Guardian Mobile SDK

Consumer-grade protection,
inside your own app

Guardian ships as a drop-in Android & iOS SDK. Nine on-device protection modules, one safety score, and a UI layer your subscribers actually understand — all white-labelled to your brand.

9Protection modules
< 4 MBBinary footprint
On-deviceSignal processing
Android + iOSNative SDKs

Watch each module work

Nine demo reels recorded from the Guardian reference build. Each one runs the real flow — a typosquat getting blocked, a scam call being labelled, a geofence firing — and loops.

Demo
14:54

Hi, Jason

Here's how you're protected today.
81/100Safety score
▲ 12 since last check ›
Last check you were at 81.
How to improve
Device trust
Good

Your device is verified and up to date.

Apps & permissions
Good

No risky app permissions detected.

Wi-Fi security
Good

BT-T5F97X — Low risk.

Home
Protection
Identity
Settings
0:00/0:07

Module 01 · Home

One number your subscribers understand

Guardian collapses every protection signal on the handset into a single 0–100 safety score, with a delta against the previous check so users can see the effect of acting on advice. Underneath it, each contributing module reports its own plain-English status — no jargon, no CVE numbers, no dead ends.

What the module exposes
  • Composite score — 0–100, weighted across all enabled modules
  • Delta since last check — signed change plus the previous value
  • Per-module status — Good / Attention / At risk, each with a one-line reason
  • Remediation queue — ordered, tappable actions behind "How to improve"
score.observe()score.deltascore.breakdown[]
Demo
14:47

Hi, Jason

Here's how you're protected today.
93/100Safety score
▲ 12 since last check ›
Last check you were at 81.
How to improve
Safe browsing
Good

Safe browsing is on — 0 unsafe requests blocked today.

Calls
Good

No scam calls today.

SIM & carrier
Good
Home
Protection
Identity
Settings
0:00/0:07

Module 02 · Protection tab

Network and telephony threats in one view

The Protection tab groups the modules that defend the connection itself — DNS filtering, scam-call screening and SIM integrity. Each card is a live status with today's counts, and taps through to a detail screen with the underlying event log.

What the module exposes
  • Safe browsing status — on/off plus unsafe requests blocked today
  • Call screening status — scam calls flagged in the current period
  • SIM integrity status — swap detection state
  • Drill-down events — timestamped log per module for support and dispute handling
protection.summary()protection.events()
Demo
14:52

Safe browsing

DNS-level phishing
protection
285Blocked today
1116Requests today
Refresh
Blocked today
whtaspp-group.pages.dev
2 Sep, 14:51
Blocked
fxjn-web-whatsapp.hk.cn
2 Sep, 14:50
Blocked
malicious.com
2 Sep, 12:31
Blocked
0:00/0:08

Module 03 · Safe browsing

Malicious DNS detection

Guardian resolves DNS through a filtering layer that scores every lookup against live phishing, malware and command-and-control intelligence. Lookalike domains — the whtaspp-group and fxjn-web-whatsapp class of typosquats — are blocked before the handset ever opens a connection. The user sees a plain list of what was stopped and when, which is what turns a silent security control into something they'll pay for.

What the module exposes
  • Blocked / total counts — per day, per device, with on-demand refresh
  • Blocked-domain log — domain, timestamp, verdict and threat category
  • Live verdicts — subscribe to block events as they happen
  • Allow-list control — user or operator override for false positives
safeBrowsing.stats()safeBrowsing.blocked()safeBrowsing.allow(domain)
Demo
15:05
07813996004Incoming call · unknown number
Checking…
How was that… • now
07813996004
SpamScamOK
✓ Reported — thanks, that helps everyone
93/100Safety score
▲ 12 since last check ›
Last check you were at 81.
How to improve
Safe browsing
Good

Safe browsing is on — 288 unsafe requests blocked today.

0:00/0:09

Module 04 · Call screening

Scam call warnings, rated by the user

Guardian screens inbound numbers against reputation intelligence and warns before the user engages. Immediately after the call ends, a heads-up prompt asks how it went — Spam, Scam or OK. That one tap is the feedback loop: it feeds a crowd-sourced reputation graph that sharpens detection for every other subscriber on your network.

What the module exposes
  • Pre-answer verdict — reputation score and category for the calling number
  • Post-call prompt — Spam / Scam / OK, returned as a user report
  • Daily scam count — feeds the Calls card on the Protection tab
  • Network learning — reports aggregate into shared reputation intelligence
calls.verdict(msisdn)calls.report(verdict)calls.today()
Demo
15:09

SIM & carrier

Checking SIM status…

Reading phone state.

DETAILS
CarrierEE
SIM slotsSingle SIM
Previous changeNone on record
0:00/0:06

Module 05 · SIM integrity

SIM-swap detection at the device layer

SIM swap is the pivot for most account-takeover fraud: move the number, intercept the OTP, drain the account. Guardian watches phone-state on the handset and records carrier, slot configuration and any change event — so a swap is detected from the victim's own device, independently of the network-side signal, and can be surfaced to your fraud team in real time.

