Kubian  ·  Enterprise Android Integrity

Enterprise-grade hardware integrity.
Low, scaling prices.

Anticheat & integrity for Android · phones + VR headsets

Kubian is an enterprise-grade hardware integrity and anticheat service for Android. Detect tampering, stop rooted devices, validate hardware integrity, and enforce studio-defined rules from one operational panel — without building an internal anti-cheat team.

Start a studio inquiry → Review the protection layers
● Service available Android · Available Meta Quest · Available Built for Unity (LTS) — more engines coming soon
scroll ↓

Platform

PlatformAndroid (phones + VR)
MonitoringContinuous
EnforcementStudio controlled
EnginesUnity (LTS)
Service statusAvailable

Independent signals. One security decision.

Selected public capabilities. A complete inventory of safeguards remains intentionally undisclosed.

Hardware integrity

Hardware-backed (TEE / StrongBox) integrity certificates validate boot state, bootloader lock, OS patch level, and platform integrity at the system level.

Root & hidden root detection Kubian Max

Rooted environments — including hidden and stealth root (Magisk, KernelSU) — are detected before they can enter a protected session.

Realtime injection prevention Kubian Max

Frida, hooking and injection frameworks are detected and blocked in realtime, along with app debugging.

App integrity validation

Package name, certificate digest and runtime state are validated throughout the session — not only at launch.

Detection routing

Security events move into review, moderation, analytics, and studio-defined enforcement workflows.

Session enforcement

Verified trust signals stay active through the session, so teams can respond with context.

These are selected public capabilities, not a complete inventory. Additional safeguards remain intentionally undisclosed to keep the suite effective.

A practical SDK workflow for game teams

Unity (LTS)Native AndroidlibKubianIntegrityCore.solibKubianIntegrity.solibKubianIntegrityCertificate.so
  • Guided SDK setup Add Kubian to your project with direct help from our team.
  • No rewrite required Fits your existing pipeline without forcing a rewrite.
  • Managed verification backend Signature checks, replay protection, and device bans handled for you.
  • Direct integration support Unity (LTS) projects supported with hands-on help. Custom engine support is not available yet.

Verification backend

Challenge-response integrity with hardware-backed keys. Every challenge is unique and single-use, so integrity responses cannot be replayed. Backend ownership is up to you — self-managed or fully managed by Kubian.

See what happened. Decide what happens next.

