Protection products
Commercial solutions, open-source libraries and coverage comparisons.
DexGuard: Android application protection
When evaluating DexGuard for Android app protection, assess code transformations separately from runtime checks.
Read the guideiXGuard: iOS code hardening and RASP
Evaluate iXGuard against iOS build, signing and framework requirements.
Read the guideIntroducing Promon Shield for Mobile
Assess Promon Shield by integration method and runtime coverage when building an application-protection shortlist.
Read the guideAppdome: a mobile application defense platform
When evaluating Appdome, establish how selected defenses enter the existing delivery pipeline.
Read the guideIntroducing Digital.ai Application Security
Define the platform and code scope of the proposed Digital.ai product. The product-family name alone does not establish protection of every application component.
Read the guideThe Zimperium MAPS product family
Do not treat MAPS as one control. Assess the questions answered by analysis, hardening and runtime components in separate evaluation entries.
Read the guideAssessing Zimperium zShield
For code-hardening products such as zShield, identify the protected code types and post-build output.
Read the guideZimperium zDefend and runtime risks
Assess which device or application risks zDefend turns into which responses in each workflow.
Read the guideDoveRunner and the former AppSealing name
Teams encountering DoveRunner and the older AppSealing name should first establish product and documentation continuity.
Read the guideIntroducing Talsec freeRASP
freeRASP is an option for teams assessing in-app security signals.
Read the guideIntroducing Talsec RASP+
Separate controls available in the free tier from the additional scope proposed for RASP+.
Read the guideApproov: app attestation and API protection
Assess Approov through the relationship between application and API trust.
Read the guideAppSweep mobile security testing
AppSweep supports mobile security assessment. Producing findings and embedding continuous protection into an application are different functions; choose tools…
Read the guideMobile threat visibility with ThreatCast
For services such as ThreatCast, event classification and context determine usefulness. The number of observed events is not a direct measure of prevented business loss.
Read the guideIntroducing Guardsquare App Attestation
Explain the boundaries where Guardsquare App Attestation evidence is generated and verified.
Read the guideAppknox mobile application security testing
Prioritize test scope and verifiable findings when assessing Appknox. An automated report does not independently accept every workflow or runtime defense.
Read the guideNowSecure mobile security assessment
Assess NowSecure through testing, evidence and integration with development. Preserve the relationship between the examined version and the final published package.
Read the guideIntroducing Quokka Q-mast
State which mobile risks Q-mast tests and under what conditions. Read its report alongside platform coverage and actual application behavior.
Read the guideOstorlab mobile security analysis
Analysis-platform output is a starting point. Teams must assess reachability, business impact and remediation evidence in application context.
Read the guideOversecured mobile application scanning
Oversecured output can support assessment of mobile code and configuration issues.
Read the guideRootBeer: an Android root-checking library
RootBeer provides checks for Android root indicators. Adding it does not complete an Android app protection architecture or establish certain knowledge of device state.
Read the guideIOSSecuritySuite: a Swift security library
IOSSecuritySuite is an option for Swift projects evaluating iOS security checks. Design how its results relate to server policy and legitimate usage.
Read the guideCertificate pinning with TrustKit
TrustKit is a library to consider for pinning implementations. Assess integration alongside pin transitions, failure behavior and older application versions.
Read the guideWhat is ProGuard, and can it replace RASP?
ProGuard transformations can affect analysis cost. Treating them as equivalent to integrity verification, root assessment or server enforcement creates incorrect…
Read the guideTalsec AppiCrypt and server-side risk decisions
Assess how AppiCrypt connects mobile data to server risk decisions. The protocol, failure policy and business outcome matter alongside product descriptions.
Read the guide