, not a decision. It does not see hooks, overlays or who is using the phone. |
| RASP on its own | Detects and reacts to attacks inside the running app. | The verdict lives in code the attacker can target, and it knows nothing about your customer's history. |
| RASP with server-side verification | On-device detection plus a proof your backend checks on every request. | This is the model NonaShield follows. |
Runtime application self-protection (RASP) is security built into a mobile app that detects and reacts to attacks while the app runs, such as rooting, hooking, emulators, repackaging and screen sharing.
Shortlist on seven checks: runtime detections, server-side verification, hardware-bound identity, behaviour and fraud scoring, evidence, where it runs, and a price you can compare. Then run the finalists on your own traffic.
Usually not. RASP protects the app, but the decision that matters is made on your backend. Pair it with hardware-bound identity, behaviour and fraud scoring, and verify every request on the server.
Obfuscation makes reverse engineering harder and a WAF filters requests at the edge. Neither sees an attack happening inside the running app on a customer's phone, which is what RASP is for.
No. RASP is an SDK that your developers add to your own mobile app. NonaShield ships one SDK for Android, iOS and React Native, with one backend.
On NonaShield SaaS, within 24 hours of the signed agreement. Your team only integrates the SDK, and we support the integration in real time.
Run a free 30-day shadow pilot. Nothing in your flow changes, and you see what NonaShield would have caught.