Finished your 14 days of testing?

Find what stands between your app and Google Play - before you apply for production.

Upload your Android app. In minutes you get a launch checklist and the security problems a stranger could pull out of it - each with the exact fix, and a prompt for the AI that built it.

Google Play launch checklist

Target API level, release build, permissions that may need a Play Console declaration, and your Data Safety form - each marked ready, to do, or fix first.

Leaked keys

OpenAI, Stripe, Supabase service_role, AWS and hundreds more - including inside compiled React Native and Flutter code.

Supabase & Firebase setup

Which projects your app talks to, and whether the key it ships is the safe one.

Risky settings

Unencrypted traffic, trusting user-installed certificates, components other apps can open.

Data-collecting SDKs

400+ ad, analytics and tracking SDKs, and a pre-filled Data Safety draft built from them.

Known-vulnerable libraries

Bundled libraries matched against a database of published vulnerabilities.

How it works

  1. 1. Free check

    Upload your APK. In a few minutes you see how many potential issues we found.

  2. 2. Get the full report

    Pay once and it's written straight away - the fix for every checklist item and finding, an AI prompt per finding, and your Data Safety draft. Ready in a few minutes; we email you.

  3. 3. Fix and re-scan

    With the re-scan option, check your new version and see what you fixed.

Free check

Free

How many potential issues the scan found. What they are, and your launch checklist, are in the report.

Your first check is free. After that each one costs 1 Wizbit - earned by testing other developers' apps. Only for apps that are yours to scan.

Production readiness report

$10.00

The fix for every checklist item and finding, AI prompts, Data Safety draft, PDF.

Report + re-scan

$15.00

Everything in the report, plus a second scan of your fixed version showing what you fixed.

Questions

Is this a penetration test or a security certification?

No. It's an automated static analysis of the APK you upload: it reads the package, it doesn't attack your app or your servers. It finds real, specific problems, but no automated check can prove an app is secure, and a clean report is not a guarantee.

What happens to my APK?

It's encrypted, analysed in an isolated environment with no internet access, never installed or run, and deleted as soon as the scan finishes. The decompiled code is destroyed at the same time. Your report is kept for a year. You can delete both at any time.

Can I scan an app that isn't mine?

Only with the owner's written permission. You'll confirm this before every scan, and you're responsible for that confirmation.

What if the scan fails?

You're refunded automatically. If your file is rejected before scanning starts (for example, it's an App Bundle rather than an APK), your credit is returned straight away so you can try again.

Is the Data Safety draft ready to submit?

It's a starting point based on what's visible in your app. The scan can't see what your servers do with data, so check every line - you're responsible for what you declare to Google Play.

Sales tax or VAT is added at checkout where it applies. See our Terms of Service and Privacy Policy.

May we use analytics and ad measurement? Analytics (Vercel, and Ahrefs on our public pages) count page views without cookies. Ad measurement lets Google's tag on our public pages see which visits came from our Google ads, using a Google cookie. The site works the same either way. Cookie Policy · How Google uses data ·