Mobile app protection for Android and iOS
Nothing crosses the moat.
Runtime protection for mobile apps, straight from your CI. No code changes.
No credit card required. The free plan covers your first app.
Works with the tools you already ship with
- GitHub
- GitHub Actions
- GitLab
- Bitrise
- Codemagic
- fastlane
- Jenkins
- CircleCI
- Xcode Cloud
- Android
- iOS
- React Native
- Expo
- Flutter
- Node.js
- Datadog
- Splunk
- Sentry
- PagerDuty
- Discord
Product names and logos are trademarks of their respective owners and are used only to indicate compatibility.
See all integrationsPlatform
Everything between your CI and production.
Five products that work together, from the pull request that adds protection to the live feed of what was stopped.
Code and string obfuscation, anti-tamper and integrity checks, added to your build pipeline through a pull request.
Learn more ShieldThreats
The attacks behind mobile fraud, stopped inside the app.
Runtime watches for the techniques attackers and fraud tools use, and acts by policy.
01
Root and jailbreak
Devices where the operating system protections were removed.
02
Emulators and virtual devices
Farms and sandboxes that automate abuse at scale.
03
Debuggers
Tools attached to inspect or change the app while it runs.
04
Hooking frameworks
Frida, Xposed and similar tools that rewrite behavior at runtime.
05
Tampering and repackaging
Modified or re-signed copies of your app.
06
Screen overlays
Fake screens drawn over your real payment or login screen.
07
Accessibility-service abuse
Malware that reads the screen or taps on the user's behalf.
08
Screen capture and recording
Sensitive content leaving the device in screenshots or recordings.
09
Remote-access tools
Someone else controlling the device during a transaction.
How it works
Protect your app in one pull request.
Connect, review, ship.
- 1
Connect your repo
Install the GitHub App and pick your Android or iOS project. Moatgator scans it and maps what needs protection.
- 2
Review one pull request
Moatgator opens a PR that adds protection to your build pipeline. You review it like any other change.
- 3
Ship and watch
Runtime checks run inside the app. Pulse shows what was attempted and what was stopped.
app: com.example.payplatforms: [android, ios]protect: shield: [obfuscation, anti-tamper] runtime: detect: [root, emulator, debugger, hooking, overlay] on_detect: monitor # monitor | warn | blockSolutions
Built for the way you ship.
Whether you are one developer or a security team, the workflow is the same.
- Fintechs and banksStop fraud on the device, keep evidence for audit.Learn more
- Startups and developersProtection without a security team.Learn more
- Agencies and software housesOne workflow to protect every client app.Learn more
- Vibecoders and makersScan your app, then fix the gaps with a pull request.Learn more
Pix Shield
Protect the payment screen, not just the login.
Banking trojans abuse overlays, accessibility services and remote access to move money out of real accounts. Pix Shield detects them on the device and can stop a transaction before it leaves.
- Overlay and accessibility-service abuse
- Screen capture and recording, with content hiding
- Active remote access, with transaction blocking
- Ready-made policies for payment screens
Security
Built so you can say yes to security review.
Practices designed for teams that have to answer to auditors.
Ephemeral builds
Build artifacts are short-lived and expire after 24 hours.
Your signing keys stay yours
Signing happens in your pipeline. Moatgator never holds your signing keys.
Aligned with OWASP MASVS
Scan reports map findings to MASVS controls your auditors already know.
LGPD-ready
Data processing terms and the subprocessor list are available on request.
Pricing
Start free. Pay per app as you grow.
Public prices, billed in USD with Brazilian reais available.
Hatchling
Free
Your first app, protected for free.
Indie
$19/mo
For solo developers and small apps.
Startup
$99/mo
For teams shipping to real users.
Scale
$399/mo
For growing portfolios and fintechs.
Enterprise
from$24,000/yr
For apps that move money.
Frequently asked questions
What is Moatgator?
Moatgator is runtime protection (RASP) for Android and iOS apps, added to your build by a pull request. It hardens the app, detects hostile environments such as root, Frida and emulators while the app runs, proves the app and device are genuine and shows you what was stopped.
Do I need to change my code or add an SDK?
No. Protection and runtime checks are added to your build by a pull request. The only code you write is the optional backend call that verifies an Attest verdict.
What is the difference between Shield, Runtime and Attest?
Shield makes the app hard to read and modify. Runtime detects hostile environments while the app runs and responds by policy. Attest gives your backend a signed verdict that the app and device are genuine. Pulse shows what happened, and Scan reports the gaps.
Which frameworks and CI systems are supported?
Native Android and iOS, React Native (including Hermes), Expo through EAS Build and Flutter, on GitHub Actions, GitLab CI, Bitrise, Codemagic, fastlane or any CI through the CLI.
Is there a free plan?
Yes. Hatchling protects your first app for free, up to 5,000 monthly active users, and Scan is free on every plan.
Can you trust what you ship?
Pick the way that suits you.
Start free
Protect your first app with the free plan. No credit card required.
Start freeTalk to sales
Questions about fintech, procurement or security review? Tell us what you need.
Talk to salesScan your app
Send your app and see the protection gaps an attacker would see.
Scan your app