Identify the vulnerabilites in your customer app. Run the free Ditto Protect app scan. Find out more

Ditto_protect_logo

See what an attacker sees in your app — and what Ditto Protect takes away

Pick an industry, and see what Ditto Protect can do...

ChatGPT Image Jun 10, 2026, 11_09_21 AM
Step one

Choose an industry

Six industries · illustrative data only

Northwind Banking*

Android · v4.2.0iOS · v4.2.1

Everyday current accounts, card controls and payments for four million retail customers.

Retail banking · illustrative example

Security score
41
CriticalHighModerateLow
Sits in the High band
Attack surface reduction
40,200
attack hits remaining, from 40,200
21 detection categories currently firing
Class and obfuscation reduction
7,900
named classes readable in the package
Every class name is readable in the shipped package
Detected in the unprotected build · 5
Financial and payment
Critical
395hits
5 of 8 patterns matched

Payment flows exposed without adequate transport security

Transport-layer weaknesses in checkout and transfer flows let an attacker on the same network read payment data in transit.

Learn more
not yet protected
Network and TLS configuration
Critical
290hits
9 of 14 patterns matched

TLS configuration allows interception of banking traffic

Permissive certificate handling made man-in-the-middle interception realistic on any untrusted network.

Learn more
not yet protected
Cloud and backend services
High
29,900hits
7 of 15 patterns matched

Backend service endpoints discoverable and under-protected

Internal API hosts and storage buckets were readable straight from the package, handing attackers a map of your estate.

Learn more
not yet protected
Insecure data storage
High
1,010hits
6 of 14 patterns matched

Some local caches still hold recoverable session data

Cached session artefacts remain on rooted devices; runtime protection narrows the window but cannot remove the files.

Learn more
not yet protected
Cryptography
Medium
880hits
12 of 21 patterns matched

Legacy crypto calls remain inside third-party libraries

Two bundled SDKs still call deprecated ciphers that cannot be rewritten without a vendor update.

Learn more
not yet protected

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.
Security score
41 88
CriticalHighModerateLow
High band → Low band
Attack surface reduction
7
attack hits remaining, from 40,200
18 of 21 detection categories fully eliminated
Class and obfuscation reduction
7,900 1,550
named classes readable in the package
80% of class names removed or renamed by obfuscation
Fully eliminated · 3
Financial and payment
Critical
3950hits
5 of 8 patterns matched

Payment flows exposed without adequate transport security

Transport-layer weaknesses in checkout and transfer flows let an attacker on the same network read payment data in transit.

Learn more
fully eliminated
Network and TLS configuration
Critical
2900hits
9 of 14 patterns matched

TLS configuration allows interception of banking traffic

Permissive certificate handling made man-in-the-middle interception realistic on any untrusted network.

Learn more
fully eliminated
Cloud and backend services
High
29,9000hits
7 of 15 patterns matched

Backend service endpoints discoverable and under-protected

Internal API hosts and storage buckets were readable straight from the package, handing attackers a map of your estate.

Learn more
fully eliminated
Still present · 2
Insecure data storage
High
1,01046hits
6 of 14 patterns matched

Some local caches still hold recoverable session data

Cached session artefacts remain on rooted devices; runtime protection narrows the window but cannot remove the files.

Learn more
95% reduced
Cryptography
Medium
880122hits
12 of 21 patterns matched

Legacy crypto calls remain inside third-party libraries

Two bundled SDKs still call deprecated ciphers that cannot be rewritten without a vendor update.

Learn more
86% reduced

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.

Larkspur Pay*

Android · v3.1.4iOS · v3.1.4

Instant transfers, virtual cards and expense controls for small business teams.

Payments and fintech · illustrative example

Security score
44
CriticalHighModerateLow
Sits in the High band
Attack surface reduction
27,800
attack hits remaining, from 27,800
19 detection categories currently firing
Class and obfuscation reduction
6,400
named classes readable in the package
Every class name is readable in the shipped package
Detected in the unprotected build · 5
Hardcoded credentials and secrets
Critical
148hits
6 of 26 patterns matched

Gateway API keys shipped inside the app binary

Live payment-gateway keys sat in plain strings, letting anyone replay authenticated calls from outside your app.

Learn more
not yet protected
Financial and payment
Critical
512hits
7 of 15 patterns matched

Card entry screens open to overlay attacks

Nothing stopped a malicious app from drawing over the card-entry flow to harvest details as they were typed.

