Kubian  ·  Development

Two years in. Built different, priced different.

Kubian Integrity and Kubian Integrity AC have been in development for almost two years — studied, created, and built by a small team with one goal: give small developers large-scale protection.

Study first. Then steel.

Kubian wasn't assembled from third-party parts. It was researched from the silicon up, then built piece by piece.

Almost two years of study, then building

The work started with study: the Android security model, hardware-backed Keystore attestation and KeyMint authorization lists, Widevine DRM identity and security levels, verified boot chains — and, just as importantly, the attacker's toolkit: Frida, Magisk, KernelSU, Zygisk, Riru, LSPosed, debuggers, and reflection-based hiding.

Only after understanding both sides did the building begin. Three native libraries with plain C entry points: libKubianIntegrityCore.so (the protection loop, one-shot scans, and shared-ban and session APIs), libKubianIntegrity.so (the attestation exchange: fetch a challenge, mint a fresh hardware key bound to its nonce, StrongBox first with TEE fallback, trade the chain for an integrity token), and libKubianIntegrityCertificate.so (fetch a nonce, mint an attested key, exchange the chain for a one-time device certificate). Every call runs off the game thread under strict network time budgets. Behind them, a verification backend with native-C cryptography, a developer dashboard with per-check policy control, an offender audit pipeline, and a realtime enforcement system with Alert, Kick, and Ban actions per detection.

Small team, senior output. Every line exists because an attack demanded it — nothing in Kubian is speculative, and nothing is borrowed without understanding.

What was studied

  • Android security & attestation model
  • KeyMint authorization lists
  • Widevine identity & security levels
  • Verified boot & trust roots
  • Frida, root & hooking toolkits

What was built

  • libKubianIntegrityCore.so
  • libKubianIntegrity.so
  • libKubianIntegrityCertificate.so
  • Native-C verification backend
  • Dashboard, audit & enforcement

System anatomy, silicon to dashboard

Six layers, each doing exactly one job. Follow a single session from hardware to verdict.

One session, six layers

It starts in silicon: a hardware-backed keystore (StrongBox first, TEE fallback) mints a key bound to a single-use challenge, alongside the Widevine device identity and security level.

The three native client libraries take it from there — libKubianIntegrity.so runs the challenge exchange (fetch a single-use challenge, trade the attestation chain for an integrity token), libKubianIntegrityCertificate.so provisions the one-time device certificate (fetch a nonce, trade the chain for a device certificate), and libKubianIntegrityCore.so starts the 2-second protection sweep while polling ban state, shared ban records, and the RSA-signed protection tier. The verification backend checks the attestation chain in native C (pyca/cryptography on OpenSSL 3.x, KeyMint structures via cached pyasn1), signs the verdict with PS-256, and stores signals in pooled, indexed Postgres. Studios watch it all from the dashboard — per-check policy, offender audit, player database, live overview — while enforcement (Alert, Kick, Ban) executes across the network.

No layer trusts another blindly. Hardware proves to the server, the server directs the client, and the dashboard lets humans audit every step.

Silicon & OS

  • StrongBox / TEE keystore
  • Verified boot & trust roots
  • Widevine L1 identity

Client native

  • libKubianIntegrityCore.so
  • libKubianIntegrity.so
  • libKubianIntegrityCertificate.so

Verify backend

  • pyca/cryptography + OpenSSL 3.x
  • PS-256 signed verdicts
  • Sub-millisecond processing

Control plane

  • Dashboard per-check policy
  • Offender audit & bans
  • Cloudflare edge delivery

Two years, five phases

How a small team turned study into a shield — and what's next.

  1. Study. The Android security model, KeyMint authorization lists, Widevine identity, verified boot chains — and the full attacker toolkit, from Frida to KernelSU. Learn both sides before writing a line.
  2. Build the libs. Three hardened native libraries with plain C entry points, hidden symbols, and stack protection — attestation, certificates, and the realtime protection loop.
  3. Prove the backend. Native-C verification, PS-256 verdicts, the developer dashboard, offender audit, and Alert/Kick/Ban enforcement — the control plane studios operate.
  4. Go realtime. Tier gating, ban polling, certificate auto-refresh, and network-wide bans — hardened daily in live production environments under real attack.
  5. Scale access (in development). Now being worked on: Enterprise tier with automated billing, then the Kubian Network Authority — Kubian-handled networking with a dedicated DNS record, while you keep the code and the service.

Small developers. Large-scale protection.

Enterprise anti-cheat has always been gated behind sales calls and custom contracts. Kubian inverted that.

Security shouldn't be a luxury good

The studios getting eaten alive by cheaters are exactly the ones priced out of traditional anti-cheat — per-seat contracts, partner tiers, and procurement cycles built for someone else.

Kubian is built like protection should be accessible: guided SDK setup with direct help from the team that built the system, Unity (LTS) and Native Android support with no rewrite of your existing pipeline, and flat per-app pricing a solo developer can put on a card today. The same hardware-rooted verification, the same realtime enforcement, the same network-wide bans — whether you have ten players or ten million.

No ticket queues. No partner tiers. No "contact sales to continue." Just defenses, documentation, and direct support.

Guided, not gated

Direct integration help from the engineers behind the system — answers from people who wrote the detections, not a support script.

Flat per-app pricing

One predictable price per application per month. Your protection doesn't get more expensive because your game got more popular.

Scales with you

Start indie, grow into Enterprise without re-integrating. The same SDK carries you from first launch to largest scale.

