Frequently asked questions

Know these boundaries before hardening an APK

These answers cover files, signing, strategy selection, independent retesting, and delivery. They do not replace complete regression testing for your application.

APK hardening workflow demonstration
Keep the APK, signing context, configuration, and validation result for every release to make investigation more controlled.
  1. 1Prepare a valid APK
  2. 2Choose a risk-appropriate strategy
  3. 3Download the unsigned artifact
  4. 4Sign and complete real validation

Files and signing

The workspace accepts valid APK files. Delivered artifacts are unsigned and must be finally signed by the application owner.

Protection and compatibility

Choose features based on dependencies and device coverage. Regress critical product flows after every configuration change.

Scanning and release

External scanning offers an independent signal, but real-device, signing, and destination-channel validation remain required release steps.

Validate a minimum profile with a real candidate

Keep the APK, signing context, configuration, and validation result for every release to make investigation more controlled.

Upload an APK

Questions

Understand the boundaries before configuring

Which files are supported?

The workspace currently accepts valid APK files.

Does the website provide online multi-engine scanning?

No. Follow the scan guide to conduct independent retesting with compliant third-party tools.

Does an APK need signing after hardening?

Yes. Sign it with your own material before final installation or distribution.

Ready to start?

Upload an APK and choose a protection strategy in the workspace

Upload an APK