Building in the open. On our terms.
A privacy tool that asks for trust should be verifiable. We are open-sourcing the detection engine under AGPL-3.0, documenting everything we do, and giving researchers controlled access to the data we collect.
Building in the open.
On our terms.
A privacy tool that asks for trust should be verifiable. We are open-sourcing the detection engine under AGPL-3.0, documenting everything we do, and giving researchers controlled access to the data we collect. The app UI and backend stay closed. The part that matters is the part you can read.
Detection methodology documented
Scan pipeline, data sources, architecture diagram, and what the AI does vs. doesn't do. Published at /how-it-works.
v5.7.0 shipped with 3 new detection systems
MalwareBazaar hash lookup, AppXpose CertNet, and Community APK Hash Verification. Three systems live and learning.
Detection engine hardening and review prep
Finalizing the public-facing interface boundary, stabilizing APIs, and preparing the engine for external code review.
Detection engine open-sourced under AGPL-3.0
The core engine (DEX reader, tracker matcher, integrity checker, signature database) published as a standalone library on GitHub. The app UI and backend remain closed.
Public research API with controlled access
CertNet data, scan corpus statistics, and tracker intelligence accessible via API key. Request access, we review.
F-Droid listing submitted
AppXpose available on F-Droid, the largest open-source Android app repository.