See what an app does with your data.
Scan at volume, export the findings, or commission a teardown from the analyst who wrote the published research.
Free
$0
Public scorecards, forever.
Check any app before you install it.
- Scan any public app, as many as you want
- TRUSTED verdict across every trust check
- Findings summary with severity breakdown
- See in plain language what leaves the device
- Public catalog access
- One free rescan a month
For researchers
Research
$299/month
Scan at volume and export the findings.
- 50 detailed scans per month
- Submit in bulk by API
- Technical report: deobfuscated code, file and line references, SDK inventory and observed behavior
- Export all findings as JSON
- Private scans. Results never published
- Direct APK / IPA / XAPK upload
- Custom prompts: ask any app a specific question and get a written answer
- AI chat over the findings: open a scan and ask follow-up questions about its results
- Cross-app query across every app you've scanned (coming soon)
Custom
Let's scope it.
Book a call
Corpus-scale screening and teardowns on commission.
- Scan beyond 50/month, up to whole-category sweeps
- Named-analyst teardowns, the same work behind the published research
- Screen the vendor and third-party apps your org depends on
- White-label and co-branded reports
- Turnaround committed in the contract
- Written findings suitable for regulatory or legal use
The verdict is never for sale.
Paying gets you volume, JSON exports, and commissioned teardowns. It never changes what an app scores.
Not a pattern scanner
| MobSF / QARK | CITT | |
|---|---|---|
| Analysis method | Regex / pattern matching | Reads the decompiled code |
| False positive rate | High (no context) | Low (reads the surrounding code) |
| What to fix first | Generic flag list | Risk-ranked by what it exposes |
| AI-powered | No | Yes, with adversarial review |
| Deobfuscation | Breaks most rules | Reads through it |
| Disclosure mapping | No | Findings mapped to GDPR, CCPA, and COPPA guidance |