Kubian  ·  Enterprise Android Attestation

Enterprise-grade hardware attestation.
Low, scaling prices.

Anticheat & attestation for Android · phones + VR headsets

Kubian is an enterprise-grade hardware attestation and anticheat service for Android. Detect tampering, stop rooted devices, validate hardware integrity, and enforce studio-defined rules from one operational panel — without building an internal anti-cheat team.

Start a studio inquiry → Review the protection layers
● Service available Android · Available Meta Quest · Available Built for Unity (LTS) — more engines coming soon
scroll ↓

Platform

PlatformAndroid (phones + VR)
MonitoringContinuous
EnforcementStudio controlled
EnginesUnity (LTS)
Service statusAvailable

Independent signals. One security decision.

Selected public capabilities. A complete inventory of safeguards remains intentionally undisclosed.

Hardware attestation

Hardware-backed (TEE / StrongBox) attestation certificates validate boot state, bootloader lock, OS patch level, and platform integrity at the system level.

Root & hidden root detection

Rooted environments — including hidden and stealth root (Magisk, KernelSU) — are detected before they can enter a protected session.

Realtime injection prevention Kubian Max

Frida, hooking and injection frameworks are detected and blocked in realtime, along with app debugging.

App integrity validation

Package name, certificate digest and runtime state are validated throughout the session — not only at launch.

Detection routing

Security events move into review, moderation, analytics, and studio-defined enforcement workflows.

Session enforcement

Verified trust signals stay active through the session, so teams can respond with context.

These are selected public capabilities, not a complete inventory. Additional safeguards remain intentionally undisclosed to keep the suite effective.

A practical SDK workflow for game teams

Unity (LTS)Native Android
  • Guided SDK setup Add Kubian to your project with direct help from our team.
  • No rewrite required Fits your existing pipeline without forcing a rewrite.
  • Managed verification backend Signature checks, replay protection, and device bans handled for you.
  • Direct integration support Unity (LTS) projects supported with hands-on help. Custom engine support is not available yet.

Verification backend

Challenge-response attestation with hardware-backed keys. Every challenge is unique and single-use, so attestation responses cannot be replayed. Backend ownership is up to you — self-managed or fully managed by Kubian.

See what happened. Decide what happens next.

