1. Scope
You share the app, the environment, and the detection stack. We agree on scope and authorization — written consent only, defensive purpose only.
Pilot program
A pilot runs the current rooting stack against your app on our device farm. You get a config-by-config gap report: what fired, what was bypassed, and how long each bypass took.
The pilot
You share the app, the environment, and the detection stack. We agree on scope and authorization — written consent only, defensive purpose only.
On our device farm we apply the rooting matrix: Magisk variants, Zygisk + Shamiko, KernelSU, APatch, Frida, overlay and mount tricks, verdict manipulation scenarios.
You get a config-by-config matrix: which checks fired, what was bypassed, how long each bypass took — plus prioritized fixes.
Optional regression CI: we re-run the matrix after your releases and after every major rooting-stack update.
Attack surface
Apply