Learn more
not yet protected
Anti-tamper and integrity
High
24,600hits
9 of 18 patterns matched

App runs happily after being repackaged

Modified builds passed no integrity check, so cloned wallets could be distributed outside the official stores.

Learn more
not yet protected
Insecure data storage
High
1,340hits
5 of 14 patterns matched

Transaction history cached longer than needed

Statement data persisted in local storage after sign-out; only a fraction survives once storage is hardened.

Learn more
not yet protected
Third-party SDKs
Medium
640hits
8 of 19 patterns matched

Analytics SDK still reads device identifiers

A vendor SDK collects hardware identifiers under its own consent flow, outside the protected boundary.

Learn more
not yet protected

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.
Security score
44 85
CriticalHighModerateLow
High band → Low band
Attack surface reduction
12
attack hits remaining, from 27,800
15 of 19 detection categories fully eliminated
Class and obfuscation reduction
6,400 1,280
named classes readable in the package
80% of class names removed or renamed by obfuscation
Fully eliminated · 3
Hardcoded credentials and secrets
Critical
1480hits
6 of 26 patterns matched

Gateway API keys shipped inside the app binary

Live payment-gateway keys sat in plain strings, letting anyone replay authenticated calls from outside your app.

Learn more
fully eliminated
Financial and payment
Critical
5120hits
7 of 15 patterns matched

Card entry screens open to overlay attacks

Nothing stopped a malicious app from drawing over the card-entry flow to harvest details as they were typed.

Learn more
fully eliminated
Anti-tamper and integrity
High
24,6000hits
9 of 18 patterns matched

App runs happily after being repackaged

Modified builds passed no integrity check, so cloned wallets could be distributed outside the official stores.

Learn more
fully eliminated
Still present · 2
Insecure data storage
High
1,34064hits
5 of 14 patterns matched

Transaction history cached longer than needed

Statement data persisted in local storage after sign-out; only a fraction survives once storage is hardened.

Learn more
95% reduced
Third-party SDKs
Medium
64098hits
8 of 19 patterns matched

Analytics SDK still reads device identifiers

A vendor SDK collects hardware identifiers under its own consent flow, outside the protected boundary.

Learn more
85% reduced

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.

Ashgrove Insure*

Android · v2.8.2iOS · v2.8.3

Motor and home cover with photo-based claims assessment and instant quotes.

Insurance · illustrative example

Security score
47
CriticalHighModerateLow
Sits in the High band
Attack surface reduction
20,600
attack hits remaining, from 20,600
18 detection categories currently firing
Class and obfuscation reduction
5,200
named classes readable in the package
Every class name is readable in the shipped package
Detected in the unprotected build · 5
Insecure data storage
Critical
268hits
7 of 14 patterns matched

Claim documents left readable on the device

Uploaded photographs and claim PDFs were written to shared storage where any other app could read them.

Learn more
not yet protected
Network and TLS configuration
High
1,910hits
8 of 21 patterns matched

Claims traffic sent over downgradeable connections

Fallback to cleartext was permitted, so an attacker could force claims submissions onto an unencrypted channel.

Learn more
not yet protected
Cloud and backend services
High
16,700hits
6 of 15 patterns matched

Document storage buckets addressable from the app

Bucket names and region hints in the package allowed direct enumeration of stored claim evidence.

Learn more
not yet protected
Personal data handling
Medium
780hits
9 of 20 patterns matched

Some diagnostic logs still capture policy numbers

Verbose logging in the offline quote module records policy references that reach your crash reporter.

Learn more
not yet protected
Cryptography
Medium
410hits
6 of 18 patterns matched

Legacy key derivation in the offline quote module

An older derivation routine remains for backwards compatibility with quotes saved on previous versions.

Learn more
not yet protected

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.
Security score
47 86
CriticalHighModerateLow
High band → Low band
Attack surface reduction
9
attack hits remaining, from 20,600
15 of 18 detection categories fully eliminated
Class and obfuscation reduction
5,200 1,120
named classes readable in the package
78% of class names removed or renamed by obfuscation
Fully eliminated · 3
Insecure data storage
Critical
2680hits
7 of 14 patterns matched

Claim documents left readable on the device

Uploaded photographs and claim PDFs were written to shared storage where any other app could read them.

Learn more
fully eliminated
Network and TLS configuration
High
1,9100hits
8 of 21 patterns matched

Claims traffic sent over downgradeable connections

Fallback to cleartext was permitted, so an attacker could force claims submissions onto an unencrypted channel.

Learn more
fully eliminated
Cloud and backend services
High
16,7000hits
6 of 15 patterns matched

Document storage buckets addressable from the app

Bucket names and region hints in the package allowed direct enumeration of stored claim evidence.

