Anticheat & attestation for Android · phones + VR headsets
Kubian is an enterprise-grade hardware attestation and anticheat service for Android. Detect tampering, stop rooted devices, validate hardware integrity, and enforce studio-defined rules from one operational panel — without building an internal anti-cheat team.
Selected public capabilities. A complete inventory of safeguards remains intentionally undisclosed.
Hardware-backed (TEE / StrongBox) attestation certificates validate boot state, bootloader lock, OS patch level, and platform integrity at the system level.
Rooted environments — including hidden and stealth root (Magisk, KernelSU) — are detected before they can enter a protected session.
Frida, hooking and injection frameworks are detected and blocked in realtime, along with app debugging.
Package name, certificate digest and runtime state are validated throughout the session — not only at launch.
Security events move into review, moderation, analytics, and studio-defined enforcement workflows.
Verified trust signals stay active through the session, so teams can respond with context.
These are selected public capabilities, not a complete inventory. Additional safeguards remain intentionally undisclosed to keep the suite effective.
Challenge-response attestation with hardware-backed keys. Every challenge is unique and single-use, so attestation responses cannot be replayed. Backend ownership is up to you — self-managed or fully managed by Kubian.
This will immediately purge all associated data: project keys, IDs, logs, metadata, registered players, ban records and members. This action cannot be recovered.
Illustrative, interactive preview — click the sidebar to explore. It does not show live statistics from any real game, and no button creates, changes, or deletes anything on the real dashboard. It exists purely so developers can see what the dashboard looks like.
The dashboard is where your team watches, reviews, and controls what happens on protected devices. Each sidebar item maps to one part of that workflow, in the same order you use it.
Your operational snapshot. Live counts of players validated, offenders flagged, pending reviews, and active bans, plus a 24-hour API request chart and the recent offender feed. This is where you start each day.
Your integrity policy. Every realtime check — Frida, injection, root (hard), root (soft), debugger, anti-debug — has its own switch and its own Alert / Kick / Ban actions. Device, hardware, and application checks are configured here too. Changes are cached for one hour before they take effect.
Every registered player on the project. Search a player UID to see when the device registered and its verification history.
The audit log. Every detection is recorded with the check that fired, the timestamp, the device, and the action that was taken — so your team can review and escalate.
Team access control. Invite and remove teammates with Owner, Admin, or Member roles, and decide who can manage the project.
Project settings: the display name, ownership, and the App ID and App Secret your SDK uses to authenticate requests to the verification backend.
Pins your release APK to the project. Upload once to lock the Application SHA-256 and package name that attestation must match. This can only be done a single time.
The destructive action. Permanently purges the project, its keys, bans, players, logs, and members. There is no recovery.
Attestation, runtime monitoring, and studio-controlled enforcement. Read how the pieces work on the security page.
On session start, the client requests a fresh challenge from Kubian. The device's hardware-backed key store signs an attestation certificate proving platform integrity. The backend cryptographically verifies the certificate chain and signature.
A native protection loop continuously monitors the running process and system — root and hidden root, Frida, hooking and injection frameworks, debuggers, and SELinux enforcement state. Detections are reported to the backend in realtime and resolved against the studio's per-check policy.
Every realtime detection maps to its own policy. For each check — Frida, injection, root, debugger — teams independently enable Alert, Kick, or Ban, or any combination. Bans are executed server-side on the device and enforced network-wide across all protected apps.
See the attestation flow, what gets verified, and the runtime protections in detail on the security page.
Simple, predictable pricing. Per application, per month.
$60/month
Self-managed integration for developers
$80/month
Fully-managed integration
Questions about volume or engine support? contact@staticlabs.app
Talk to us about integrating Kubian into your project. We work with studios of all sizes — low, scaling prices.