TrustPin™
Technology partnership

Certificate Pinning Meets
Runtime Protection

TrustPin has partnered with Promon, the app-security company trusted by banks and governments worldwide, to bring defense-in-depth to mobile apps: TrustPin secures the connection, Promon secures the runtime.

Why This Partnership

Certificate pinning and Runtime Application Self-Protection (RASP) solve two different problems, and neither is complete without the other. Pinning stops attackers from intercepting the connection between your app and your servers. RASP stops attackers from compromising the app itself: hooking its functions, repackaging it, or running it in a hostile environment.

That's why TrustPin partners with Promon. Their app-shielding technology protects the runtime our SDK executes in, and our dynamic pinning protects the channel their shielded apps communicate over. The result is one coherent security stack instead of two disconnected tools.

In partnership withPromon logo

Two Layers, One Defense

Each product protects what the other cannot reach.

TrustPin secures the connection

Dynamic certificate pinning

  • Blocks man-in-the-middle attacks at the TLS handshake
  • Validates certificates against a signed, remotely managed pin set
  • Zero-downtime pin rotation, no app-store release required
  • OWASP MASVS-aligned pinning for iOS, Android, Flutter, and React Native

Promon protects the app itself

Runtime Application Self-Protection (RASP) & app shielding

  • Detects and blocks hooking frameworks and code injection at runtime
  • Protects against repackaging, tampering, and debugger attachment
  • Shields apps running on rooted or jailbroken devices
  • Obfuscation and integrity checks that raise the cost of reverse engineering

Defense-in-Depth in Practice

The OWASP Mobile Application Security Verification Standard treats channel security and runtime resilience as separate requirements, because attackers treat them separately too.

Attacks on the channel

Malicious proxies, rogue WiFi, and compromised certificate authorities try to intercept traffic between your app and your servers. Certificate pinning shuts this down: the app only talks to servers presenting the exact keys you pinned.

Attacks on the app

Hooking frameworks, repackaged builds, and instrumented devices attack the app from inside the process, where even a perfectly pinned connection can be bypassed. RASP detects and reacts to these attacks while the app runs.

Covered together

Pinning without runtime protection can be unhooked; runtime protection without pinning leaves the network exposed. Combining TrustPin and Promon closes both gaps. Each layer protects the other.

About Promon

Promon is a Norwegian application-security company and a pioneer of in-app protection. Its app-shielding technology defends mobile apps for banks, payment providers, and government services around the world, protecting them against tampering, hooking, repackaging, and malware at runtime.“You develop. We protect.”

Learn more at promon.io

Build defense-in-depth into your mobile apps

Talk to us about combining TrustPin certificate pinning with Promon's runtime protection in your security architecture.