99.99%
API uptime
150–300ms
Response time
PS-256
Encryption
PS-256 (RSASSA-PSS with SHA-256) is a probabilistic digital signature algorithm used to sign JWTs. Every attestation verdict and integrity response is signed with PS-256, so session data cannot be forged or tampered with.
Kubian
by Static Labs LLC
Attestation operational Kubian — Max Example Studio — VR Title
demo@example.studio D
Operational Overview
Players Validated
1,284
Offenders Flagged
23
Pending Reviews
4
Active Bans
6
Trusted Now (30m)
412
API Requests — Last 24 Hours
00:00 · 20 req 01:00 · 12 req 02:00 · 8 req 03:00 · 6 req 04:00 · 9 req 05:00 · 18 req 06:00 · 32 req 07:00 · 48 req 08:00 · 62 req 09:00 · 71 req 10:00 · 58 req 11:00 · 46 req 12:00 · 55 req 13:00 · 63 req 14:00 · 72 req 15:00 · 80 req 16:00 · 95 req 17:00 · 88 req 18:00 · 76 req 19:00 · 68 req 20:00 · 74 req 21:00 · 69 req 22:00 · 58 req 23:00 · 44 req
00:0006:0012:0018:00Now
Recent Activity
a13d8f91b2c4d6e8 verification_failed
DEVICE_BOOT_LOADER_INTEGRITY_FAILED
2026-08-13T02:17:10.883019
91e7c3d4e5f6a7b8 verify_success
DEVICE_PASS
2026-08-12T23:44:02.105633
Critical Flags
DEVICE_BOOT_LOADER_INTEGRITY_FAILED
a13d8f91b2c4d6e8f0a92c1e7d4b5f6a8c9d0e1f2a3b4c5d6e7f8a9b0c1d2
high PENDING
2026-08-13T02:17:10
Signed in as demo@example.studio for Example Studio — VR Title. Select a section from the sidebar to get started. Auto-refreshes every 10s · Last refreshed 05:22:37
All settings implemented are cached for 1 hour, so after changing you will have to wait for the old cache to expire.
Realtime Protection Max
On-device checks the Kubian library performs while the app is running. The configuration is cryptographically signed by Kubian and cached for 1 hour, so the library rejects any tampered response and falls back to full protection.
Frida Detection
Detect the Frida instrumentation framework (maps, files and default ports).
Injection Detection
Detect Xposed, Zygisk, LSPosed, Substrate, ShadowHook, Dobby and other runtime hooks.
Root (Hard)
Strong root signals: su binaries, uid 0, Magisk/KernelSU mounts and hidden root modules.
Root (Soft)
Weak root signals: SELinux permissive, test-keys builds and insecure/debuggable properties.
Debugger Detection
Detect an attached debugger through TracerPid.
Anti-Debug Trap
Arm the ptrace/seccomp trap that blocks debugger attachment.
Device
Boot integrity, OS version and device trust checks
Device Integrity
Fail when Kubian Integrity reports the device integrity as "Compromised".
Verified Boot Keys
Fail when the verified boot key or hash values are zeroed out.
Trusted Boot State
Fail when SecurityLevel or VerifiedBoot is "NotTrusted", or the bootloader is unlocked.
Security Level
Require the reported security level to be "Advanced" or "Basic".
Verified Boot
Require VerifiedBoot to be "Trusted".
Bootloader Lock
Require BootloaderLocked to be "True".
OS Version / Security Patch
Fail when the OS patch level is below the minimum (202606). Disable to skip OS version checks.
Hardware
Hardware-backed attestation checks
Hardware Certificate
Require the intermediate hardware certificate to be present and well-formed.
Application
App binary and package checks
Application SHA-256
Require the app binary digest to match the registered SHA-256.
Application Package
Require the app package to be recognized and match the registered identifier.
601046ec7dfe70e9
Registered 2026-05-18T11:40:12.004113
TRUSTED VALID
a13d8f91b2c4d6e8f0a92c1e7d4b5f6a8c9d0e1f2a3b4c5d6e7f8a9b0c1d2
Registered 2026-03-28T14:09:33.112087
BANNED 3 FLAGS
cc04aab1c2d3e4f5a6b7f190c2e3d4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1
Registered 2026-06-02T09:15:41.882341
1 FLAG DEVICE_INTEGRITY_COMPROMISED
4 flagged UID(s)
a13d8f91b2c4d6e8f0a92c1e7d4b5f6a8c9d0e1f2a3b4c5d6e7f8a9b0c1d2 critical BANNED 3 PENDING
3 flag(s) 2026-08-12 09:41:02 – 2026-08-13 02:17:11
Reasons
DEVICE_INTEGRITY_COMPROMISED —2 critical DEVICE_BOOT_LOADER_INTEGRITY_FAILED —1 high
Latest Signals
integrity
Compromised
verified_boot
NotTrusted
bootloader_locked
False
os_patch_level
2026-03
cc04aab1c2d3e4f5a6b7f190c2e3d4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1 high REVIEWED
1 flag(s) 2026-08-12 11:22:48
Reasons
DEVICE_BOOT_INTEGRITY_FAILED —1 high
Latest Signals
integrity
Valid
verified_boot
Trusted
bootloader_locked
True
os_patch_level
2026-05

Project Members

Manage who can access this application.
demo@example.studio
Owner
security@example.studio
Project Name
Studio Title
Project Ownership
alex@kubian.app Owner
App ID
kbn_demo_4f2a91c8e5d7b3091c6a4d8f
App Secret
•••••••••••••••••••••••••••••••••

App Certificate

The certificate pins the verified client to this project. The Application SHA-256 and package identifier below are checked against the attestation token on every verification.
Application SHA256
--
Application Package
--
Upload the release APK once to compute its certificate. This can only be done a single time.
Upload APK to compute certificate

Delete this application permanently

This will immediately purge all associated data: project keys, IDs, logs, metadata, registered players, ban records and members. This action cannot be recovered.

