FAQ

Eight questions buyers actually ask

CalfSec is Android app hardening (shell, optional Dex2C/VMP, evidence ZIP) with invite-only cloud jobs. Not MLPS/等保 certified, not MASA certified, not Cloud GA.

What is CalfSec?

Android APK/AAB hardening: shell, optional Dex2C/VMP, evidence ZIP. Cloud is invite-only jobs and quota, not a full threat console.

Can I self-register?

No. Invite only. Email to request access. Public registration stays closed.

Are you MLPS/等保 or MASA certified?

No. MLPS Level-2 is a build baseline (djbh_certified=false), not filed, not evaluated. Official MASA AL1/AL2 are not obtained.

Is this Cloud GA? Can I pay with a card?

Not Cloud GA. Paddle sandbox quota is for tests. Live card checkout is operator-configured; otherwise email for a quote.

Is this a DexGuard or 梆梆 substitute?

No. Comparable in spirit to industrial hardening, not claimed equivalent, and not Frida/Stalker immune. See the honest compare page.

How does Play App Signing work here?

Bind the app signing certificate, not the upload key. Delivery includes a cert inventory. No Play approval guarantee.

Do you harden Uni-app packages?

There is a pragmatic path (ClassLoader/resource overlay) and fail-closed cases such as blank screens. Not every Uni package will pass. See the Uni page.

Do you take my keystore? Is the upload the finished APK?

Customer keystore private keys are not collected by default. The uploaded APK is never the finished artifact; output SHA must differ.

Start trial