Skip to content

FAQ

Can device_shield stop a determined attacker?

Section titled “Can device_shield stop a determined attacker?”

No. Every check runs on the device, and tools like Magisk DenyList and Frida can defeat on-device checks. Use it to raise the cost of tampering and as a risk signal. For guarantees, use server-verified attestation. See the Security model.

Should I block rooted or jailbroken users?

Section titled “Should I block rooted or jailbroken users?”

Only after measuring. Log results in production first and look at which signals fire on real users. Many legitimate users run custom ROMs. A softer response, such as extra verification, is usually better than a hard block.

No. It makes no network requests and stores nothing.

On Android it adds one install-time permission (DETECT_SCREEN_CAPTURE) and package-visibility entries. Neither shows a prompt. Location permission is optional, requested by your app, and only used for mock-location detection.

Why is iOS screenshot protection not supported?

Section titled “Why is iOS screenshot protection not supported?”

Apple provides no API to block screenshots. Techniques that work around this rely on undocumented UIKit behaviour, which is fragile and failed in testing.

No. Android and iOS only.

Not yet. See Installation.

How is this different from other root/jailbreak packages?

Section titled “How is this different from other root/jailbreak packages?”

It reports which signals fired, not just a boolean. It says when a check doesn’t apply (applicable: false) or failed (status: failed), and its documentation states what has and hasn’t been verified.