Skip to content
Contact us

Mobile app protection for Android and iOS

Nothing crosses the moat.

Runtime protection for mobile apps, straight from your CI. No code changes.

No credit card required. The free plan covers your first app.

FridaOverlayRepackEmulatorRemote
Live threat feedSample data

Works with the tools you already ship with

Product names and logos are trademarks of their respective owners and are used only to indicate compatibility.

See all integrations

Platform

Everything between your CI and production.

Five products that work together, from the pull request that adds protection to the live feed of what was stopped.

Your sourceDecompiled outputShield
Your source, Decompiled output, Shield

Code and string obfuscation, anti-tamper and integrity checks, added to your build pipeline through a pull request.

Learn more Shield

Threats

The attacks behind mobile fraud, stopped inside the app.

Runtime watches for the techniques attackers and fraud tools use, and acts by policy.

  • 01

    Root and jailbreak

    Devices where the operating system protections were removed.

  • 02

    Emulators and virtual devices

    Farms and sandboxes that automate abuse at scale.

  • 03

    Debuggers

    Tools attached to inspect or change the app while it runs.

  • 04

    Hooking frameworks

    Frida, Xposed and similar tools that rewrite behavior at runtime.

  • 05

    Tampering and repackaging

    Modified or re-signed copies of your app.

  • 06

    Screen overlays

    Fake screens drawn over your real payment or login screen.

  • 07

    Accessibility-service abuse

    Malware that reads the screen or taps on the user's behalf.

  • 08

    Screen capture and recording

    Sensitive content leaving the device in screenshots or recordings.

  • 09

    Remote-access tools

    Someone else controlling the device during a transaction.

See every detection

How it works

Protect your app in one pull request.

Connect, review, ship.

  1. 1

    Connect your repo

    Install the GitHub App and pick your Android or iOS project. Moatgator scans it and maps what needs protection.

  2. 2

    Review one pull request

    Moatgator opens a PR that adds protection to your build pipeline. You review it like any other change.

  3. 3

    Ship and watch

    Runtime checks run inside the app. Pulse shows what was attempted and what was stopped.

moatgator.ymlExample policy, versioned in your repo.
app: com.example.payplatforms: [android, ios]protect:  shield: [obfuscation, anti-tamper]  runtime:    detect: [root, emulator, debugger, hooking, overlay]    on_detect: monitor   # monitor | warn | block

Pix Shield

Protect the payment screen, not just the login.

Banking trojans abuse overlays, accessibility services and remote access to move money out of real accounts. Pix Shield detects them on the device and can stop a transaction before it leaves.

  • Overlay and accessibility-service abuse
  • Screen capture and recording, with content hiding
  • Active remote access, with transaction blocking
  • Ready-made policies for payment screens
Explore Pix Shield
Transfer, Fake overlay, Transaction blocked, Remote access, Accessibility abuse

Security

Built so you can say yes to security review.

Practices designed for teams that have to answer to auditors.

  • Ephemeral builds

    Build artifacts are short-lived and expire after 24 hours.

  • Your signing keys stay yours

    Signing happens in your pipeline. Moatgator never holds your signing keys.

  • Aligned with OWASP MASVS

    Scan reports map findings to MASVS controls your auditors already know.

  • LGPD-ready

    Data processing terms and the subprocessor list are available on request.

Read about our security practices

Pricing

Start free. Pay per app as you grow.

Public prices, billed in USD with Brazilian reais available.

  • Hatchling

    Free

    Your first app, protected for free.

  • Indie

    $19/mo

    For solo developers and small apps.

  • Startup

    $99/mo

    For teams shipping to real users.

  • Scale

    $399/mo

    For growing portfolios and fintechs.

  • Enterprise

    from$24,000/yr

    For apps that move money.

See pricing and compare plans

Frequently asked questions

What is Moatgator?

Moatgator is runtime protection (RASP) for Android and iOS apps, added to your build by a pull request. It hardens the app, detects hostile environments such as root, Frida and emulators while the app runs, proves the app and device are genuine and shows you what was stopped.

Do I need to change my code or add an SDK?

No. Protection and runtime checks are added to your build by a pull request. The only code you write is the optional backend call that verifies an Attest verdict.

What is the difference between Shield, Runtime and Attest?

Shield makes the app hard to read and modify. Runtime detects hostile environments while the app runs and responds by policy. Attest gives your backend a signed verdict that the app and device are genuine. Pulse shows what happened, and Scan reports the gaps.

Which frameworks and CI systems are supported?

Native Android and iOS, React Native (including Hermes), Expo through EAS Build and Flutter, on GitHub Actions, GitLab CI, Bitrise, Codemagic, fastlane or any CI through the CLI.

Is there a free plan?

Yes. Hatchling protects your first app for free, up to 5,000 monthly active users, and Scan is free on every plan.

Can you trust what you ship?

Pick the way that suits you.

  • Start free

    Protect your first app with the free plan. No credit card required.

    Start free
  • Talk to sales

    Questions about fintech, procurement or security review? Tell us what you need.

    Talk to sales
  • Scan your app

    Send your app and see the protection gaps an attacker would see.

    Scan your app