Security Architecture

Fraud-Resistant by
Design, Not Detection.

Mobile payments face unique fraud vectors — SIM swap, device takeover, number porting, synthetic identities. Jalda combines operator-native verification, device-bound authentication, and bounded-loss architecture to make fraud structurally unprofitable.

View Security Layers

Defense in Depth

Security failures cascade. Jalda implements multiple independent verification layers so that no single compromise can drain value.

Operator-Native Identity

Mobile operators maintain authoritative identity and billing relationships. Jalda leverages CAMARA Number Verification and SIM Swap Detection to verify that the person initiating payment controls the registered phone number and SIM card.

Device-Bound Authentication

For large-value transactions, Jalda requires WebAuthn/FIDO2 biometric authentication tied to a registered device. Credentials never leave the device, and possession + biometric factors prevent remote account takeover.

Bounded Loss Architecture

Transaction limits scale with trust signals. New accounts start with low per-transaction and monthly caps. Trust increases with verified history, device consistency, and operator risk scores, limiting exposure from any single compromise.

Multi-Layer Fraud Prevention

Each layer addresses a specific attack vector. Together they create structural barriers that make fraud economically infeasible.

1

CAMARA Number Verification

Before accepting payment, Jalda verifies that the user's device is connected to the mobile network with the claimed phone number. This uses GSMA's CAMARA API standard, where the operator cryptographically confirms number ownership without exposing PII.

Prevents

  • Spoofed caller IDs and fake SMS
  • VoIP number impersonation
  • Recycled or ported number fraud
  • Synthetic identity schemes

How It Works

1
User initiates payment on mobile device
2
Jalda calls operator CAMARA endpoint
3
Operator verifies device network identity
4
Transaction proceeds only if verified
2

SIM Swap Detection

SIM swap fraud is the primary vector for mobile account takeover. Attackers social-engineer operators to port a victim's number to a new SIM, then intercept SMS 2FA codes. Jalda queries CAMARA SIM Swap APIs to detect recent SIM changes and blocks high-risk transactions during the vulnerability window.

Detection Windows

Low-value payment 7-day check
Medium-value payment 14-day check
High-value payment 30-day check
Account changes 90-day check

Response Actions

  • Block transaction if swap detected in window
  • Require additional authentication (WebAuthn)
  • Lower transaction limits for new SIMs
  • Flag account for manual review
3

Device Swap & Fingerprinting

Legitimate users rarely change devices frequently. Jalda tracks device fingerprints (browser, OS, hardware tokens) and flags accounts that exhibit rapid device rotation, location jumps, or inconsistent behavioral patterns characteristic of account takeover or device farms.

Tracked Signals

  • Browser user-agent and capabilities
  • Screen resolution and pixel density
  • Time zone consistency and drift
  • Connection type (WiFi, 4G, 5G)
  • Geographic location patterns
  • Session behavior and interaction timing

Risk Scoring

Low Risk 0-20 points

Consistent device, known location, normal behavior

Medium Risk 21-60 points

New device, VPN usage, infrequent user

High Risk 61-100 points

Device farm patterns, location jumps, automation signals

4

WebAuthn Biometric Authentication

For transactions above defined thresholds, Jalda requires FIDO2/WebAuthn biometric authentication (FaceID, TouchID, Windows Hello). Private keys never leave the secure enclave, and the protocol cryptographically binds authentication to specific devices and origins, preventing phishing and remote attacks.

Authentication Thresholds

New account (0-30 days) > 5 EUR
Established account (30-90 days) > 20 EUR
Trusted account (90+ days) > 50 EUR
Risk flag triggered All amounts

Security Properties

  • Private key never leaves hardware enclave
  • Biometric data stored locally, not transmitted
  • Origin-bound credentials prevent phishing
  • No shared secrets vulnerable to breach
  • Attestation verifies genuine hardware authenticator
  • Replay attacks cryptographically prevented
5

Bounded-Loss Transaction Limits

Even with all verification layers, compromise is possible. Jalda implements strict per-transaction and cumulative limits that scale with account trust. If an account is compromised, exposure is capped to amounts that make fraud structurally unprofitable given attack costs.

Tier 1: New Account
Per-transaction 5 EUR
Daily limit 20 EUR
Monthly limit 50 EUR
0-30 days, no WebAuthn
Tier 2: Established
Per-transaction 20 EUR
Daily limit 100 EUR
Monthly limit 300 EUR
30-90 days, verified device
Tier 3: Trusted
Per-transaction 50 EUR
Daily limit 300 EUR
Monthly limit 1,000 EUR
90+ days, WebAuthn enrolled

Economics matter. If a SIM swap attack costs 200 EUR in labor and social engineering, and the maximum extractable value per account is 50 EUR, the attack is economically irrational at scale.

Why Mobile Operators Partner With Jalda

MNO fraud teams evaluate partners on risk posture. Jalda's architecture aligns operator incentives with security outcomes.

Shared Fraud Liability

Operators absorb chargeback risk on DCB transactions. Jalda reduces operator exposure through defense-in-depth, limiting fraud losses that would otherwise hit operator P&L. Lower fraud = higher revenue share and sustainable partnerships.

CAMARA-Native Integration

Jalda uses GSMA CAMARA APIs (Number Verification, SIM Swap Detection, Device Swap), making integration with operator infrastructure standardized and auditable. No proprietary backdoors, no regulatory ambiguity.

Real-Time Fraud Reporting

Operators receive structured fraud event logs: blocked transactions, SIM swap detections, device anomalies, chargeback claims. This data improves operator fraud models and informs network-wide security policies.

PSD2 & GDPR Compliant

Strong Customer Authentication (SCA) via WebAuthn meets PSD2 requirements. CAMARA's privacy-preserving verification architecture aligns with GDPR data minimization principles. No raw PII exposed during authentication.

Security Is a Feature, Not a Cost Center.

For fraud teams at mobile operators or risk officers at content providers, Jalda's architecture is designed to make your second meeting easier. Let's talk specifics.

Discuss Security Architecture