Skip to content
Contact us

Moatgator Shield

Harden every build before it ships.

Code and string obfuscation, anti-tamper and integrity checks, added to your build pipeline through a pull request.

Your sourceDecompiled outputShield
Your source, Decompiled output, Shield

Make reverse engineering expensive.

Attackers start by reading your app. Shield rewrites the compiled app so that logic, endpoints and secrets are far harder to read, change and repackage, without touching your source code.

  • Code and string obfuscation
  • Anti-tamper and integrity checks
  • Mapping files kept for readable crash reports

What Shield does

  • 01

    Name and code obfuscation

    Renames classes, methods and fields and restructures control flow, so decompiled output tells an attacker little about how the app works.

  • 02

    String encryption

    On Android, endpoints, keys and other sensitive strings are encrypted in the build and decrypted only when they are needed.

  • 03

    Integrity and anti-tamper

    The app verifies its own code and signature at runtime and reacts when a modified or re-signed copy runs.

  • 04

    Per-build diversification

    Protection varies from build to build, so a bypass written for one release does not carry over to the next.

  • 05

    Asset and resource protection

    Bundled assets and resources are protected, so they cannot simply be unpacked and reused elsewhere.

  • 06

    Readable crash reports

    A mapping file is produced for every build and works with Crashlytics, Sentry and Play Console to de-obfuscate stack traces.

How Shield fits your release

  1. 1

    Protect in your pipeline

    A pull request adds Moatgator to your Android or iOS build. Protection runs on the compiled app, never on your source.

  2. 2

    You sign, as always

    Moatgator hands back an unsigned artifact. Your pipeline aligns and signs it, so signing keys and certificates stay with you.

  3. 3

    Know the cost

    Every build reports its effect on app size and startup time, so you can tune what you enable.

moatgator.ymlIllustrative example
shield:  android:    obfuscation: names + control-flow    string_encryption: true    asset_protection: true  integrity: signature + code  diversify_per_build: true  report: [size, startup]   # impact per build

What Shield covers

Android

  • Class, method and field renaming
  • Control-flow obfuscation
  • String encryption
  • Resource and asset protection
  • Integrity and signature checks

iOS

  • Name, string and symbol hardening
  • Re-signing in your own pipeline
  • Certificates and profiles stay with you

Frameworks

  • React Native with Hermes bundle protection
  • Expo through an EAS Build custom function
  • Flutter with Dart code protection

Frequently asked questions

Does Shield change my source code?

No. It works on the compiled app inside your build pipeline, through a pull request you review.

Will protection slow my app down or make it bigger?

Protection adds some overhead. Every build reports its effect on app size and startup time, so you can see the cost and tune which protections you enable.

Do you hold my signing keys?

No. Moatgator returns an unsigned artifact and your own pipeline signs it. Keys, certificates and provisioning profiles stay with you.

Does it work with React Native, Expo and Flutter?

Yes. React Native bundles built with Hermes are protected, Expo works through an EAS Build custom function, and Flutter apps get Dart code protection.

Will my crash reports still be readable?

Yes. A mapping file is generated for every build, and it works with Crashlytics, Sentry and Play Console to de-obfuscate stack traces.

Is obfuscation enough on its own?

No. Obfuscation raises the cost of analysis; it does not stop a determined attacker. Pair Shield with Runtime, which detects tampering and instrumentation while the app runs.

Ready to protect your app?

Start free, or tell us what you need.