Harden the build
Obfuscation and string protection ship in the Client binary. Secrets still stay in KeysDefender — not in JS.
App Security · AppDefender.dev
Obfuscation, anti-tampering, and anti-analysis for source and binary.
Broader than renaming classes. CodeDefender covers obfuscation, string and control-flow protection, JS/Hermes and native layers, anti-decompilation, Frida/Xposed/LLDB, APK/IPA repackaging, and runtime binary checks. If the build is rebuilt or hooked, the launch score fails.
What it does
CodeDefender is integrity and anti-analysis for the Client binary — not a rename-only obfuscator. It covers JavaScript, Hermes bytecode, the React Native bridge, and the native Android / iOS layers that AppDefender already scores.
String encryption, control-flow protection, and anti-decompilation raise the cost of static analysis. Runtime checks catch Frida, Xposed, LLDB, and signature mismatch after a repack. If the APK or IPA is rebuilt, the launch score fails before login.
CodeDefender does not replace AppDefender. It feeds the same Detect → Decide → Enforce path. A hooked exam, fee, or UPI build is BLOCK. Super Admin still enables Sandbox first so Makers can prove FAIL paths.
What it scores
How it runs
Obfuscation and string protection ship in the Client binary. Secrets still stay in KeysDefender — not in JS.
Integrity and hooking sensors run with AppDefender before Client UI. Isolated Android and iOS catalogs do not mix.
A rebuilt or hooked package is BLOCK. The security screen uses the Client app name only.
Operators
Enables the environment that holds the hardened catalog. Production changes still need two checkers.
Reviews integrity FAILs in ThreatDesk for that Client. Sandbox proof comes before Production.
Other App Security modules
All modules