apkproof / the facts inside an APK
ENRU

Methodology

Cards come in two kinds, and they carry different facts. This page says exactly which.

Cards where we host the file

  1. The file is fetched from a source recorded in our configuration — the developer's own release page or site. We do not take files from stores or mirrors.
  2. Android's own apksigner verifies the signature before anything is written. A file that does not verify, that carries more than one signer, or whose report we cannot read unambiguously is refused: it never becomes a card.
  3. The certificate is compared against the one we recorded for that app. The first one is confirmed by hand: an editor reviews that the source is the developer's official distribution point and records the fingerprint, the source URL, their name and the date.
  4. A later release signed with a different certificate is rejected, and the card is not updated.
  5. Separately, an editor records why apkproof is prepared to distribute the file at all. Without that record the card has no page and serves nothing.
  6. We cache a VirusTotal reading of the exact file and show it as a dated count. A flagged file is pulled out of public serving.

Cards where we don't host the file

We hold no file and have checked none. The card points at the official source and lists reference details from that listing — the package name and the publisher the store names. Nothing on such a card is the result of a check we ran on an APK.

What none of this proves

  • Not that an app is safe. A signature says the file did not change after signing; it says nothing about what the code does.
  • Not who holds the signing key in real life. A certificate names a key, not a verified person or company.
  • Not a malware verdict. The VirusTotal count is a third party's dated reading, not our judgement.
  • Not an endorsement by any store or vendor, and no statement about anything we never held.

When something is wrong

A card can be taken off the site by one operator action while a report is reviewed. Where a takedown is sustained, we also stop accepting that app's package at ingest — plus the exact file hash and source URL when we know them — so a later release of the same app is refused rather than quietly re-added. Neither the takedown nor the refusal is a finding that anything infringes, and neither is a malware verdict: both are editorial decisions we record.

Report a copyright problem · Report a suspicious file

Who is responsible

Operator
Denis Ostroukhov
Status
Independent non-commercial project
Country
Serbia
Legal and privacy contact