
Scoffable Customer
Story
Minimizing
Revenue Loss and Protecting
Sensitive Data
.webp)

Scoffable, founded in 2010, provides a fast and convenient online ordering experience for takeaway consumers.
With the increase in online transactions and the use of mobile apps, protecting sensitive data has not only become a part of doing business, but a requirement to earn the trust of customers.
It was our API that we were looking to harden against abuse and potential bad actors attempting to threaten the security and availability of our service.
'- Daniel Jones, Founding Partner, Scoffable'
.webp?width=700&height=248&name=scoffable-challenge-1%20(2).webp)
The Challenge
How Approov Mobile App Protection Helped
The team at Scoffable had already employed some common techniques to prevent abuse, such as rate limiting, Google reCAPTCHA and the use of Cloudflare’s Web Application Firewall product to help protect their services from various threats, including DDoS attacks.
This wasn't enough for mobile, so they reached out to the Approov team for a solution purpose built for mobile. Approov's use of signed JWTs (JSON Web Tokens) could be validated quickly and, in conjunction with Cloudflare, solved the DDoS mitigation problem with their APIs.
Scoffable has also made use of Approov’s integration with the Apple DeviceCheck API to ban specific devices from using the Scoffable service. More details on this Approov feature can be found here.
Finally, we asked Daniel why they chose Approov:
We couldn’t find anything else quite like Approov, for us it solved a number of problems:
- Preventing non-Scoffable applications from making requests to our public APIs
- Providing a DDoS mitigation solution (in conjunction with Cloudflare)
- Reducing legitimate user friction on iOS where Google reCAPTCHA is not native
- Providing a simplified approach to the management of Certificate Pinning
Read on


Retail Cyberattacks Highlight Need for Mobile App and API Security
The recent cyberattack on UK retailer, Marks & Spencer (M&S), along with similar threats to Harrods...

Enhancing Mobile Payment Security: A Comprehensive Approach with Approov
Mobile payment systems are increasingly popular, offering convenience and speed for consumers and...

Shielding APIs that Service Mobile Apps: Part 1 - Why?
In this series of articles, we are going to explore the why, what, how and when of shielding APIs...

What Can You Test with an Approov 30-Day Free Trial?
Everything. If you are reading this, then it's probably because you are actively considering a free...

Why the OWASP Mobile Application Security Project is Critical
The OWASP MAS project continues to lead the way in mobile application security. This article...

Why Loyalty Apps Need to Be Protected - and How to Do it
My favorite local sushi restaurant has just introduced a loyalty program so I can get discounts...

Empowering Mobile Payments: Approov's Security and PCI MPoC Mastery
In the ever-evolving landscape of mobile applications, especially those dealing with sensitive...

How To Protect Against Account Takeover In 2021
Editor's note: This post was originally published in September 2021 in Threatpost.
Data breaches...
Request a Demo
Give us 30 minutes and our security experts will show you how to protect your revenue and business data by deploying Approov to secure your mobile apps and your.
Get a Trial
Approov offers a complimentary 30 day trial (no credit card necessary) to give you immediate and valuable insight into the security risks of your mobile apps and the devices they run on.