Your starting point

Start where you are. Grow when you’re ready.

All three modules share the same core: app hardening, device binding and transaction signing on a PSD2-certified security server (KOBIL AST Services). They differ in what wraps around it. Security puts that core into your own app. Basic delivers it as a finished app with a managed backend. Ecosystem extends Basic into a platform for many services. Pick the one that matches your situation today.

Standalone

Security module

You keep your own app and your own identity landscape. The security, identity and authorization layer goes underneath, delivered as an SDK.

Basic module

A ready-made hardened app plus managed cloud backend for push approvals, document signatures and secure chat.

Extends the Basic module

Ecosystem module

One SuperApp for your own and third-party services, with identity, chat and signature provided centrally and a Portal to run it.

App hardening and secure identity the core shared by all three modules

Basic grows into Ecosystem without a migration project. Moving between Security and the other two modules is possible, but it is a migration project.

Module comparison

Every module, side by side.

The same criteria across all three modules, so you can shortlist before you talk to anyone. Each module name links to its detail page further down.

Criteria Security Basic Ecosystem
Built for Organizations with their own branded app or an existing identity landscape (LDAP, Active Directory, IAM) that want app hardening, PSD2-certified two-factor authentication and an identity provider underneath, optionally in their own data center. Organizations that need strong customer authentication, transaction approvals, document signatures and secure chat in production, without developing and operating a hardened app themselves. Organizations that bundle their own and partner services as MiniApps in one SuperApp and provide identity, chat and signature centrally.
The app your customers use Your own app with the App Security SDK (KOBIL MC SDK) inside. A white-label app is available as an alternative. The KOBIL Finance App for iOS and Android, branded and configured in the Portal, published in the App Store and Play Store. The KOBIL SuperApp, branded in the Portal and published in the app stores. Your services and partner services are reached through it, as MiniApps inside the app or as external apps started from it.
Where it runs KOBIL Cloud, or your own Kubernetes environment installed via Helm. KOBIL Cloud SaaS in Frankfurt am Main on AWS. KOBIL Cloud SaaS in Frankfurt am Main on AWS, operated by a partner certified to C5, ISO 27001 and ISO 27017/18.
Sign-in and identity KOBIL IDP with single sign-on, identity and access management, OIDC code flow, user registration and 2FA device management. Onboarding and login flows carry your branding. Two-factor authentication with device binding plus password or biometrics. User and device management in the Portal and via REST APIs. KOBIL IDP as the shared identity service: one login for all microservices, MiniApps and external apps, consent management per MiniApp, self-service for account, app and password.
Approvals and signatures Push approval with what-you-see-is-what-you-sign (Transaction Management Service, TMS), payment and non-payment transaction signatures, customer confirmations with evidence. All signatures are advanced electronic signatures under eIDAS. Everything from Security, plus approvals directly inside the chat and PDF document signatures with a personal digital signature and a visible signature applied on the device. Everything from Basic, plus approvals triggered directly from MiniApps.
Secure communication Not part of this module Encrypted secure chat with attachments, document and file delivery, broadcasts to all users or to groups. Everything from Basic, plus chat and chatbot services provided by your teams and partners.
Third-party services Not supported Not supported MiniApps, SuperApp2App, web2app and chatbot services, connected via OpenID Connect or the Shift REST API.
Changes while live Integration changes are made by your app developers and shipped through your own release and publishing process. App changes are made in the Portal and delivered through the app store release process. Home screen, MiniApps, modules and chat services are changed in the Portal, without an app store release.
Trial system Not available at present Cloud-based trial system including the mobile app, access provided by KOBIL. Not available at present
Path to the other modules Moving to Basic or Ecosystem is a migration project. Grows into Ecosystem without a migration project. Extends Basic. Coming from Security is a migration project.
The Security module

Your app, our security layer underneath.

Your customers already know your app, and your identity landscape took years to build. Both stay: the Security module hardens the app you have, adds PSD2-certified two-factor authentication and puts an identity provider behind it.

Module profile Security Standalone
Built for
  • You already have an app your customers use
  • You run your own directory or IAM
  • Cloud is ruled out, or you prefer your own data center
The app

Your own app with the App Security SDK (KOBIL MC SDK) inside. No second app for your customers.

