Release source
The file comes from a developer-confirmed release channel or another verifiable official distribution path.
A public standard for everyday users and security researchers: what we inspect, how we decide, and where verification has limits.
The file comes from a developer-confirmed release channel or another verifiable official distribution path.
Package name and version information inside the installer must match the published release data.
We store and display SHA-256 so anyone can independently confirm that a download was not replaced.
Static analysis and multiple malware-intelligence sources are combined with human review of unusual detections.
We identify added, removed, and high-risk permissions and explain changes before download.
High-risk or anomalous samples run in a sandbox to inspect network and file-system behavior.
It does not guarantee that an app has no product defects, and it cannot replace your judgment about permissions, privacy policies, and developer reputation. Verification means we have reasonable evidence for the file’s source, integrity, and safety at the time of review.