Skip to content

Vitality isn’t a traditional insurer. As a pioneer of the shared value insurance model, it rewards customers for healthy lifestyle choices, from steps and workouts to heart rate activity, with a mission to help people live healthier lives. This model relies on seamless integration between the Vitality mobile app, wearable devices such as Apple Watch, and a backend platform processing large volumes of behavioral and biometric data. To protect this ecosystem, Vitality needed to ensure that every interaction—from earning rewards to submitting activity data—came from a genuine, untampered app running on a trusted device, rather than scripts, bots, or compromised apps.

left-quote-svgrepo-com-1Approov gives us strong, reliable assurance that only genuine instances of our app are talking to our APIs. That’s absolutely essential when we’re protecting sensitive health data and rewarding healthy behavior. The integration was clean, the support was excellent, and we now have a mobile API security model we can trust.

'- Peter Paddock, Digital and Mobile Solutions Architect, Vitality'

Man-in-sports-gear-with-mobile-on-arm-1

The Challenge

With a growing base of highly engaged users and increasing integration with consumer health devices, Vitality faced several challenges:
- Ensuring API access only from genuine apps.
- Preventing mobile API abuse and reward fraud.
- Maintaining data integrity across iOS, Android, and Apple Watch.
- Securing high-value personal health data from interception or manipulation.

Apple Watch is particularly important, with a flagship program that rewards active members with a subsidized device. Because activity directly drives financial rewards, accurate, tamper-proof data is essential to the program’s fairness. At the same time, health and wellness data is highly valuable to criminals, fueling insurance fraud, identity theft, and targeted scams.

How Approov Mobile App Protection Helped

Approov’s Mobile App Attestation verifies the authenticity of every mobile API request, helping ensure that only trusted apps and devices can access backend APIs. This creates a zero-trust security layer for mobile apps, protecting backend systems even when devices are compromised. 

left-quote-svgrepo-com-1With a strong defense against scripted attacks in place we haven’t encountered any issues regarding credential stuffing or other security breaches.

Vitality-case-study-cover-1
Read the Full Story

Request a Demo

Give us 30 minutes and our security experts will show you how to protect your revenue and business data by deploying Approov to secure your mobile apps