Illustrative, interactive preview — click the sidebar to explore. It does not show live statistics from any real game, and no button creates, changes, or deletes anything on the real dashboard. It exists purely so developers can see what the dashboard looks like.

Every section, explained

The dashboard is where your team watches, reviews, and controls what happens on protected devices. Each sidebar item maps to one part of that workflow, in the same order you use it.

Overview

Your operational snapshot. Live counts of players validated, offenders flagged, pending reviews, and active bans, plus a 24-hour API request chart and the recent offender feed. This is where you start each day.

API Settings

Your integrity policy. Every realtime check — Frida, injection, root (hard), root (soft), debugger, anti-debug — has its own switch and its own Alert / Kick / Ban actions. Device, hardware, and application checks are configured here too. Changes are cached for one hour before they take effect.

Players

Every registered player on the project. Search a player UID to see when the device registered and its verification history.

Offenders

The audit log. Every detection is recorded with the check that fired, the timestamp, the device, and the action that was taken — so your team can review and escalate.

Members

Team access control. Invite and remove teammates with Owner, Admin, or Member roles, and decide who can manage the project.

Details

Project settings: the display name, ownership, and the App ID and App Secret your SDK uses to authenticate requests to the verification backend.

Certificates

Pins your release APK to the project. Upload once to lock the Application SHA-256 and package name that attestation must match. This can only be done a single time.

Delete

The destructive action. Permanently purges the project, its keys, bans, players, logs, and members. There is no recovery.

How Kubian protects sessions

Attestation, runtime monitoring, and studio-controlled enforcement. Read how the pieces work on the security page.

Attestation flow

On session start, the client requests a fresh challenge from Kubian. The device's hardware-backed key store signs an attestation certificate proving platform integrity. The backend cryptographically verifies the certificate chain and signature.

Runtime protection

A native protection loop continuously monitors the running process and system — root and hidden root, Frida, hooking and injection frameworks, debuggers, and SELinux enforcement state. Detections are reported to the backend in realtime and resolved against the studio's per-check policy.

Studio-controlled enforcement

Every realtime detection maps to its own policy. For each check — Frida, injection, root, debugger — teams independently enable Alert, Kick, or Ban, or any combination. Bans are executed server-side on the device and enforced network-wide across all protected apps.

Want the full technical overview?

See the attestation flow, what gets verified, and the runtime protections in detail on the security page.

Low, scaling prices

Simple, predictable pricing. Per application, per month.

Kubian — Mini

$60/month

Self-managed integration for developers

  • Hardware attestation detections
  • Anti-app tamper detections
  • Developer handles backend code, API requests to Kubian, custom domain, and server infrastructure
  • Includes specific hardware attestation detections
Start an inquiry

Questions about volume or engine support? contact@staticlabs.app

Questions, answered

Hardware attestation uses security features built into the device's hardware (TEE / StrongBox) to prove the device is in a known, unmodified state. Kubian verifies these certificates to confirm boot state, bootloader lock, and platform integrity before a protected session is trusted.
Android phones and Android-based VR headsets such as Meta Quest, with Unity (LTS) integration. Custom engine support is not available yet.
Pricing is per application, per month. Kubian Mini is $60/month for a self-managed integration, and Kubian Max is $80/month for a fully managed integration with realtime protections. Low and scaling prices as your needs grow.
No. Kubian provides the attestation and runtime protections, and the developer portal handles review, moderation, analytics, and enforcement — so studios can enforce fair play without running an internal anti-cheat operation.
Yes. Enforcement is studio-controlled per detection. For each realtime check — Frida, injection, root, debugger — teams independently enable Alert (log for review), Kick, or Ban, or any combination. Bans are permanent, executed server-side on the device, and enforced network-wide across all protected apps.
Yes. Direct integration support is part of every plan, and teams can reach us at support@staticlabs.app or through the Kubian community on Discord.
Flagged sessions move into the review queue in the developer portal. Your team decides the next step with full context — review, kick, timeout, or ban.

Start a studio inquiry

Talk to us about integrating Kubian into your project. We work with studios of all sizes — low, scaling prices.