Encrypted Push

šŸ“˜

API

indigitall has created a system of encrypted push notifications for data sensitive and economic transactions through a fast and customizable integration. It is an infallible system against hackers and, especially suitable for the development of financial activities, e-commerce, marketplaces and other sectors.

  • Safer than SMS service
  • Cheaper than SMS service
  • Acceptance Rate: + 20%

The encrypted push notifications serve to confirm the customer’s online purchases responding to the requirement of the European directive PSD2 for the implementation of the two-factor authentication process (Strong Customer Authentication: SCA).

  1. The customer receives the notification with an OTP code immediately and securely
  2. Thus verifying that the user is in possession of the trusted device, the only one capable of receiving these OTP codes.
  3. Afterwards, it is only necessary to confirm the identity among several options:
  • Something you know (password)
  • Something that is (fingerprint)
  • Something that is (face)

Our encrypted push system is developed and customized for each company being managed completely by the indigitall Team with the maximum guarantees and security measures. If you are interested, please let us know. Discover our e-book here!

Watch the video below to see how Push Secure outperforms traditional soft tokens and SMS by offering a more affordable, branded, and highly secure communication channel that increases approval rates while maintaining total data integrity.

Non-transactional App Push vs. Push Secure

The following table outlines the technical specifications and performance enhancements available when moving from standard Non-transactional App Push to the high-availability Push Secure microservice, specifically designed for mission-critical and transactional notifications.

FeatureNon-transactional App PushPush Secure
Security & EncryptionStandard OS-level encryption (APNs/FCM).End-to-End Encryption (E2EE): Content is encrypted at the backend and decrypted on-device with unique keys.
Delivery FeedbackAsynchronous (standard reporting).Real-time Synchronous Response: Immediate delivery status from providers (Apple, Firebase, Huawei).
Throughput / SpeedStandard API limits (up to 100 req/min).High-Performance: 250 requests per minute (independent of the standard Push API).
AvailabilityStandard availability for marketing.Mission-Critical High Availability: Designed for OTPs, transactional alerts, and real-time consumption limits.
Redundancy MechanismsManual or scheduled follow-ups.Immediate Backup Triggers: Automatic failover to SMS, WhatsApp, or Email based on real-time error responses.
Device Status TrackingClick and open rates.Rendering Confirmation: Ability to track if the notification was actually painted/displayed on the final device.
API ConnectivityStandard Push API.Dedicated Secure API: Exclusive endpoints to query real-time notification status and device events.

Key Technical Advantages of Push Secure

1. End-to-End Encryption (E2EE)

Push Secure ensures that sensitive payload data is encrypted at the origin (indigitall backend) and only decrypted at the destination (user device). By utilizing unique device-level keys, the content remains opaque to intermediaries, providing a robust defense against interception.

2. Synchronous Delivery & Automated Failover

Unlike standard asynchronous APIs, Push Secure provides a real-time response from the push service providers (FCM, APNs, HMS). This allows your infrastructure to apply Immediate Backup Mechanisms. If a push delivery fails due to connectivity or token expiration, the system can instantly trigger an alternative channel like SMS or WhatsApp, ensuring the user receives their critical notification without delay.

3. Hardware-Level Verification (Painted Status)

Standard push metrics often leave a "blind spot" between the provider sending the message and the user seeing it. Push Secure introduces a specialized event that signals when a notification has been successfully painted (rendered) on the device screen. This status is accessible via API, providing an unprecedented level of auditability for compliance-heavy industries.