Enroll
The first honest launch binds device and SIM after ALLOW. Sandbox proof comes before Production enrollment.
App Security · AppDefender.dev
Zero-trust device and SIM binding for the enrolled handset.
Keeps the session on the device and SIM Super Admin enrolled. Detects SIM swap, cloned device, and sideloaded twins. Binding is evaluated at launch and again on ATS Full payment routes.
What it does
BindDefender keeps a Client session on the enrolled Android or iOS handset and SIM. That is the NPCI-shaped control banks already expect — applied at the launch gate, not only after a password.
Clone installs, sideloaded twins, and SIM swap fail the bind. Super Admin can block one device without taking down the Client app for everyone else. Binding is scored at launch and again when ApiDefender runs ATS Full.
BindDefender does not replace AppDefender. A rooted enrolled phone is still BLOCK. A clean phone with a swapped SIM fails bind. Isolated Sandbox and Production catalogs never share bind records.
What it scores
How it runs
The first honest launch binds device and SIM after ALLOW. Sandbox proof comes before Production enrollment.
Launch and ATS Full payment routes confirm the same handset. A twin install fails.
Super Admin blocks that Android or iOS device. Other Client users stay up.
Operators
Enables bind policy per environment. Can block one handset without a Client-wide outage.
Sees bind FAILs for that Client. Cannot copy Production bind keys into Sandbox.
Other App Security modules
All modules