What it covers
  • App hardeningRuntime protection, device binding and integrity checks inside your app.
  • Fraud detectionRemote control tools, screen recording, keyloggers, rooted devices and manipulation by phone (Call Guard).
  • Two-factor authenticationPSD2-certified, device-bound, no hardware tokens.
  • Push approvalsWhat the customer sees is what gets signed, only on a checked device.
  • Identity serviceKOBIL IDP: one login for app, browser and webview, under your branding.
  • Portal and APIsApp versions, users and devices, with audit trail.
Delivery

KOBIL Cloud, or your own Kubernetes environment (requirements). Your developers integrate the SDK, your backend the REST APIs.

Path

Standalone. Moving to Basic or Ecosystem is a migration project.

The Basic module

A finished app, run for you.

A regulator asks for strong customer authentication, and the clock is running. Basic is the route with the least to build: a hardened app under your brand, a managed backend and REST APIs into the systems you already run.

Module profile Basic Standalone
Built for
  • You have no mobile security team of your own
  • Your IT can connect REST APIs
  • Cloud on AWS in Frankfurt is permitted
The app

The KOBIL Finance App for iOS and Android under your brand, in the app stores.

What it covers
  • App hardeningThe same hardened core as Security, kept current by KOBIL.
  • Two-factor authenticationPSD2-certified, device-bound, no hardware tokens.
  • Push approvalsTransactions and confirmations signed on the phone, also inside the chat.
  • PDF signaturesDocuments signed in the app, as advanced electronic signatures under eIDAS.
  • Secure chatChat encrypted in transit, attachments and broadcasts to user groups.
  • Portal and APIsSupport manages users and blocks lost devices, also via REST API.
Delivery

KOBIL Cloud SaaS in Frankfurt am Main on AWS, operated for you. You integrate the REST APIs you need.

Try it

Cloud trial system including the app. See the demo

Path

Standalone. Grows into Ecosystem without a migration project.

The Ecosystem module

One app. Your services and your partners’ services.

Several brands, business lines or partners need to reach your customers through one login, and marketing is tired of waiting for the next app store release. Ecosystem extends Basic into a platform your teams and partners build on.

Module profile Ecosystem Extends Basic
Built for
  • Several business lines, brands or a partner network
  • Partners who bring their own services into your app
  • A business team that will run the Portal
The app

The KOBIL SuperApp under your brand, with your services and partner services inside.

What it adds to Basic
  • Partner services inside your appMiniApps, external apps (SuperApp2App), web and chatbot services.
  • One login for everythingKOBIL IDP as the shared identity service, with consent per MiniApp.
  • Staged onboardingAnonymous use first, login only where it is needed.
  • Approvals and chat for every serviceSignatures, push approvals and chat shared across the ecosystem.
  • Portal with Smart BuilderHome screen, services and campaigns change without an app store release.
  • Analytics and monitoringUsage analytics, client and server monitoring as part of the platform.
Delivery

KOBIL Cloud SaaS in Frankfurt am Main on AWS, operated by a partner certified to C5 and ISO 27001. Your teams or partners build the MiniApps.

Path

Extends Basic, no migration project from there. Coming from Security is a migration project.

The Portal with Smart Builder at a glance

Your teams change home screen, services and campaigns. No release cycle in between.

  • No-code home screenArrange the home screen from modules like Banner, Spotlight, News and Pack, with a preview.
  • Broadcast CenterSegmented messages and push campaigns to the user groups they are meant for.
  • Tenants, versions and reportsTenant setup, approved app versions, branding, users and usage reports in one place.
Delivery

From decision to go-live.

What actually happens after you pick a module: where the platform runs, what your team integrates, where you get help and who is responsible for what. Enough for a project plan. The complete package description is in the whitepaper.

Choose the operating model

Basic and Ecosystem run as KOBIL Cloud SaaS in Frankfurt am Main on AWS. Security runs in KOBIL Cloud or in your own Kubernetes environment, installed via Helm; self-hosting needs a DevOps team on your side. Some regulatory frameworks do not permit SaaS operation; where that applies, the SaaS deployment model is not available.

