02What the platform does
Capabilities
Nine analysis and operations capabilities, working together on every release, from source inspection to signed, framework-mapped evidence.
Static analysis
Inspects your app's source and bytecode for insecure patterns before the app ever runs. Works with Android (Java, Kotlin), iOS (Swift, Objective-C) and hybrid frameworks.
Dynamic analysis
Launches your app on an emulated device and observes its real behaviour: network calls, storage, permissions and inter-app communication.
Runtime instrumentation
Hooks live function calls to verify that security controls such as certificate pinning, root detection and data protection work as intended on an emulated device.
Secret detection
Finds API keys, tokens and credentials that were accidentally bundled into the application package. Detections are prioritised so real risks stand out from false positives.
Software bill of materials
Generates a complete inventory of third-party libraries in every release and matches each dependency against recognised vulnerability sources.
Framework coverage
Every finding is mapped to an OWASP MASVS / MASTG test-case identifier. Reports reference NIST SSDF and ISO 27001 controls where applicable, so evidence is portable across audits.
Integrations
Plug the platform into your CI/CD system, issue tracker and SIEM. Open tickets, block risky merges, stream events, all through supported connectors or a generic webhook.
Single sign-on and access control
SAML 2.0 and OIDC single sign-on, role-based access control, per-tenant isolation and an immutable audit log for privileged actions.
Flexible deployment
Use the platform as SaaS, deploy it inside your own cloud account, or install it fully air-gapped on-premise. The feature set is the same in every mode.