Learn more
fully eliminated
Still present · 2
Personal data handling
Medium
780110hits
9 of 20 patterns matched

Some diagnostic logs still capture policy numbers

Verbose logging in the offline quote module records policy references that reach your crash reporter.

Learn more
86% reduced
Cryptography
Medium
41088hits
6 of 18 patterns matched

Legacy key derivation in the offline quote module

An older derivation routine remains for backwards compatibility with quotes saved on previous versions.

Learn more
79% reduced

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.

Vantage Play*

Android · v6.0.7iOS · v6.0.5

Live tables and tournaments with real-money balances and instant payouts.

Gaming and betting · illustrative example

Security score
38
CriticalHighModerateLow
Sits in the Critical band
Attack surface reduction
38,900
attack hits remaining, from 38,900
22 detection categories currently firing
Class and obfuscation reduction
9,600
named classes readable in the package
Every class name is readable in the shipped package
Detected in the unprotected build · 5
Anti-tamper and integrity
Critical
640hits
8 of 18 patterns matched

Game client can be modified without detection

Balance and odds logic could be patched in a repackaged build and still connect to your live tables.

Learn more
not yet protected
Runtime hooking
Critical
33,400hits
11 of 22 patterns matched

Hooking frameworks attach to the running game

Common instrumentation tools attached at runtime, exposing every in-game call and wallet operation.

Learn more
not yet protected
Hardcoded credentials and secrets
High
96hits
5 of 26 patterns matched

Server tokens embedded in the shipped build

Static service tokens in the binary allowed table state to be queried without an authenticated session.

Learn more
not yet protected
Emulator and rooted devices
High
2,100hits
7 of 16 patterns matched

Play from emulators remains partly possible

Hardened checks block known emulators, but bespoke virtual devices can still reach the lobby.

Learn more
not yet protected
Third-party SDKs
Medium
520hits
6 of 19 patterns matched

Ad SDK still fingerprints the device

The bundled ad network builds its own device signature outside the protected runtime.

Learn more
not yet protected

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.
Security score
38 81
CriticalHighModerateLow
Critical band → Low band
Attack surface reduction
14
attack hits remaining, from 38,900
18 of 22 detection categories fully eliminated
Class and obfuscation reduction
9,600 1,820
named classes readable in the package
81% of class names removed or renamed by obfuscation
Fully eliminated · 3
Anti-tamper and integrity
Critical
6400hits
8 of 18 patterns matched

Game client can be modified without detection

Balance and odds logic could be patched in a repackaged build and still connect to your live tables.

Learn more
fully eliminated
Runtime hooking
Critical
33,4000hits
11 of 22 patterns matched

Hooking frameworks attach to the running game

Common instrumentation tools attached at runtime, exposing every in-game call and wallet operation.

Learn more
fully eliminated
Hardcoded credentials and secrets
High
960hits
5 of 26 patterns matched

Server tokens embedded in the shipped build

Static service tokens in the binary allowed table state to be queried without an authenticated session.

Learn more
fully eliminated
Still present · 2
Emulator and rooted devices
High
2,100180hits
7 of 16 patterns matched

Play from emulators remains partly possible

Hardened checks block known emulators, but bespoke virtual devices can still reach the lobby.

Learn more
91% reduced
Third-party SDKs
Medium
52096hits
6 of 19 patterns matched

Ad SDK still fingerprints the device

The bundled ad network builds its own device signature outside the protected runtime.

Learn more
82% reduced

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.

Meridian Stay*

Android · v5.4.1iOS · v5.4.0

Booking, mobile room keys and contactless check-in across 240 properties.

Travel and hospitality · illustrative example

Security score
45
CriticalHighModerateLow
Sits in the High band
Attack surface reduction
18,400
attack hits remaining, from 18,400
17 detection categories currently firing
Class and obfuscation reduction
4,800
named classes readable in the package
Every class name is readable in the shipped package
Detected in the unprotected build · 5
Hardcoded credentials and secrets
Critical
132hits
6 of 26 patterns matched

Door-key service credentials sat in the package

Credentials for the mobile key service were extractable, putting room access logic within reach of an attacker.

Learn more
not yet protected
Network and TLS configuration
High
1,420hits
7 of 21 patterns matched

Booking traffic interceptable on shared wifi

Weak certificate validation made guest bookings readable on exactly the networks guests use most.

Learn more
not yet protected
Cloud and backend services
High
14,900hits
5 of 15 patterns matched

Reservation APIs enumerable from the client

Endpoint patterns in the binary allowed reservation identifiers to be walked without authentication.

