Home
Six languages. One verdict.¶
-
Kotlin — the reference
The original backend verifier, published on Maven Central as
tech.thessemaj:verifier-kotlin. Scan + token flows, zero dependencies. -
Python
Pip-installable port with the full token path and the scan-verification flow. Runs the same rooted-Pixel fixture, grades it the same.
-
TypeScript / Node
Feature-packaged npm module with a flat facade — token path complete, scan flow on the roadmap.
-
Go
Stdlib-only module:
crypto/ecdhX25519, AES-GCM,crypto/x509chain verification, embedded registry and pinned roots. -
PHP
PSR-4 package on ext-openssl + ext-sodium, self-contained test runner — no phpunit dependency.
-
Ruby
Gemspec-packaged port with a pure-Ruby RFC 7748 X25519 where the host OpenSSL binding falls short.
-
Rust
Crate-packaged port on the pure-Rust stack: dalek X25519, aes-gcm, p256/p384 ECDSA, rsa — zero OpenSSL linkage.
Three principles¶
-
Detection only
The device reports; the backend decides. Nothing is killed, blocked or degraded on-device — anything the app could enforce, a rooted attacker can remove.
-
Hardware-bound sessions
Hardware attestation runs once per session, keyed to the session id your backend issued. The attested key signs every later scan — a captured token is worthless anywhere else.
-
Opaque on the wire
Tokens carry
INTEL_XXXXcodes, not explanations. Detector names, probe mechanisms and evasion semantics never leave the device; your backend resolves them from the registry.
Verify a token in 30 seconds¶
What the device checks¶
-
Hardware attestation
Keymaster KeyDescription chains verified against pinned Google roots, StrongBox vs TEE assurance, challenge-bound freshness.
-
Verified boot
The TEE's own word on boot state and lock — a spoofer's self-report is cross-checked against hardware and flagged as INTEL_0055.
-
Hook frameworks
Inline prologues, GOT entries, JNIEnv tables, sealed memfds, linker<->maps divergence, behavioral syscall lies — mechanism-independent evidence.
-
Root & clones
su binaries, Magisk artifacts, init mount namespaces, daemon sockets, test-keys builds, foreign APK mappings.
-
Emulators
Translated environments, CPU re-routing anomalies, hypervisor evidence, VM platform markers — probes that cannot fire on genuine silicon.
-
Package tampering
Live APK vs build-time baseline: signature, entries, dex provenance, installer identity.
Prove it¶
Every port runs the same rooted-Pixel capture (KernelSU + TrickyStore) and grades it COMPROMISED, check-for-check. CI runs all six suites in parallel on every push:
Deep dive: the verification specification, the signal catalogue, and the verifier ports page carry the full contract and per-language coverage.