Z
Golden Armor Android · iOS · HarmonyOS Protection Service
Checking service
CROSS-PLATFORM APP PROTECTION

Golden Armor

One-stop post-build protection for Android, iOS, and HarmonyOS. No source code required - keep apps safe from decompilation, tampering, and repackaging.

3 free protectionsNever expires · Full features on every platform
PROTECTION MATRIX

One platform for three ecosystems

Independent and auditable workflows for every application format.

A

Android

DEX transformation, native runtime protection, ABI compatibility, repackaging, and signature verification.

  • DEX function extraction and virtualized execution
  • Method data AES-256-GCM encryption
  • Native runtime injection across four ABIs
  • v1+v2 re-signing with apksigner verification
i

iOS

Lightweight Mach-O processing, symbol cleanup, integrity manifests, and compliance reports.

  • ARM64 Mach-O structure and signature preflight
  • Local and debug symbol stripping with DWARF cleanup
  • SHA-256 integrity manifest for all files
  • Categorized sensitive plaintext audit report
H

HarmonyOS

HAP validation, Ark bytecode auditing, debug artifact cleanup, and re-signing delivery.

  • Stage-model HAP structure validation
  • Ark bytecode and native ABI inventory
  • Cleanup of source maps and other debug leftovers
  • Unsigned artifacts delivered with re-signing guidance
DEFENSE MATRIX

A layered defense system

A protection model benchmarked against leading hardening products, built around anti-reversing, integrity, security auditing, and delivery safety. Every capability ships with auditable evidence - no unverifiable claims.

Anti-reversing

Keep decompilers from recovering your Java business logic.

  • DEX method extractionDalvik bytecode is extracted class by class and method by method. Original bodies become stub shells, so decompilers only see native declarations.
  • DEX virtualized executionExtracted instructions are interpreted one by one in the native layer by an embedded Rust Dalvik interpreter, so method logic never appears as standard bytecode.
  • Method data encryptionExtracted data is stored with AES-256-GCM authenticated encryption, leaving no plaintext instructions inside the package.
  • Native runtime injectionThe in-house runtime library is injected automatically, supporting arm64-v8a, armeabi-v7a, x86_64, and x86.
  • Granular controlProGuard-style rule files and obfuscation mappings scope protection precisely by class and method.

Anti-tampering and runtime verification

Delivered artifacts continuously prove their integrity on-device.

  • Runtime signature verificationThe native runtime verifies the host APK's signing certificate fingerprint at startup against expectations in the encrypted data region, refusing to execute on mismatch - repackaging immediately breaks the app.
  • DEX integrity self-checkAt runtime, every classesN.dex in the APK is SHA-256 hashed and compared against the embedded manifest, exposing any tampering.
  • Package binding against SO theftThe runtime binds to the host package name, so the SO and encrypted data stop working when lifted into another app.
  • Re-signing with verificationOutput APKs are automatically signed with v1+v2 schemes and verified with the official apksigner before delivery.
  • Per-file integrity manifestSHA-256 is computed per file for iOS and HarmonyOS artifacts, producing an integrity manifest that exposes any modification.

Anti-dynamic attack

Fight debuggers and injection frameworks at runtime.

  • Anti-debuggingptrace self-attachment seizes the debug channel, blocking gdb/strace attaches, while a background thread continuously polls TracerPid.
  • Debug channel detectionMonitors the process thread list; a JDWP thread in a non-debuggable app is treated as an injection attack.
  • Anti-hookingVerifies GOT resolution ownership of critical libc functions and byte-compares function prologues against on-disk libc on arm64, detecting inline hooks.
  • Silent enforcementMulti-point checks only set an internal flag; protected calls then return harmless results, never exposing detection points to attackers.

Sensitive data audit

See what risky leftovers remain in the package before delivery.

  • Sensitive plaintext scanningBinaries and resources are pattern-matched for URLs, API keys, private keys, and secrets, with counts reported per category.
  • Reports never leak secretsAudit results contain only categories and counts - original strings are never exposed in reports.
  • Debug artifact cleanupiOS strips local and debug symbols and zeroes DWARF data; HarmonyOS removes source maps and tsbuildinfo files.
  • Auditable deliveryEvery job ships a processing report, integrity manifest, and logs, so each enabled capability can be verified.
  • Pre-protection checksDEX instruction compatibility scanning and duplicate-protection detection reject packages that cannot be processed safely, so no broken artifact is ever delivered.
  • Read-only code segmentThe iOS workflow removes write permission from the __TEXT segment, reducing the risk of runtime code patching.

Platform and data safety

Your packages and signing materials are protected as carefully as the artifacts themselves.

  • Job isolationEach protection job runs in an isolated temporary directory, and intermediate data is destroyed automatically afterwards.
  • Time-limited downloadsResult links use independent random tokens and expire automatically after 24 hours by default.
  • Signing material safetyCustom keystores are used only during the job and wiped with the job directory - never persisted.
  • No charge on failureCredits are reserved first and settled only on success; failed jobs release them automatically, so nothing is wasted.
SCENARIOS

Protecting core business scenarios

High-value businesses such as finance, gaming, enterprise, and IoT are prime targets for reverse engineering and repackaging attacks.

Mobile finance

Protect payment, account, and transaction logic from reverse analysis, reducing interface spoofing and protocol replay risks.

Mobile games

Raise the bar for cheating tools and cracking, protecting virtual assets, in-app purchase logic, and anti-cheat mechanisms.

Enterprise and government apps

Protect internal business logic and API endpoints, reducing data leakage and counterfeit distribution risks.

IoT and smart hardware

Protect device communication and control logic from analysis-driven protocol leaks and mass counterfeiting.

SIMPLE WORKFLOW

Protect your application in three steps

01

Upload the package

Choose an APK, IPA, or HAP. Source code is never required.

02

Isolated cloud protection

Each job runs in isolation and temporary data is removed afterwards.

03

Download and verify

Receive the protected package, integrity manifest, and audit report.

PRICING

Flexible usage options

Purchased credits accumulate forever. Active subscriptions are unlimited and never consume credits.

Loading prices…

Payment providers will be enabled in phase two. Prices currently show product configuration only.