Pilot program

Your detection, attacked for real.

A pilot runs the current rooting stack against your app on our device farm. You get a config-by-config gap report: what fired, what was bypassed, and how long each bypass took.

The pilot

Four steps. Written consent first.

1. Scope

You share the app, the environment, and the detection stack. We agree on scope and authorization — written consent only, defensive purpose only.

2. Attack

On our device farm we apply the rooting matrix: Magisk variants, Zygisk + Shamiko, KernelSU, APatch, Frida, overlay and mount tricks, verdict manipulation scenarios.

3. Report

You get a config-by-config matrix: which checks fired, what was bypassed, how long each bypass took — plus prioritized fixes.

4. Re-run

Optional regression CI: we re-run the matrix after your releases and after every major rooting-stack update.

Attack surface

What we bring to your app.

  • Magisk (stable, Delta, Kitsune) with DenyList
  • Zygisk + Shamiko hiding
  • KernelSU (GKI and LKM) and APatch (SuperCall)
  • Frida and ptrace injection, overlay and mount tricks
  • Boot and verified-boot states, hardware attestation context

Apply

Three fields are enough to start.