Learn more
not yet protected
Insecure data storage
Medium
690hits
5 of 14 patterns matched

Guest profile cache persists after sign-out

Name and stay history remain in an encrypted local cache until the next launch clears it.

Learn more
not yet protected
Personal data handling
Medium
320hits
7 of 20 patterns matched

Loyalty identifiers still appear in crash reports

Membership numbers are attached to diagnostic payloads handled by your third-party reporter.

Learn more
not yet protected

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.
Security score
45 84
CriticalHighModerateLow
High band → Low band
Attack surface reduction
6
attack hits remaining, from 18,400
14 of 17 detection categories fully eliminated
Class and obfuscation reduction
4,800 990
named classes readable in the package
79% of class names removed or renamed by obfuscation
Fully eliminated · 3
Hardcoded credentials and secrets
Critical
1320hits
6 of 26 patterns matched

Door-key service credentials sat in the package

Credentials for the mobile key service were extractable, putting room access logic within reach of an attacker.

Learn more
fully eliminated
Network and TLS configuration
High
1,4200hits
7 of 21 patterns matched

Booking traffic interceptable on shared wifi

Weak certificate validation made guest bookings readable on exactly the networks guests use most.

Learn more
fully eliminated
Cloud and backend services
High
14,9000hits
5 of 15 patterns matched

Reservation APIs enumerable from the client

Endpoint patterns in the binary allowed reservation identifiers to be walked without authentication.

Learn more
fully eliminated
Still present · 2
Insecure data storage
Medium
69074hits
5 of 14 patterns matched

Guest profile cache persists after sign-out

Name and stay history remain in an encrypted local cache until the next launch clears it.

Learn more
89% reduced
Personal data handling
Medium
32060hits
7 of 20 patterns matched

Loyalty identifiers still appear in crash reports

Membership numbers are attached to diagnostic payloads handled by your third-party reporter.

Learn more
81% reduced

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.

Cardia Health*

Android · v1.9.6iOS · v1.9.6

Appointments, repeat prescriptions and remote cardiac monitoring for patients at home.

Healthcare · illustrative example

Security score
43
CriticalHighModerateLow
Sits in the High band
Attack surface reduction
24,700
attack hits remaining, from 24,700
20 detection categories currently firing
Class and obfuscation reduction
6,900
named classes readable in the package
Every class name is readable in the shipped package
Detected in the unprotected build · 5
Personal data handling
Critical
214hits
9 of 20 patterns matched

Patient records written to unprotected storage

Monitoring readings and prescription history were cached in cleartext on the device filesystem.

Learn more
not yet protected
Cryptography
Critical
1,060hits
12 of 21 patterns matched

Health data encrypted with deprecated ciphers

Records at rest used algorithms considered broken, so encryption offered little practical protection.

Learn more
not yet protected
Cloud and backend services
High
21,300hits
6 of 15 patterns matched

Clinical backend endpoints exposed in the binary

Hostnames for the clinical record service were readable, exposing internal infrastructure to probing.

Learn more
not yet protected
Third-party SDKs
High
940hits
8 of 19 patterns matched

Monitoring SDK still transmits device metadata

The device vendor SDK reports hardware telemetry through its own channel, outside the protected boundary.

Learn more
not yet protected
Insecure data storage
Medium
400hits
4 of 14 patterns matched

Appointment cache readable on rooted devices

A small appointment cache stays accessible where the device itself is already compromised.

Learn more
not yet protected

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.
Security score
43 85
CriticalHighModerateLow
High band → Low band
Attack surface reduction
11
attack hits remaining, from 24,700
16 of 20 detection categories fully eliminated
Class and obfuscation reduction
6,900 1,410
named classes readable in the package
80% of class names removed or renamed by obfuscation
Fully eliminated · 3
Personal data handling
Critical
2140hits
9 of 20 patterns matched

Patient records written to unprotected storage

Monitoring readings and prescription history were cached in cleartext on the device filesystem.

Learn more
fully eliminated
Cryptography
Critical
1,0600hits
12 of 21 patterns matched

Health data encrypted with deprecated ciphers

Records at rest used algorithms considered broken, so encryption offered little practical protection.

Learn more
fully eliminated
Cloud and backend services
High
21,3000hits
6 of 15 patterns matched

Clinical backend endpoints exposed in the binary

Hostnames for the clinical record service were readable, exposing internal infrastructure to probing.

