Sense
Sign inBook a demo
App Auth · Genuine app, bound device

Tell your real app apart from every copy of it.

App attestation and device binding give every genuine install a hardware-backed identity, checked on each call. Repackaged builds, cloned installs and scripted copies never hold a valid one — so your backend can tell them apart before it answers.

Book a walkthroughScan my app for clones
~40 msper verdict, on device
One keyper install, held in hardware
Bundledships with Sense RASP
INSTALL LEDGER · yourbank v8.2last 60 min
Play Store build · signed by youkey bound since 12 Mar · 3,412 installs
GENUINE
Resigned build from a mirror sitecertificate mismatch · no device key
REFUSED
Cloned install, 14th on one handsetkey already bound elsewhere
REFUSED
Emulated install calling the API directlyno platform attestation
REFUSED
Your backend sees one field: genuine, or notsigned verdict · per install · per call
47 refused today
THE PROBLEM

A copy of your app is cheap to make and expensive to serve.

Your build is downloadable, editable and re-signable by anyone. Everything that follows is an account your team has to clean up later.

01Your app, someone else's buildRepackaged copies sit on mirror sites and third-party stores with your name and logo. Customers install one, sign in, and never know.
02One handset, dozens of accountsCloned installs let a single device open account after account — signup bonuses, referral credit and mule accounts at farm scale.
03Limits edited out of the clientPaywalls, transaction caps and client-side checks are removed from a modified build, and the API answers it exactly as it answers you.
THE PROOF

Two questions, answered on every call.

Neither one asks anything of the customer. Both are checked in the app and signed into the request your backend already receives.

APP ATTESTATIONIs this the build we shipped?The app proves it is the build you published, signed by your certificate and unmodified since.
Package name and signing certificate
Repackaging and resigning detection
Play Integrity and App Attest checks
Debug, hooked and instrumented builds flagged
DEVICE BINDINGIs this the install we registered?Each install holds a key in the handset's secure hardware that never leaves the device.
Key generated in Keystore or Secure Enclave
One key per install, non-exportable
Challenged per call, so nothing replays
Cloned and emulated installs cannot answer
SIDE BY SIDE

Same screens. Same logo. Different app.

A customer cannot tell these apart. Pick what the copy on the right actually is.

yourbank · v8.2from the Play Store
signing certificateYOURS
package integrityUNMODIFIED
platform attestationPASSED
device keyBOUND · 12 MAR
Answered as your appGENUINE
yourbank · v8.2from a mirror site
signing certificateNOT YOURS
package integrityMODIFIED
platform attestationFAILED
device keyABSENT
Never answered as your appREFUSED

The customer-facing difference is nothing. The difference your backend sees is one signed field on the request.

WHERE IT SHOWS UP

What changes, journey by journey.

JOURNEY
TODAY
WITH APP AUTH
Signup & onboarding
TODAYA device can open accounts as fast as it can fill the form, and the pattern only surfaces in review.
WITH APP AUTHOnly registered installs of your build can start an application.
Login
TODAYCredentials are all the API asks for, whatever client sends them.
WITH APP AUTHThe call carries proof of a genuine app on a bound device.
Payments & transfers
TODAYA modified build can move a limit and the backend accepts the result.
WITH APP AUTHA tampered or unbound install is refused before the transfer is authorised.
Referrals & promos
TODAYCloned installs collect the same offer again and again.
WITH APP AUTHOne install, one identity — repeat claims have nowhere to hide.
IN THE BUNDLE

Ships as an add-on to Sense RASP.

One SDK, one console. RASP watches what happens inside a running app; App Auth answers who the install is in the first place. Turn it on for the endpoints that matter and leave the rest unchanged.

No login rebuild, no change to your auth provider — the verdict travels as a signed header on calls you already make.

WHAT YOU GET BACK
Fewer fraudulent accountsFarmed signups and promo abuse stop at the install, before a customer ID exists.
A session you can trustEvery request carries proof that it came from a real install of the build you shipped.
FIDO-aligned key handlingOWASP MASVSPlay IntegrityApp AttestISO 27001DPDP & GDPR

Authenticate the app, not just the password.

Send us one endpoint and we will show you how much of its traffic is not your app.

Free app scan