Anticheat & integrity for Android · phones + VR headsets
Kubian is an enterprise-grade hardware integrity and anticheat service for Android. Detect tampering, stop rooted devices, validate hardware integrity, and enforce studio-defined rules from one operational panel — without building an internal anti-cheat team.
Selected public capabilities. A complete inventory of safeguards remains intentionally undisclosed.
Hardware-backed (TEE / StrongBox) integrity certificates validate boot state, bootloader lock, OS patch level, and platform integrity at the system level.
Rooted environments — including hidden and stealth root (Magisk, KernelSU) — are detected before they can enter a protected session.
Frida, hooking and injection frameworks are detected and blocked in realtime, along with app debugging.
Package name, certificate digest and runtime state are validated throughout the session — not only at launch.
Security events move into review, moderation, analytics, and studio-defined enforcement workflows.
Verified trust signals stay active through the session, so teams can respond with context.
These are selected public capabilities, not a complete inventory. Additional safeguards remain intentionally undisclosed to keep the suite effective.
Challenge-response integrity with hardware-backed keys. Every challenge is unique and single-use, so integrity responses cannot be replayed. Backend ownership is up to you — self-managed or fully managed by Kubian.
This will immediately purge all associated data: project keys, IDs, logs, metadata, registered players, ban records and members. This action cannot be recovered.
Illustrative, interactive preview — click the sidebar to explore. It does not show live statistics from any real game, and no button creates, changes, or deletes anything on the real dashboard. It exists purely so developers can see what the dashboard looks like.
The dashboard is where your team watches, reviews, and controls what happens on protected devices. Each sidebar item maps to one part of that workflow, in the same order you use it.
Your operational snapshot. Live counts of players validated, offenders flagged, pending reviews, and active bans, plus a 24-hour API request chart and the recent offender feed. This is where you start each day.
Your integrity policy. Every realtime check — Frida, injection, root (hard), root (soft), debugger, anti-debug — has its own switch and its own Alert / Kick / Ban actions. Device, issuer, and application checks are configured here too. API settings are recalculated every 30s asynchronously to avoid double-request edge cases, and your saved settings are still served out extremely fast.
Every registered player on the project. Search a player UID to see when the device registered and its verification history.
The audit log. Every detection is recorded with the check that fired, the timestamp, the device, and the action that was taken — so your team can review and escalate.
Team access control. Invite and remove teammates with Owner, Admin, or Member roles, and decide who can manage the project.
Project settings: the display name, ownership, and the App ID and App Secret your SDK uses to authenticate requests to the verification backend.
Pins your release APK to the project. Upload once to lock the Application SHA-256 and package name that integrity must match. This can only be done a single time.
The destructive action. Permanently purges the project, its keys, bans, players, logs, and members. There is no recovery.
Integrity, runtime monitoring, and studio-controlled enforcement. Read how the pieces work on the security page.
On session start, libKubianIntegrity.so fetches a single-use challenge, signs it with a fresh hardware-backed KeyStore key (StrongBox-first, TEE fallback), and trades the attestation chain — Build fingerprint, Android ID, Widevine ID — for an integrity token. The backend cryptographically verifies the certificate chain and signature.
libKubianIntegrityCore.so runs a native protection loop (2s sweep) inside the process — debugger attach via TracerPid, Frida (memory maps, ports 27042–27043, anon-exec pages), Zygisk / Riru / LSPosed / Magisk / KernelSU injection, su paths, test-keys builds, SELinux enforce state, and its own .text anti-tamper hash. Detections are reported to the backend in realtime and resolved against the studio's per-check policy — Alert, Kick, or Ban.
Every realtime detection maps to its own policy. For each check — Frida, injection, root, debugger — teams independently enable Alert, Kick, or Ban, or any combination. Bans are executed server-side on the device and enforced network-wide across all protected apps.
See the integrity flow, what gets verified, and the runtime protections in detail on the security page.
Kubian doesn't sit in a demo — it runs inside large, live game environments with real players and real cheaters, where every release is probed for weaknesses from day one.
Threat catalog, patch cycle, and the immunity network — in full detail on the Battle Tested page.
Kubian Integrity and Kubian Integrity AC have been in development for almost two years — studied, created, and built by a small team with one goal: give small developers large-scale protection.
Two years of R&D, the indie mission, Enterprise, and the Kubian Network Authority — in full on the Development page.
Traditional anti-cheat is expensive because it is manual: sales teams, per-seat contracts, and human review queues. Kubian replaces all three with automation. Verification runs in under a millisecond on commodity servers — attestation parsing cached per certificate, telemetry fire-and-forget, bans enforced by code instead of people. One automated backend serves every studio, so the cost per game falls as the network grows instead of rising with headcount. Flat per-app pricing works because the marginal cost of protecting your game is near zero — and we pass that on instead of pocketing it.
Simple, predictable pricing. Per application, per month.
$60/month
Self-managed integration for developers
$80/month
Fully-managed integration
Questions about volume or engine support? contact@staticlabs.app
Talk to us about integrating Kubian into your project. We work with studios of all sizes — low, scaling prices.