Skip to content

Approov

Mobile app attestation and API-security platform (formerly CriticalBlue) that verifies genuine, untampered app instances at runtime to block bots, emulators, and repackaged apps.

Visit Website ↗ + Add to Compare
52/100Incremental Innovator

Overview

Approov provides mobile app attestation and API-protection technology that verifies, at runtime, that API traffic is coming from a genuine, untampered instance of a mobile app rather than a bot, emulator, repackaged app, or script, a Zero Trust check applied to mobile-to-backend traffic rather than to network location or user credentials. The platform pairs runtime attestation with dynamic API secret delivery and built-in runtime application self-protection, aimed at stopping credential stuffing, API scraping, and automated abuse that bypass traditional WAF and bot-management tools sitting in front of web traffic.

Originally founded in Edinburgh, Scotland in 2001 as CriticalBlue, a mobile and embedded-software tools company, the business pivoted to focus on its Approov mobile API security product around 2017 and now operates as Approov Mobile Security, still headquartered in Edinburgh with U.S. operations in Palo Alto. In August 2025, the company closed a £5 million (approximately $6.7 million) Series A round led by the Investment Fund for Scotland, managed by Maven Capital Partners, with participation from Souter Investments, Lanza techVentures, and Scottish Enterprise.

The company’s positioning has recently expanded to explicitly cover agentic-AI threats, attackers using AI-driven automation to probe and abuse mobile APIs at scale, extending its original mobile-bot and repackaged-app problem into the newer AI-agent-abuse category, though as a small, recently-recapitalized company its independent validation and market share remain modest relative to larger mobile-security incumbents.

Innovation Matrix Assessment

Innovation Velocity 5/10

A 24-year-old engineering-tools company that pivoted to its current mobile-attestation focus around 2017 and has since extended into AI-agent-abuse protection, a reasonable but not especially fast pace of evolution.

Operational Value 6/10

Runtime attestation combined with dynamic API secret delivery and built-in RASP is a genuine, technically specific capability set purpose-built for mobile-to-backend traffic that generic WAF and bot-management tools handle poorly.

Market Momentum 5/10

A fresh £5 million Series A in 2025 backed by a Scottish government-linked investment fund and existing investors is a real but modest funding signal for a company operating since 2001, not evidence of rapid scale.

Category Disruption 5/10

Runtime mobile app attestation as an alternative to static code obfuscation is a genuinely different technical approach to mobile app protection, though the mobile-attestation category itself, including competitors, is fairly well established.

Real-World Efficacy 4/10

Two decades of engineering history and continued customer use lend some indirect credibility, but no independent, named third-party test of Approov's attestation or RASP effectiveness was found; efficacy evidence is largely vendor-documented.

Enduring Relevance 6/10

As mobile apps increasingly serve as the primary client for consumer and enterprise services, and AI-driven automation makes API abuse easier to scale, runtime mobile attestation addresses a real and growing gap left by traditional network-perimeter security tools.

Why CISOs Should Care

Closes a gap most CISOs' existing WAF and bot-management tools don't cover: verifying that mobile API calls actually originate from a genuine, untampered instance of the app rather than a bot, emulator, or repackaged clone.

What Makes It Different

Uses cloud-based runtime attestation and dynamic secret delivery instead of static code obfuscation, and has extended that same verification model to cover AI-agent-driven API abuse as that threat has emerged.

The Matrix Verdict

52/100 — INCREMENTAL INNOVATOR

A long-running, technically focused mobile-security specialist with a real and distinct capability in runtime app attestation, freshly recapitalized but still small-scale and lacking independent efficacy validation.

Editorial Note: Claims vs. Verified Findings

The company's 2001 founding as CriticalBlue, its pivot to Approov, and the 2025 £5 million Series A (Investment Fund for Scotland, Maven Capital Partners) are independently reported via EU-Startups and BusinessWire. Specific claims about attestation accuracy and effectiveness against 'agentic AI threats' are vendor-stated marketing language without independent benchmarking found.

Sources