99.99%
API uptime
<1ms
Server response time
Measured backend processing time via the x-response-time header on a live verification request: 0.72ms on a fresh TLS 1.3 connection, 0.63ms on a reused HTTP/2 connection (Sep 2026).
PS-256
Signatures
PS-256 (RSASSA-PSS with SHA-256) is a digital signature algorithm — every integrity verdict is PS-256 signed, so responses cannot be forged or tampered with. Verification runs in native C through pyca/cryptography on OpenSSL 3.x.
Kubian
by Static Labs LLC
Integrity operational Kubian — Max Example Studio — VR Title
Integrity Docs demo@example.studio D
Operational Overview
Lifetime Players Validated
1,284
Last 24H Players Validated
96
Resets 12am UTC
Offenders Flagged
23
Pending Reviews
4
Active Bans
6
Trusted Now (30m)
412
API Requests — Last 24 Hours
00:00 · 20 req 01:00 · 12 req 02:00 · 8 req 03:00 · 6 req 04:00 · 9 req 05:00 · 18 req 06:00 · 32 req 07:00 · 48 req 08:00 · 62 req 09:00 · 71 req 10:00 · 58 req 11:00 · 46 req 12:00 · 55 req 13:00 · 63 req 14:00 · 72 req 15:00 · 80 req 16:00 · 95 req 17:00 · 88 req 18:00 · 76 req 19:00 · 68 req 20:00 · 74 req 21:00 · 69 req 22:00 · 58 req 23:00 · 44 req
00:0006:0012:0018:00Now
Recent Activity
a13d8f91b2c4d6e8 verification_failed
DEVICE_INTEGRITY_STANDARD_UNMET
2026-08-13T02:17:10.883019
91e7c3d4e5f6a7b8 verify_success
DEVICE_PASS
2026-08-12T23:44:02.105633
Critical Flags
DEVICE_INTEGRITY_STANDARD_UNMET
a13d8f91b2c4d6e8f0a92c1e7d4b5f6a8c9d0e1f2a3b4c5d6e7f8a9b0c1d2
high PENDING
2026-08-13T02:17:10
Signed in as demo@example.studio for Example Studio — VR Title. Select a section from the sidebar to get started. Auto-refreshes every 10s · Last refreshed 05:22:37
Realtime Protection Max
On-device checks the Kubian library performs while the app is running. The configuration is cryptographically signed by Kubian and recalculated every 30s asynchronously, so the library rejects any tampered response and falls back to full protection.
▶
Frida Detection
Detect the Frida instrumentation framework (maps, files and default ports).
Injection Detection
Detect Xposed, Zygisk, LSPosed, Substrate, ShadowHook, Dobby and other runtime hooks.
Root (Hard)
Strong root signals: su binaries, uid 0, Magisk/KernelSU mounts and hidden root modules.
Root (Soft)
Weak root signals: SELinux permissive, test-keys builds and insecure/debuggable properties.
Debugger Detection
Detect an attached debugger through TracerPid.
Anti-Debug Trap
Arm the ptrace/seccomp trap that blocks debugger attachment.
Device
Boot integrity, OS version and device trust checks
▶
Device Integrity
Fail when Kubian Integrity reports the device integrity as "Compromised".
Trusted Boot State
Fail when the computed device integrity state is not "tee_integrity", "strong_integrity", or an allowed simple state.
Security Level
Set the minimum hardware security level this project accepts. "Basic and above" allows TEE-backed devices (Basic or Advanced), "Advanced only" requires StrongBox-backed devices. "Allow any" disables the check (Please ensure to research the devices you are targetting).
Allow Simple Integrity
Allow devices whose Widevine security level did not reach L1 ("simple_tee_integrity" / "simple_integrity"). Off by default.
Verified Boot
Require VerifiedBoot to be "Trusted".
Bootloader Lock
Require BootloaderLocked to be "True".
OS Version / Security Patch
Fail when the OS patch level is below the minimum. Google issued devices require 202607 and above; Meta issued devices require 202606 and above. Disable to skip OS version checks.
Google Issued Devices
Allow devices attested by Google hardware attestation (Android devices).
Meta Issued Devices
Allow devices attested by Meta hardware attestation (Quest VR headsets).
Attested Serial Revocation
Fail when the attested hardware serial number is on the revocation list (CRL).
Application
App binary and package checks
▶
Application SHA-256
Require the app binary digest to match the registered SHA-256.
Application Package
Require the app package to be recognized and match the registered identifier.
601046ec7dfe70e9
Registered 2026-05-18T11:40:12.004113
TRUSTED VALID
a13d8f91b2c4d6e8f0a92c1e7d4b5f6a8c9d0e1f2a3b4c5d6e7f8a9b0c1d2
Registered 2026-03-28T14:09:33.112087
BANNED 3 FLAGS
cc04aab1c2d3e4f5a6b7f190c2e3d4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1
Registered 2026-06-02T09:15:41.882341
1 FLAG DEVICE_INTEGRITY_STANDARDS_UNMET
4 flagged UID(s)
a13d8f91b2c4d6e8f0a92c1e7d4b5f6a8c9d0e1f2a3b4c5d6e7f8a9b0c1d2 critical BANNED 3 PENDING
3 flag(s) 2026-08-12 09:41:02 – 2026-08-13 02:17:11
▸
Reasons
DEVICE_INTEGRITY_STANDARDS_UNMET —2 critical DEVICE_INTEGRITY_STANDARD_UNMET —1 high
Latest Signals
integrity
Compromised
requested_device
Google Issued Device
verified_boot
NotTrusted
bootloader_locked
False
os_patch_level
2026-03
attested_serial_number
a1b2c3d4e5f6...
attested_serial_revoked
True
cc04aab1c2d3e4f5a6b7f190c2e3d4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1 high REVIEWED
1 flag(s) 2026-08-12 11:22:48
▸
Reasons
DEVICE_INTEGRITY_STANDARD_UNMET —1 high
Latest Signals
integrity
Valid
requested_device
Meta Issued Device
verified_boot
Trusted
bootloader_locked
True
os_patch_level
2026-05
attested_serial_number
cc04aab1c2d3e4f5a6b7f190c2e3d4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1
attested_serial_revoked
False

Project Members

Manage who can access this application.
demo@example.studio
Owner
security@example.studio
Project Name
Studio Title
Project Ownership
alex@kubian.app Owner
App ID
kbn_demo_4f2a91c8e5d7b3091c6a4d8f
App Secret
•••••••••••••••••••••••••••••••••

App Certificate

The certificate pins the verified client to this project. The Application SHA-256 and package identifier below are checked against the integrity token on every verification.
Application SHA256
--
Application Package
--
Upload the release APK once to compute its certificate. This can only be done a single time.
Upload APK to compute certificate

Delete this application permanently

This will immediately purge all associated data: project keys, IDs, logs, metadata, registered players, ban records and members. This action cannot be recovered.

Illustrative, interactive preview — click the sidebar to explore. It does not show live statistics from any real game, and no button creates, changes, or deletes anything on the real dashboard. It exists purely so developers can see what the dashboard looks like.

Every section, explained

The dashboard is where your team watches, reviews, and controls what happens on protected devices. Each sidebar item maps to one part of that workflow, in the same order you use it.

Overview

Your operational snapshot. Live counts of players validated, offenders flagged, pending reviews, and active bans, plus a 24-hour API request chart and the recent offender feed. This is where you start each day.

