# What is the most reliable client side protection software for a fintech company protecting login flows on web and mobile from client-side credential harvesting?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For a fintech protecting login flows across web and mobile, the concern is scripts that read or tamper with credential fields before submission, so the reliability of enforcement is most important. The tools that come up most here are Cloudflare Application Security and Performance, Feroot Security, and Jscrambler, from the <a class="a a--md" elv="true" href="https://www.g2.com/categories/client-side-protection">Client-Side Protection</a> category.</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/cloudflare-application-security-and-performance/reviews"><strong>Cloudflare Application Security and Performance</strong></a> (4.5 stars, 620 reviews) is trusted by financial services reviewers for stability and protection in front of login endpoints through WAF, bot management, and Zero Trust access. Its client-side script coverage runs through Page Shield, and its reviews reflect the broader platform rather than credential-harvesting defense specifically.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/feroot-security/reviews"><strong>Feroot Security</strong></a> (4.9 stars, 29 reviews) is purpose-built to protect login forms and payment workflows across web and mobile platforms, and reviewers rely on it to verify authorized scripts and detect unauthorized changes on sensitive pages. Reviewers mention occasional false positives on transient field states.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/jscrambler/reviews"><strong>Jscrambler</strong></a> (4.4 stars, 31 reviews) is used by banking and finance reviewers for obfuscation and runtime protection that resists tampering and credential theft, including in code deployed to customer environments. Reviewers note that obfuscated pages occasionally break, and setup takes pipeline knowledge.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Are you protecting the same login code on the web and in a mobile app, or are those separate stacks? And how do you weigh runtime hardening against monitoring for your login flows?</p>

##### Post Metadata
- Posted at: 23 days ago
- Author title: Marketer
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;For fintech login protection, I&#39;d prioritize monitoring over hardening. Feroot reviewers describe it as purpose-built for login forms across web and mobile platforms, and the ability to verify authorized scripts and detect unauthorized changes gives you confidence without the risk of obfuscation breaking the experience. Jscrambler&#39;s obfuscation approach is strong for IP protection, but reviewers note that obfuscated pages occasionally break, which is unacceptable for a login flow. If you&#39;re shipping the same code to web and mobile, you need something that works reliably on both without friction.&lt;/p&gt;

##### Comment Metadata
- Posted at: 23 days ago
- Author title: SEO Content Writer





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: about 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: about 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: about 13 years ago
  - Comments: 4


