Cache
After an honest online launch, the device holds a signed policy for that environment only.
App Security · AppDefender.dev
Signed cached policy and local detection when the radio is down.
Offline Threat Defender is a first-class module inside the Launch Security Gate. When the network is down, a signed cached policy plus local sensors still return ALLOW, RESTRICT, or BLOCK. Waiting for the cloud is not fail-open.
What it does
Offline Threat Defender runs on every launch. AppDefender sensors score the handset against a signed cached policy when the radio is down. React Native UI is not trusted until the gate returns a decision.
The same BLOCK rule holds on a rooted or hooked handset with a valid access token. Network restore does not reopen a blocked launch. Sandbox and Production caches never mix.
Super Admin enables the environment. Client Admin sees offline FAILs in ThreatDesk for that Client only. Fail mode is operator policy — default is BLOCK.
What it scores
How it runs
After an honest online launch, the device holds a signed policy for that environment only.
Local AppDefender and CodeDefender sensors run against the cache. No API call is required.
ALLOW, RESTRICT, or BLOCK. A later network path cannot override BLOCK.
Operators
Enables Offline Threat Defender per environment. Owns default failMode.
Reviews offline FAILs. Cannot copy a Production cache into Sandbox.
Other App Security modules
All modules