Enterprise, without the enterprise nonsense

Automated billing and an Enterprise tier are on the way — a full, accessible, state-of-the-art solution for studios at the largest scale.

Self-serve power, not sales calls

In development

Enterprise doesn't mean a sales rep and a PDF. It means automated billing — upgrade, downgrade, and scale without talking to anyone — wrapped around the most complete Kubian offering.

Expect dedicated verification capacity for launch-day traffic spikes, deeper policy controls and audit tooling for compliance-minded teams, priority review pipelines for offender triage at volume, and hands-on support from the engineers who built the defenses. Everything the indie tiers get, plus the headroom and control that large-scale operations demand — accessible the same way everything Kubian makes is accessible.

Enterprise adds

  • Automated, self-serve billing
  • Dedicated verification capacity
  • Deeper policy & audit controls
  • Priority offender review pipelines
  • Hands-on engineering support

Enterprise keeps

  • No sales reps, no PDFs
  • No annual lock-in theater
  • Same SDK, same integration
  • Same network-wide immunity

Next: Kubian Network Authority

The roadmap goes beyond the device — from verdicts about devices to authority over the network itself.

Networking, handled — code, yours

In development

Today Kubian tells your game whether a device can be trusted. Network Authority takes the next step: Kubian handles the Networking for you. You manage the code. You manage the service.

Every project gets a dedicated DNS record under kubian.app or staticlabs.app — your own address on Kubian's network, pointing at your backend. Kubian operates everything in front of it: routed ingress, TLS termination, and the edge that already serves verification traffic today. Your players resolve you through Kubian hardened infrastructure — while your code, your deploys, your game logic, and your service stay entirely yours. No shared tenancy surprises, no reverse-proxy archaeology: one record, your service behind it, Kubian's network wrapped around it.

The endgame: stop stitching together DNS, certificates, and ingress around your game. Point your record at your code and get back to building — the network is handled.

How Kubian sustains large games at low prices

Traditional anti-cheat is expensive because it is manual: sales teams, per-seat contracts, and human review queues. Kubian replaces all three with automation — and then optimizes the automation until the cost per request nearly vanishes.

The math is simple. Our small fleet of verification nodes is engineered so that each request costs almost nothing to serve: cryptographic primitives execute in microseconds inside native C (OpenSSL 3.x with AES-NI hardware acceleration), and full request processing completes in under a millisecond — measured live at 0.72ms on a fresh TLS 1.3 connection and 0.63ms on a reused one. When one commodity server answers thousands of integrity checks per second at that cost, absorbing millions of requests is a capacity-planning exercise, not a hiring plan. The fleet grows by adding identical nodes, never by adding headcount — and as request volume climbs, the cost per game keeps falling instead of rising.

That is why flat per-app pricing works: the marginal cost of protecting your game is near zero, and we pass that on instead of pocketing it. Below is the actual optimization ledger — every entry is a real mechanism in the running system, not a roadmap promise.

Native-C cryptography

  • ECDSA & X.509 verify in OpenSSL C — microseconds, not milliseconds
  • AES-NI hardware throughput measured in gigabytes per second
  • Single-use 120-second nonces kill replays by construction

Cache everything hot

  • Attestation parses cached 1 hour per certificate
  • Dashboard overviews cached 15 seconds per project
  • Revocation list cached 24 hours, refreshed in background
  • Single-flight refresh: cold requests never pay the ~300ms upstream fetch

Never wait on writes

  • Telemetry, counters & events flush fire-and-forget
  • Responses return before the database write lands
  • Rate-limit counters observe but never gate requests

Pooled, indexed storage

  • Pooled Postgres connections — no handshake per request
  • GIN indexes over document stores, targeted indexes on hot keys
  • Ban checks collapsed from 6 round trips into 1 query
  • Schema checks gated to once per 10 minutes per process

Parallel reads

  • Overviews fan out across a worker thread pool
  • Stale caches keep serving while refreshers run
  • Signed policy pushes propagate network-wide in 30 seconds

Edge & self-watch

  • Cloudflare edge: anycast, TLS 1.3, HTTP/2 + HTTP/3
  • Clients re-poll bans every 10 seconds, refresh certs automatically
  • Any response slower than 400ms pages the team automatically
  • Zero humans in the request path — automation all the way down

Available by design

  • Identical stateless nodes — capacity added by cloning, never re-architecting
  • Pooled connections and indexed reads absorb traffic spikes without new hardware
  • Stale-serving caches ride through upstream outages and deploys
  • No maintenance windows: policy, revocation, and version gates push live

Refined automatically

  • Every detection lands in the offender audit with full signal context
  • Novel bypasses harden into permanent named detections
  • Signed policy updates reach every project without client updates
  • Compromised credentials land on the revocation list the same cycle

Cheap, available, and getting stronger on its own

Low prices, high availability, and constant patching are not three separate achievements. They are the same architecture compounding: automation removes the humans from the cost equation, identical nodes remove them from the scaling equation, and the shared audit trail removes them from the improvement equation.

A new attack arrives as telemetry, is studied once, and ships back out as a permanent detection to every protected game — no tickets, no war rooms, no client updates. Each cycle makes the next attack more expensive for the attacker while the cost per verification keeps falling for everyone else. That is how Kubian sustains large-scale protection at indie prices: the system does the work that legacy vendors staff entire teams to do, around the clock, and gets better at it every day.

Build on two years of battle-tested R&D

Start an inquiry, read the integration docs, or talk to the team directly.