API Settings

Your integrity policy. Every realtime check — Frida, injection, root (hard), root (soft), debugger, anti-debug — has its own switch and its own Alert / Kick / Ban actions. Device, issuer, and application checks are configured here too. API settings are recalculated every 30s asynchronously to avoid double-request edge cases, and your saved settings are still served out extremely fast.

Players

Every registered player on the project. Search a player UID to see when the device registered and its verification history.

Offenders

The audit log. Every detection is recorded with the check that fired, the timestamp, the device, and the action that was taken — so your team can review and escalate.

Members

Team access control. Invite and remove teammates with Owner, Admin, or Member roles, and decide who can manage the project.

Details

Project settings: the display name, ownership, and the App ID and App Secret your SDK uses to authenticate requests to the verification backend.

Certificates

Pins your release APK to the project. Upload once to lock the Application SHA-256 and package name that integrity must match. This can only be done a single time.

Delete

The destructive action. Permanently purges the project, its keys, bans, players, logs, and members. There is no recovery.

How Kubian protects sessions

Integrity, runtime monitoring, and studio-controlled enforcement. Read how the pieces work on the security page.

Integrity flow

On session start, libKubianIntegrity.so fetches a single-use challenge, signs it with a fresh hardware-backed KeyStore key (StrongBox-first, TEE fallback), and trades the attestation chain — Build fingerprint, Android ID, Widevine ID — for an integrity token. The backend cryptographically verifies the certificate chain and signature.

Runtime protection

libKubianIntegrityCore.so runs a native protection loop (2s sweep) inside the process — debugger attach via TracerPid, Frida (memory maps, ports 27042–27043, anon-exec pages), Zygisk / Riru / LSPosed / Magisk / KernelSU injection, su paths, test-keys builds, SELinux enforce state, and its own .text anti-tamper hash. Detections are reported to the backend in realtime and resolved against the studio's per-check policy — Alert, Kick, or Ban.

Studio-controlled enforcement

Every realtime detection maps to its own policy. For each check — Frida, injection, root, debugger — teams independently enable Alert, Kick, or Ban, or any combination. Bans are executed server-side on the device and enforced network-wide across all protected apps.

Want the full technical overview?

See the integrity flow, what gets verified, and the runtime protections in detail on the security page.

Battle tested, not lab tested.

Kubian doesn't sit in a demo — it runs inside large, live game environments with real players and real cheaters, where every release is probed for weaknesses from day one.

See how Kubian earns trust

Threat catalog, patch cycle, and the immunity network — in full detail on the Battle Tested page.

Two years in. Built different, priced different.

Kubian Integrity and Kubian Integrity AC have been in development for almost two years — studied, created, and built by a small team with one goal: give small developers large-scale protection.

Read the full development story

Two years of R&D, the indie mission, Enterprise, and the Kubian Network Authority — in full on the Development page.

How Kubian sustains large games at low prices

Traditional anti-cheat is expensive because it is manual: sales teams, per-seat contracts, and human review queues. Kubian replaces all three with automation. Verification runs in under a millisecond on commodity servers — attestation parsing cached per certificate, telemetry fire-and-forget, bans enforced by code instead of people. One automated backend serves every studio, so the cost per game falls as the network grows instead of rising with headcount. Flat per-app pricing works because the marginal cost of protecting your game is near zero — and we pass that on instead of pocketing it.

Low, scaling prices

Simple, predictable pricing. Per application, per month.

Kubian — Mini

$60/month

Self-managed integration for developers

  • Hardware integrity detections
  • Anti-app tamper detections
  • Developer handles backend code, API requests to Kubian, custom domain, and server infrastructure
  • Includes specific hardware integrity detections
Start an inquiry

Questions about volume or engine support? contact@staticlabs.app

Questions, answered

Hardware integrity uses security features built into the device's hardware (TEE / StrongBox) to prove the device is in a known, unmodified state. Kubian verifies these certificates to confirm boot state, bootloader lock, and platform integrity before a protected session is trusted.
Android phones and Android-based VR headsets such as Meta Quest, with Unity (LTS) integration. Custom engine support is not available yet.
Pricing is per application, per month. Kubian Mini is $60/month for a self-managed integration, and Kubian Max is $80/month for a fully managed integration with realtime protections. Low and scaling prices as your needs grow.
No. Kubian provides the integrity and runtime protections, and the developer portal handles review, moderation, analytics, and enforcement — so studios can enforce fair play without running an internal anti-cheat operation.
Yes. Enforcement is studio-controlled per detection. For each realtime check — Frida, injection, root, debugger — teams independently enable Alert (log for review), Kick, or Ban, or any combination. Bans are permanent, executed server-side on the device, and enforced network-wide across all protected apps.
Yes. Direct integration support is part of every plan, and teams can reach us at support@staticlabs.app or through the Kubian community on Discord.
Flagged sessions move into the review queue in the developer portal. Your team decides the next step with full context — review, kick, timeout, or ban.

Start a studio inquiry

Talk to us about integrating Kubian into your project. We work with studios of all sizes — low, scaling prices.