Graphs related to mobile app development

Speed to Market: Building a Mobile Banking App in a Year

Using NEAF’s pre-built components and security features, Neontri delivered a secure, feature-rich mobile banking platform in less than a year.

light gray lines
NEAF speeding  up the  development process

Client: A cloud-native digital bank 

Industry: Banking 

Scope: Design and development of a secure, multi-country mobile banking application

Key technologies: Kotlin Multiplatform (cross-platform development), Kotlin (backend), NEAF (SecureCore, Secure WebView, Admin Panel)

Timeline: Less than 1 year 

Challenge

We were approached by a banking client with ambitious plans to expand into multiple countries. To achieve this goal, they needed a high-quality mobile application that would appeal to their target customers and meet the highest quality standards. 

This posed two significant challenges:

  • As the bank handles sensitive customer data, the application needed robust security measures to protect documents and personal information in the cloud.
  • Since the client is a fully digital bank, they had no established tech landscape, so we had to build the entire infrastructure from scratch.

Solution

To meet the project goals, we implemented Neontri Enterprise Application Framework (NEAF), our proprietary development platform. Designed as a comprehensive white-label solution, it includes the essential components needed to build a secure, feature-rich application.

SecureCore: Built-in security at every layer

SecureCore, our robust security framework, was designed to fortify mobile applications against any potential vulnerabilities and threats, ensuring the highest levels of protection available for mobile applications. This comprehensive security model has several important features that were critical for the project’s success:

Security updates and patches are implemented independently of the operating system, ensuring the app’s security does not rely on the user’s device being up to date with the latest OS version.

  • Network communication between the client (app) and the server is secured using mutual TLS protocols, which involve two-way authentication to verify identities on both ends.
  • Our security model has its own integrated Public Key Infrastructure (PKI) system to issue and manage digital certificates and encryption keys.
  • Multiple techniques are employed to protect sensitive data stored locally on the device, including encrypted persistent storage, secure data wiping, and safe memory management practices.
  • The framework incorporates algorithms to verify the integrity of the application code, ensuring it has not been tampered with or modified. It also features anti-debugging measures and code obfuscation to prevent unauthorized individuals from accessing or reverse-engineering the app’s inner workings.
An office building on the mobile phone

Worried about mobile app vulnerabilities?

We build banking-grade security into every app from day one, so you don’t have to design it from scratch.

WebView: Secure foundation for hybrid applications

While platform-specific technologies are the best way to build an enterprise application, our client needed the flexibility of a hybrid application approach. With our WebView module, we were able to strike a balance between deployment speed and security, combining the strengths of native mobile development with the flexibility of web-based components within a single application.

Here are the key features of the WebView that allowed us to achieve these results:

  • Hybrid application support enables businesses to run web-based components securely within their native app.
  • The WebView component is implemented separately for iOS and Android, addressing potential vulnerabilities and compatibility issues across different versions of these operating systems.
  • Certificate pinning provides an extra layer of security to ensure that the WebView communicates only with trusted and verified servers.
  • WebView supports all HTTP methods, providing full functionality for web-based interactions within the native app.
  • JavaScript API facilitates access to native functions and hardware features, enabling integration between the app’s native and web-based parts.

Admin panel: Centralized control for app content

We enhanced our framework with a centralized control center, enabling the client to manage and customize the content displayed within their banking application. It streamlines the digital publishing process and allows the bank to tailor the app’s functionality to create an engaging user journey aligned with their service offerings.

The admin panel’s key capabilities:

  • Authorized personnel can easily update information, modify layouts, and add new components, ensuring that customers have access to the most up-to-date and relevant content.
  • The Admin Panel allows the client to incorporate their brand identity, color schemes, and visual elements, creating a consistent and personalized experience across all touchpoints.
  • Granular access controls and permission levels ensure that only authorized personnel can make changes to the app’s content and configurations, maintaining data integrity and regulatory compliance.
  • Detailed audit logs and version history track all changes made to the app’s content, enabling transparency, accountability, and the ability to roll back changes if necessary.
  • The user-friendly interface simplifies the content management process, reducing the learning curve and enabling efficient collaboration among teams responsible for maintaining and updating the banking application.
Neontri Enterprise Application Framework Architecture

On top of this architecture, we built the core functionality needed to manage the client’s mobile applications, including:

  • Multi-language support so users can engage with the app in their native language.
  • Dynamic rich text labels for efficient content management.
  • Feature toggle mechanisms to remotely enable or disable specific features, allowing developers to safely experiment with new functionality through A/B testing.
  • Intelligent caching that reduces redundant network requests and improves responsiveness.
  • In-app messaging mechanisms for delivery of essential notifications and prompts within the mobile app.

Delivery approach

To ensure a clear understanding of the client’s requirements, our team followed a structured process to design a high-performing, user-centric mobile app that fully met all functional expectations. 

The engagement began with a workshop phase, where the bank outlined their needs and objectives. Based on these requirements, Neontri experts defined the project’s scope and deliverables, then analyzed the client’s existing architecture to determine how our solution could best integrate with it.

With the scope defined, we assembled a mobile app development team with the right mix of skills to tackle the challenges ahead: 

  • three mobile developers;
  • three back-end developers;
  • three or four analysts;
  • a product owner;
  • a technical product owner;
  • and several testers.

This structured approach allowed us to complete discovery in just 4 weeks and deliver a working MVP within 6 months. 

Results

NEAF's impact on  time-to-market and  security

Neontri delivered a secure, user-friendly, and easily customizable mobile banking app that meets the client’s immediate requirements and provides a solid foundation to launch across their target markets.

  • Speed to market: The application was built and launched in less than a year, against an initial timeline of 18 months.
  • 30% faster development: NEAF’s pre-built libraries and ready-to-use back-end components allowed the team to bypass repetitive coding tasks and accelerate delivery. 
  • 65% safer than typical banking apps: SecureCore’s mutual TLS authentication, integrated PKI, and code integrity checks gave the client enterprise-grade protection for sensitive customer data from day one.
  • Multi-country readiness: The modular NEAF architecture, combined with the Admin Panel’s branding and content controls, allowed the client to configure and roll out the app across European markets without rebuilding core infrastructure.
purple abstract shapes

Looking to speed up your next mobile banking project?

How we integrate NEAF into your app

  • 01

    Discovery

    Joint sessions with business analysts, solution architects, and product owners to define business goals, target user flows, security constraints, and system dependencies.

  • 02

    Architecture setup

    The core security layer is configured alongside the application infrastructure to establish a strong technical foundation.

  • 03

    Core framework integration

    NEAF’s modular building blocks are embedded into native applications, with an API layer for seamless communication between the app and back-end services.

  • 04

    Custom feature development

    Building client-specific domain features directly on top of NEAF’s foundation accelerates overall time-to-market without disrupting existing operations. 

  • 05

    Testing and deployment

    Conducting end-to-end testing and security penetration audits to validate overall app resilience, performance, and compliance prior to launch.

Written by
Alia Shkurdoda

Alia Shkurdoda

Content Specialist
Andrzej Puczyk

Andrzej Puczyk

Head of Delivery
Share it
A neon style building

Banking Success with GenAI

Download our PDF and learn about how GenAI can elevate your business to a whole new level.

    By submitting this request, you are accepting our privacy policy terms and allowing Neontri to contact you.

    Get in touch with us!

      Files *

      By submitting this request, you are accepting our privacy policy terms and allowing Neontri to contact you.