Learn more
fully eliminated
Still present · 2
Third-party SDKs
High
94088hits
8 of 19 patterns matched

Monitoring SDK still transmits device metadata

The device vendor SDK reports hardware telemetry through its own channel, outside the protected boundary.

Learn more
91% reduced
Insecure data storage
Medium
40070hits
4 of 14 patterns matched

Appointment cache readable on rooted devices

A small appointment cache stays accessible where the device itself is already compromised.

Learn more
83% reduced

16 more categories in the full report

Findings, hit counts and pattern detail for the remaining categories are withheld in the public showcase. Run a scan on your own build to see all of them.

Insecure data storageCryptographyThird-party SDKsWebView securityAnti-debuggingRoot and jailbreak detectionEmulator detectionNative library hardeningLogging and diagnosticsDeep link handlingInter-process communicationBiometric integrationSession managementCertificate handlingCode obfuscation coveragePermissions and manifest
Added by Ditto Protect
Code signing hardened
Signature and installer origin verified at every launch.
Anti-tamper protection added
Modified or repackaged builds refuse to run.
Anti-hook protection active
Runtime instrumentation is detected and blocked.
How Ditto Protect works

One build, zero code changes

Unmanaged devices, public networks, reverse-engineered binaries, handsets that drift out of compliance months after they ship, Ditto Protect manages it all, without slowing down a release.

  • tick-filled

    Harden at build time

    Upload a release or plug into CI/CD. Every binary ships obfuscated and hardened automatically, no code to write or maintain.

  • tick-filled

    Protect data in the app

    Secrets and sensitive local data are encrypted and device-bound, never resting on the OS keychain alone.

  • tick-filled

    Respond automatically

    A detected threat triggers a warning, a branded lock screen, or end the session, configurable per business and per detection type.

  • tick-filled

    Detect continuously

    Every protected app becomes a live sensor for device integrity, tampering and network threats, for the life of the install, not just at login.

  • tick-filled

    Prove it is working

    The detection test suite runs real attacks against a live device and confirms the right defence fired, providing evidence, not assertion.

What’s inside?

Built to close attack vectors, not just patch them

Four layers work together, hardening, detection, fleet oversight and analytics so protection is something you can point to, not just something you are told.

Illustrated Card 1

Build-time hardening

Every release ships obfuscated by default, Android code and string obfuscation, iOS symbol obfuscation, native-code protection, with nothing for engineering to write or maintain.

Illustrated Card 2

Runtime detection

Over 50+ configurable detections span device integrity, tampering and network threats — each one independently tuned to warn, lock or end a session.

Illustrated Card 3

Malware lab and analytics

Every build is scored against OWASP, MASVS and MASTG, and tested against real malware families, producing evidence of protection, not just a claim.

Illustrated Card 4

One view across the fleet

One dashboard for every app, version and device, live threat feed, geo view and automated countermeasures, so nothing is missed.

warning-filled 1
Never miss a threat

Ditto Protect catches what others don't.

Ditto's research lab found an entire app catalogue from a single developer quietly running overlay attacks on banking apps, passing every antivirus check while requesting root access and talking to known malware servers. Protect caught what they could not.

Why Organisations
Choose Ditto Protect

Ditto Protect goes beyond traditional endpoint protection, embedding device trust, runtime protection and secure channels into your application with no development overhead or disruption to your existing stack.

password-MFA

Block Attacks Before They Cause Damage

Malware hijacks sessions while backend systems see nothing.

Ditto Protect monitors for overlays, hooking frameworks, code injection and tampering from first launch, stopping attacks before they can impact your systems or your customers.

fraud

Built for Regulatory Compliance

Built to align with DORA, NIS2, PSD2 and the Cyber Resilience Act, Ditto Protect enforces runtime protections that continuously monitor and log threat activity across every session.

The result is audit-ready evidence that proves compliance, accelerates reviews and keeps you ahead of evolving regulatory requirements.

minimise

More Intelligence. Better Risk Decisions.

Machine learning correlates device, network and application threats in real time, scoring risk across every session.

Those signals feed directly into your existing fraud and risk platforms, giving your team better intelligence without replacing the tools or the expertise they already have.

See Ditto Protect in Action

Combine device integrity, runtime protection, and secure channels to stop fraud before it starts.

CTA Image

Comprehensive Threat Protection

Privacy-by-design protection across four attack surfaces minimising data collection while preserving individual privacy by default.

See Ditto
Protect in Action

Protect logins, transactions, and wallets by detecting compromised devices and sessions in real time.

Book your demo today

Shape your identity
stack with Ditto: