Methodology
Every public record has a content kind — App or Game — and a handling mode: HOST, where we host the file, or DATA_LINK, where we point at the official source and hold no file. (A third mode, EXCLUDED, is used internally for things we will not serve; it never reaches the public catalogue.) The mode sets the ceiling on which file-related facts a card may carry — it does not invent them: within that ceiling we show only the facts we actually hold for the record. This page says exactly which.
Cards where we host the file
- The file is fetched from a source recorded in our configuration — the developer's own release page or site. We do not take files from stores or mirrors.
- The file is downloaded to temporary storage, and Android's own apksigner verifies the signature before a version is written to the catalogue. A file that does not verify, that carries more than one signer, or whose report we cannot read unambiguously is refused and not added as a version.
- The certificate is compared against the one we recorded for that app. The first one is confirmed by hand: an editor reviews that the source is the developer's official distribution point and records the fingerprint, the source URL, their name and the date.
- A later release signed with a different certificate is rejected, and the card is not updated.
- Separately, an editor records why apkproof is prepared to distribute the file at all. Without that record the card has no page and serves nothing.
- Where VirusTotal returned data on the exact file, we display it as a dated count, and a positive malicious-engine count blocks the file from public serving. Not every file has such a reading, and the count is a third party's data, not a malware verdict of ours.
Cards where we don't host the file
We hold no file and have checked none. The card points at the official source and lists reference details from that listing — the package name and the publisher the store names. Nothing on such a card is the result of a check we ran on an APK.
Categories and tags
A record's primary category and any curated tags stay inside its App or Game namespace. They are editorial classification only — a way to group and find records — and never a claim about trust, safety, a licence, a source, or any verification we ran.
What none of this proves
- Not that an app is safe. A signature says the file did not change after signing; it says nothing about what the code does.
- Not who holds the signing key in real life. A certificate names a key, not a verified person or company.
- Not a malware verdict. The VirusTotal count is a third party's dated reading, not our judgement.
- Not an endorsement by any store or vendor, and no statement about anything we never held.
When something is wrong
A record can be taken off the site by one operator action while a report is reviewed. Where a takedown is sustained, the operator can also activate exact-match blocks — on the package, and on the exact file hash and source URL when we know them — so the same package or file is refused at ingest rather than quietly re-added, for as long as the block stays active. Neither the takedown nor the refusal is a finding that anything infringes, and neither is a malware verdict: both are editorial decisions we record.