IN THE WILD
●ARXAN SECURITY CONTINUES AT DIGITAL.AI●PROTECT · MONITOR · REACT●QUICK PROTECT AGENT AUTOMATES HARDENING

Company / Application security

Arxan taught software to guard itself

Once an app leaves its maker, the locks on the office door become rather irrelevant. Arxan built protection that travels with the code - and waited years for the market to catch up.

A software company has a peculiar delivery problem. The customer receives the product. So does the person who wants to take it apart. Both can download the same application, inspect its workings and run it on a machine the developer will never see. Arxan’s business begins at that uncomfortable moment: the code is out of the building, and the building’s security is no longer much help.

The story in four lines
  • Arxan puts defenses inside applications distributed to users.
  • Its roots lie in Purdue research on linked software guards.
  • Integration friction slowed early commercial adoption.
  • Since 2020, the technology has lived within Digital.ai.

Five founders, one awkward environment

In 2001, entrepreneur Eric Davis joined Purdue researchers Mikhail Atallah, Tim Korb, John Rice and graduate researcher Hoi Chang to form Arxan Technologies. Their subject was software operating in an untrusted environment. The mechanism became known as “guards”: protections placed at different points in code, linked together rather than left as a single conspicuous checkpoint.

Purdue helped with early funding, patent expenses, space and technology licensing. The intellectual problem was already clear. A conventional security boundary assumes you can keep an adversary outside. Distributed software grants the adversary a copy. You cannot ask a hostile laptop to behave nicely, however politely you word the license agreement.

The important unit of protection therefore became the application itself. Its defenses needed to travel wherever its executable went. That principle remains visible in Arxan’s current products.

The market had its own calendar

A promising mechanism did not immediately produce willing customers. In his retrospective, Davis describes early commercial protection as difficult to integrate, with platform support becoming a recurring expense. Software publishers were skeptical of piracy defenses. Every new compiler or chipset could mean more engineering before a sale.

Defense work offered an earlier market. Arxan later sold its defense business to Microsemi in 2010. Commercial demand strengthened with mobile computing; Davis recalls that profitability took more than eleven years. The first thing to disappoint was the assumption that explaining a clever invention would be enough to sell it.

2001Purdue roots
2013TA investment
2020Joins Digital.ai

Capital bought development time. A contemporary account records an $8.25 million Series B in 2003, after a six-month fundraising effort. TA Associates made a majority investment in 2013. In April 2020, Arxan joined CollabNet VersionOne and XebiaLabs in Digital.ai, backed by TPG Capital. Protection now sat alongside the machinery used to deliver software.

Three jobs, carried inside the app

Today’s Arxan Security proposition has three practical jobs. Hardening makes code harder to understand and alter. Monitoring tells the maker what is happening to distributed applications. Runtime application self-protection, or RASP, gives the application a response when a defense detects trouble.

The reaction need not be theatrical. A developer can configure additional authentication, change selected capabilities or shut an application down. Choosing among those responses is a product decision as well as a security decision. A banking app’s interrupted transaction and a game’s suspected cheat require different judgments.

Another product addresses a quieter vulnerability: cryptographic keys. Encryption is awkward when the person attacking the application can observe its execution. Digital.ai’s Key and Data Protection uses white-box cryptography to protect keys and operations in that exposed setting. It is relevant to payments, protected content and other applications whose secrets must survive close inspection.

Digital.ai monitoring product illustration showing script-modification and unauthorized-domain alerts
The app has a complaint. This Digital.ai product illustration shows alerts from software beyond its maker’s walls.

Threat monitoring makes those encounters visible. App Aware collects attack information and supplies alerts; integration with existing security operations tools lets the signals join a wider investigation. A shipped application can become a source of evidence, rather than an object everyone assumes is behaving.

The pirate’s bill arrives in engineering hours

Grass Valley’s EDIUS video-editing software provides a useful customer example. In Digital.ai’s published account, piracy and unauthorized changes were consuming engineering attention and damaging trust among paying users. The problem was larger than a missing license payment. Every defensive repair competed with work on the product.

Grass Valley applied stronger protections to critical parts of EDIUS, including mutual authentication between modules, and simpler protection elsewhere. The company integrated protection into its continuous integration and delivery pipeline. The unevenness matters: valuable code received more attention, rather than every component receiving the same treatment.

“The net benefit all comes down to one word: trust.”

Nobumasa Tamaoki · Grass Valley

The customer account reports no received cracking reports that modified the protected binary modules after implementation. That is a bounded observation about a protected portion of one application. It also offers a practical lesson: identify the assets that justify protection, automate that protection and judge the results against the original business problem.

Buying time, then maintaining it

Arxan sells to businesses making valuable software: banks, payment providers, publishers, gaming companies and medical-device manufacturers. The commercial model combines security software with implementation expertise. Current Digital.ai purchasing starts with a demonstration and a sales conversation. Buyers should budget engineering time alongside the software contract: build integration, device testing and response policies all require work.

Alternatives include Guardsquare, Promon and Appdome. Their capabilities overlap, especially on mobile. Arxan’s relevant distinction is its mobile, web and desktop coverage, key protection and place within Digital.ai’s wider delivery portfolio. The sensible comparison starts with the application’s actual languages and platforms, then examines protections, telemetry and deployment effort.

Digital.ai now promotes Quick Protect Agent v2, which uses AI-driven analysis to find valuable code paths and apply protection. Easier deployment addresses a difficulty present in Arxan’s earliest commercial years. Automation still leaves the maker responsible for deciding what matters.

Protection also needs maintenance. Digital.ai’s engineering principles emphasize new platform support and evolving defenses. Hardening cannot compensate for broken server authorization or a flawed business rule. Its useful promise is more modest: make inspection and tampering costlier, detect suspicious activity and respond deliberately. For software that must live on somebody else’s machine, that is a concrete job worth doing.