Play
Bind the app signing cert, not the upload key
For teams shipping to Google Play: hardening must target the right certificate or re-sign fail-closes.
With Play App Signing, devices see Google's app signing key, not your local upload key.
CalfSec binds the app signing certificate. Re-signing with the wrong cert fail-closes by design — control, not a sticker.
When you request a Trial, send: package name, Play App Signing status, cert fingerprints, APK or AAB.
Trial can include one remote call to walk the checklist. No store-approval guarantee. No immunity claims.
Customer keystore private keys are not collected by default. HSM/private cloud are not in public SKUs.
Play review depends on policy, content, and other technical items. Hardening is one piece. Not MASA — do not read this as an official badge.