Play

Bind the app signing cert, not the upload key

For teams shipping to Google Play: hardening must target the right certificate or re-sign fail-closes.

With Play App Signing, devices see Google's app signing key, not your local upload key.

CalfSec binds the app signing certificate. Re-signing with the wrong cert fail-closes by design — control, not a sticker.

When you request a Trial, send: package name, Play App Signing status, cert fingerprints, APK or AAB.

Trial can include one remote call to walk the checklist. No store-approval guarantee. No immunity claims.

Customer keystore private keys are not collected by default. HSM/private cloud are not in public SKUs.

Play review depends on policy, content, and other technical items. Hardening is one piece. Not MASA — do not read this as an official badge.

Start trial