AppXpose AppXpose
Credits & Data Sources

Standing on
open shoulders.

AppXpose is built on the work of community projects and open databases. Here is what we use, why, and what gets transmitted. No fine print, no buried disclosures. For legal processor details, see our privacy policy.

01

Have I Been Pwned

haveibeenpwned.com ↗

Troy Hunt's breach database. We pull the public /api/v3/breaches catalogue - a list of every known breach with its domain, date, and affected data types. Our server then matches each scanned app's developer domain against this list. No email address is ever sent. No API key is used. No personal data leaves the device. We query the catalogue, not individual accounts. GUARD subscribers get automatic alerts when a developer they have installed shows up in a new breach.

Data transmitted: none. Public catalogue only.
02

MalwareBazaar

bazaar.abuse.ch ↗

A community-driven, nonprofit malware sample exchange run by abuse.ch - a research project at the Bern University of Applied Sciences. When AppXpose scans an app, it sends only the APK's SHA-256 hash to MalwareBazaar's lookup API. Never the APK itself, never file contents, never metadata about you. If the hash matches a known malware sample, the scan result reflects it. MalwareBazaar is free, open, and funded by donations.

Data transmitted: SHA-256 hash only. → Support abuse.ch ↗
03

Koodous

koodous.com ↗

A community-driven Android threat intelligence platform with millions of analyzed APK samples. When AppXpose scans an app, the APK's SHA-256 hash is checked against Koodous in parallel with MalwareBazaar. Two independent databases, queried simultaneously, zero extra latency. If Koodous flags the hash as detected or negatively rated by the community, the risk score increases. Koodous is free and open.

Data transmitted: SHA-256 hash only.
04

AppXpose CertNet

Internal

Our own crowd-sourced database of 4,700+ verified Android app signing certificates. Every time an AppXpose user scans an app, the signing certificate hash is compared against the known-good baseline. If someone installed a repackaged APK with a different cert, CertNet catches it. The database grows with every scan - trust-on-first-use for new apps, verification for everything after. No personal data is stored alongside certificates. CertNet is entirely first-party.

Data transmitted: cert hash + package name. No device identifiers.
05

Anthropic Claude

anthropic.com ↗

The LLM behind AppXpose's natural-language risk reports. When you scan an app, our server sends the app's metadata - name, package, permissions, category, pre-computed risk score, tracker list, and breach history - to Claude's API. Claude writes the explanation you read. It never receives bytecode, APK contents, device identifiers, or anything about you. The prompt is deterministic: same app, same data, same report. Claude does not train on AppXpose data.

Data transmitted: app metadata + permissions. No personal data, no bytecode.
06

Cloudflare

cloudflare.com ↗

Our entire backend runs on Cloudflare Workers at the edge - no central server, no traditional hosting. D1 (Cloudflare's SQLite-based database) stores the analysis cache, scan corpus, tracker signatures, and community votes. This website is served via Cloudflare Pages. All data stays within Cloudflare's infrastructure. We chose Workers because they execute close to the user, keep cold-start latency low, and let a one-person operation run infrastructure that scales without ops overhead.

Role: hosting, database, edge compute. All infrastructure.
07

APKiD Patterns

github.com/rednaga/APKiD ↗

APKiD is an open-source tool for identifying packers, obfuscators, and other compilers used in Android apps. AppXpose's on-device APK Integrity Checker uses detection patterns inspired by APKiD's research to analyze DEX headers, signing blocks, native libraries, and file structures for tampering indicators. The checker has been expanded beyond APKiD's original scope to also detect hooking frameworks, root tools, debug artifacts, and repackaging indicators.

Data transmitted: none. Runs on-device.