Mobile apps that keep data where it belongs

Android and iOS apps that ask only for the permissions a feature needs. Aegis, our own Android app, is in early access.

Assume it gets taken apart

Designed against OWASP MASVS, OWASP MASTG and NIST SSDF.

  1. App binary

    The binary

    It will be taken apart. No secrets in the app, every rule enforced on the server.

  2. Permissions

    Permissions

    Only what a feature needs, asked for when it needs it.

  3. On the device

    Storage

    Secrets in the Keystore or Keychain. Nothing sensitive in backups or logs.

  4. Network

    Network

    TLS only, cleartext blocked, pinning where the risk is worth the upkeep.

  5. Your API

    API authorisation

    Tokens scoped to one user, checked on every request.

  6. Third-party code

    SDKs on purpose

    No ad or analytics SDK unless you decide you need one.

Your app runs on a phone you don’t control, in the hands of anyone who downloads it. We design for that from the first screen.

Phone, tablet and the API they call

  • Native Android apps

    Kotlin for phones and tablets, with Java where a codebase or library needs it.

  • Native iOS apps

    Swift and SwiftUI for iPhone and iPad.

  • Cross-platform apps

    Capacitor or React Native when one codebase is the right trade, native code where the platform needs it.

  • Privacy-first features

    On-device processing, the fewest permissions, and data that leaves only when the user says so.

  • Mobile APIs

    Tokens, rate limits and authorisation designed for a client that will be taken apart.

  • Store readiness

    Permission and privacy declarations written from what the code actually does.

Aegis is built this way

  • Aegis

    Status: Early accessAndroid 7.0 and later

    • Capacitor with a native Java plugin.
    • Scan information is processed on the phone. No advertising SDKs, no scan analytics.
    • Cloud backup is off for its data, and cleartext traffic is blocked.
    • Removal always goes through Android’s own uninstall confirmation.
    About Aegis

Native when it matters

  • Android

    KotlinJava

    Kotlin for new work. Java where a codebase needs it, as in Aegis’s native plugin.

  • iOS

    SwiftSwiftUI

    The Keychain and the privacy prompts used the way Apple intends.

Cross-platform

CapacitorReact Native

One codebase for both platforms, native code where it has to be.

Tools we use: Android Studio, Xcode, MobSF and Frida.

Native or cross-platform?

Native Kotlin and Swift when the app leans on the platform: background work, sensors, a demanding interface. Capacitor or React Native when one codebase serves both well. You’ll know which before we quote.

How do you keep user data safe?

Mostly by collecting less of it. Data stays on the device unless it has to leave, secrets go in the Keystore or Keychain, and traffic is TLS only.

Tell us about your app.

Android, iOS or both, and when it has to be in the stores. You get a written quote.