Digital AI introduces Quick Protect Agent, a no-code way to protect mobile apps

news
Jun 10, 20254 mins
Application SecurityMobile DevelopmentMobile Security

The agent helps developers secure their apps with enterprise-grade, OWASP MASVS-aligned defenses like obfuscation, anti-tamper, and anti-analysis.

Mobile app developer showing test version of product to team lead
Credit: Dragon Images / Shutterstock

Threat actors are increasingly targeting mobile apps, adding to the security risks for enterprises and their customers.

To help address this burgeoning issue, enterprise software delivery platform vendor Digital.ai Tuesday is expanding its Application Security suite with the addition of Quick Protect Agent to give developers a quick, no-code way to protect their enterprise apps from tampering.

While flagship apps such as client-facing mobile banking receive a lot of attention from security teams, secondary and tertiary apps such as trading apps, or apps for employees only that arenโ€™t in public app stores, may not, noted Digital.ai CEO Derek Holt. Security teams just donโ€™t have the resources to apply the same rigor to them. The Quick Protect Agent is designed to fill that gap.

In the 2025 version of Digital.aiโ€™s Annual Application Security Threat Report, Holt said, โ€œWe saw that over 80% of the apps in the respective app stores are under attack, and we saw about a 20% increase year over year in the number of attacks.โ€ When investigators dug deeper, they found that the industry has done a โ€œpretty good jobโ€ of putting more guards and protections in place in some industry verticals and with primary apps.

โ€œHowever, the threat actors are now going after secondary and tertiary apps and are starting to expand into industry verticals that maybe were previously not as much of a focus area,โ€ he said.

That discovery led to the development of the Quick Protect Agent, with a simple interface that allows developers to drag and drop their binaries into a GUI and select the level of security required and any or all of the offered protections, including all four OWASP MASVS (Mobile Application Security Verification Standard) Resilience categories. Once the protections are approved, the tool provides a command line interface version of the configuration to include in automated pipelines for future builds.

While the full Application Security Suite gives security teams the ability to fine-tune security for flagship apps, balancing security protections and performance, Holt said, they frequently donโ€™t have the resources to give all apps the same attention. Quick Protect Agent asks a series of questions about general areas of concern and the required balance between performance and security, and the agent then generates the security profile for the app.

In both cases, he said, detailed logs record every decision.

โ€œThis is an interesting new set of capabilities and largely aligns with what we are seeing in the devops space,โ€ said Jason Andersen, principal analyst at Moor Insights & Strategy. โ€œOverall, Digital.aiโ€™s assertion that we are witnessing a significant increase in hacking activity is accurate. Companies like JFrog, who cover different aspects of the toolchain, are also seeing similar increases and itโ€™s largely being chalked up to increased use of automation and AI technology by hackers. So, the need is certainly there, especially in mobile applications which tend to be much more frequently updated than typical enterprise web apps. Thatโ€™s a crucial distinction for a set of applications that are frankly higher visibility due to customer and partner contact.โ€

Andersen noted that the use of agents in the development workflow accomplishes two things. First, it helps developers not well acquainted with application security to protect their apps. โ€œIโ€™d expect this to lead to better coverage and more frequent application of security processes,โ€ he said.

In addition, he pointed out, the solution makes a lot of sense as the use and complexity of agents increases.

โ€œNew agent capabilities and standards, such as those seen in tools like GitHub Copilot, are pointing to a new future in the devops toolchain,โ€ he said. โ€œConsider agents like these engaging in some degree of cross-agent teaming, resulting in a more real-time and autonomous application security process.โ€

However, said David Shipley, CEO of Beauceron Security, โ€œObscure code helps, but it doesnโ€™t close vulnerabilities: it makes them harder to find by, for example, old-fashioned trial and error.โ€ This kind of intervention, he said, โ€œis like having the forward collision alert come on to stop an accidentโ€ โ€” itโ€™s a good thing, but it would be better if we understood the reason so that we fixed the underlying cause, not just the symptom.

Lynn Greiner

Lynn Greiner has been interpreting tech for businesses for over 20 years and has worked in the industry as well as writing about it, giving her a unique perspective into the issues companies face. She has both IT credentials and a business degree.

Lynn was most recently Editor in Chief of IT World Canada. Earlier in her career, Lynn held IT leadership roles at Ipsos and The NPD Group Canada. Her work has appeared in The Globe and Mail, Financial Post, InformIT, and Channel Daily News, among other publications.

She won a 2014 Excellence in Science & Technology Reporting Award sponsored by National Public Relations for her work raising the public profile of science and technology and contributing to the building of a science and technology culture in Canada.

More from this author