Signed delivery
Every scanner module is Ed25519-signed and its signature verified on the device before it runs.
Mobile Hexii ships signed scanner modules to enrolled devices, captures DNS and VPN flow telemetry, inventories every installed app and permission, and scores the result with an explainable risk engine — so a finding always arrives with the evidence behind it.
Every scanner module is Ed25519-signed and its signature verified on the device before it runs.
Queries, flows, and counters — never payload, request bodies, or decrypted traffic.
Each score decomposes into the signals that produced it, largest contribution first.
Every dashboard and API write lands in a filterable, sortable audit trail.
Upload a Python module once. Mobile Hexii signs it, hashes it, and pins it to a platform, release channel, and app version range. Roll it out to a slice of your fleet, or revoke it instantly if it misbehaves.
Assign DNS-only or full VPN flow capture to any enrolled device. Queries, answer records, and flow metadata stream back with the raw packet bytes preserved — payloads are never touched. Search the whole capture by domain, resolved IP, port, or response code.
The scanner reads the device's package manager directly: every installed app, its signing certificate, and the full permission table with what was actually granted. Ask which package holds CAMERA and get an answer, not a spreadsheet.
Every risk score decomposes into the signals that produced it, largest contribution first. Open a finding to see the evidence, the provider verdict, and exactly how many points it added — no opaque numbers.
Every version is signed, hashed, and revocable from one screen.
Raw packet bytes are preserved so a finding traces back to what was observed.
The full package inventory, searchable down to a single permission.
Each score breaks down into the signals that produced it.
Component checks are recorded on every poll and kept for seven days — the same evidence standard we hold your scans to.