Integrate via REST APIs

All integration runs through documented REST APIs for authentication, transaction signatures, document signatures, secure messages, document delivery and user management. Typical use cases:

  • Create, block and delete users; manage devices
  • Onboarding with an activation code that you send out-of-band, by SMS, email or letter
  • Login confirmation and transaction authorization via push approval with WYSIWYS
  • Basic and Ecosystem: chat messages with attachments, PDF signature requests
  • Ecosystem: MiniApps via OpenID Connect or REST API

Integration and API documentation at developer.kobil.com and documentation.cloud.kobil.com.

Get help where you want it

Optional professional services with a dedicated project manager or lead consultant:

  • Solution architecture and use case consulting
  • Backend integration consulting
  • Support with the app store upload, a frequent source of delay
  • Regular project status meetings
  • App development consulting if you build your own app
  • Deployment support for self-hosted backends
  • Branding and customizing of the IDP and the white-label app

An integration workshop at project start is where the effort gets estimated.

Run it with support behind you

Ticket-based help center, error analysis and handling, and maintenance and security updates within the SaaS platform. Supported mobile platforms: the last two major iOS releases and the last five major Android releases.

Changes beyond the agreed scope go through a change process that assesses effort, time, cost and the impact on architecture and operation.

What you take care of
  • Define the use cases, describe the business processes, functional acceptance
  • Integrate the REST APIs, run system and acceptance tests and user acceptance tests
  • Name contacts and coordinate your internal teams with the KOBIL professional services team
  • Assess regulatory requirements and data protection, approve the processes in use
  • Full-solution penetration tests, if wanted or required
  • Security module, self-hosted: provide and operate the Kubernetes environment
  • Ecosystem: develop and operate MiniApps, SuperApp2App applications and chat services, run the Portal, govern partners, and hold the contracts with external analytics, monitoring, KYC and chatbot providers
What KOBIL takes care of
  • The hardened app or the App Security SDK, the backend platform and the Portal of your module
  • Operation of the SaaS platform, including maintenance and security updates
  • Integration, API and user management documentation, plus getting-started apps
  • Ticket-based support with error analysis
  • Optional professional services, from architecture consulting to app store upload
  • PSD2 compliance reports on request
Self-hosting requirements (Security module)

For all modules: internet access, HTTPS/TLS-capable communication, REST API integration and supported mobile operating system versions. For a self-hosted Security module, your Kubernetes environment needs the following, as of August 2026:

Kubernetes 1.23 to 1.33 Helm 3.x PostgreSQL 13.x and 16.x Redis 7.x and 8.x, standalone or cluster Istio 1.19.0 to 1.27.3 Strimzi Kafka Operator 0.47.0 with Kafka 4.0.0 Elasticsearch 8.17.2

PostgreSQL: scram-sha-256 password hashing is not supported. The currently supported versions are listed in the readme of each component.

In detail

The fine print, in one place.

Topics that apply across all three modules, collected here with stable anchors so the rest of the site can point to them.

Supported regulatory frameworks

KOBIL Finance supports the technical implementation of strong customer authentication and strong authorization under these frameworks:

PSD2 SCA BDDK FINMA FCA MAS HKMA FFIEC HIPAA Gematik

SRC has confirmed the conformity of the KOBIL technology mAST with the requirements of the EBA RTS on Article 98 PSD2. Compliance reports are available on request. The cloud operation of the Ecosystem module is provided by a partner certified to C5, ISO 27001 and ISO 27017/18.

The functional and regulatory assessment for your specific use case remains with your organization. KOBIL provides the technical building blocks; the evidence available today is the PSD2 certification of the KOBIL mAST technology by SRC and, for the Ecosystem module, the certifications of the cloud partner. Some of the listed frameworks do not permit SaaS solutions outside their regulatory perimeter; where that applies, the SaaS deployment model is not available.

What no module includes

An honest scope beats a surprise in the project. These parts sit deliberately outside every module:

  • Development of complete business applications
  • Custom middleware development
  • Operation of customer-owned infrastructure
  • The functional and regulatory assessment of your specific scenario, which stays with your organization
  • Qualified electronic signatures (QES) under eIDAS; all signatures are advanced electronic signatures

Need every detail? The whitepaper carries the complete package description. Or see the Basic module working first.