VERIFICATION STANDARD · V3.2

How we verify APKs

A public standard for everyday users and security researchers: what we inspect, how we decide, and where verification has limits.

Standard updated: 2026-07-18Average processing time: 18 minutes
Receive fileConfirm sourceFile and hashSecurity analysisHuman release
THE CHECKLIST

Verification checklist

01

Release source

The file comes from a developer-confirmed release channel or another verifiable official distribution path.

Required
02

Package and version

Package name and version information inside the installer must match the published release data.

Must match
03

File hash

We store and display SHA-256 so anyone can independently confirm that a download was not replaced.

Fully published
04

Scanning engines

Static analysis and multiple malware-intelligence sources are combined with human review of unusual detections.

Multi-engine
05

Permission changes

We identify added, removed, and high-risk permissions and explain changes before download.

Version comparison
06

Dynamic behavior

High-risk or anomalous samples run in a sandbox to inspect network and file-system behavior.

Risk-triggered
IMPORTANT

What “verified” does not mean

It does not guarantee that an app has no product defects, and it cannot replace your judgment about permissions, privacy policies, and developer reputation. Verification means we have reasonable evidence for the file’s source, integrity, and safety at the time of review.