What the module exposes
  • Change verdict — whether a SIM change has been detected
  • Carrier and slot state — current operator, single vs dual SIM
  • Change history — timestamp of the previous change, or none on record
  • Out-of-band alerting — routed to the recovery email, not just an on-device toast
sim.state()sim.onChange()sim.history()
Demo
15:11

Apps & permissions

We scan installed apps for permissions fraudsters commonly abuse. Tap a card to see which apps hold it.

MicrophoneHigh
Can turn on your microphone.
1 app · 1 to review
Phone stateMedium
Can read your phone number and call state.
1 app · all accepted
ContactsMedium
Can read your contacts list.
1 app · 1 to review
Post notificationsLow
Can post notifications to your device.
1 app · all accepted
Scan again
0:00/0:08

Module 06 · Apps & permissions

Permission risk, ranked by how fraud actually works

Rather than dumping the full Android permission table on the user, Guardian scans installed apps for the specific grants fraudsters abuse and ranks them High / Medium / Low. Each card explains the capability in one sentence — "can turn on your microphone" — and tapping it reveals exactly which apps hold that grant, with a review-or-accept decision the user can actually make.

What the module exposes
  • Risk-ranked permission set — High / Medium / Low against a fraud-abuse model
  • Holder attribution — which installed apps hold each grant
  • Review state — per-permission accepted vs still to review
  • On-demand rescan — user-triggered, results feed the safety score
permissions.scan()permissions.holders(p)permissions.accept(p)
Demo
14:55

Location safety zones

Pos Penitipan Paket Balaikota Google
📍
1 zone configured1 active
Zones+ Add
📍
Jakarta Town Hall200m radius
Active
Recent activity
No recent events
Entered Jakarta Town Hall2 Sep, 14:58
0:00/0:08

Module 07 · Location safety zones

Geofences the user sets themselves

Users define named zones with a radius — home, school, a parent's address — and Guardian reports arrival and departure against them. It's the consumer-friendly half of location intelligence: the same signal that flags impossible travel for your fraud engine is presented here as reassurance rather than surveillance, with the user in control of every zone.

What the module exposes
  • Zone CRUD — create, activate, delete named zones with a metre radius
  • Enter / exit events — timestamped, per zone
  • Impossible-travel signal — feeds the Identity tab's Location status
  • Configured / active counts — summary for the zone list header
zones.add(name, latLng, r)zones.events()zones.list()
Demo
14:54

Hi, Jason

Here's how you're protected today.
93/100Safety score
▲ 12 since last check ›
Last check you were at 81.
How to improve
Location
Checking…

Comparing against travel history.

Identity monitoring
Checking…

Querying breach corpora.

Home
Protection
Identity
Settings
0:00/0:07

Module 08 · Identity

Breach exposure and travel anomalies

The Identity tab pairs two long-running checks: continuous breach monitoring for the identifiers the user has registered, and behavioural location analysis that flags travel patterns inconsistent with the device's history. Both report as plain status lines — "no breaches found", "no unusual travel detected" — and both escalate out-of-band when they don't.

What the module exposes
  • Monitored identity count — registered emails and numbers under watch
  • Breach findings — source, date and exposed field classes
  • Travel anomaly verdict — impossible-travel and velocity checks
  • Escalation hooks — webhook to your fraud platform on any positive finding
identity.monitor(email)identity.breaches()location.anomalies()
Demo
14:55

Settings

PROTECTION
Safe browsingDNS-level phishing protection.
Scam call warningsNo scam calls today.
SIM & carrierPhone-state access on — checking for SIM swaps.

Your protection runs out on 31 Oct 2026

RECOVERY EMAIL

If this phone is stolen, a notification shown on it won't help. We'll email this address instead when we detect a location or SIM-card change.

Recovery email address
Send code
LANGUAGE
Home
Protection
Identity
Settings
0:00/0:09

Module 09 · Consent & settings

Every module is opt-in, and says why

Each protection module has its own toggle and its own justification — "phone-state access on — checking for SIM swaps" — so consent is informed and revocable at module granularity. The recovery email is the deliberate design choice worth noting: a stolen handset can't be warned on its own screen, so location and SIM-change alerts go out-of-band to a verified address instead.

What the module exposes
  • Per-module consent — independent toggles with rationale strings you can localise
  • Entitlement expiry — subscription end date surfaced in-app
  • Verified recovery channel — email with code verification for out-of-band alerts
  • Localisation — all strings externalised, RTL supported
consent.set(module, on)recovery.verify(email)entitlement.expiry

What ships in the box

Nine modules, one score, one consent model. Enable the subset your market and regulator allow.

Malicious DNS detection

Phishing, malware and C2 domains blocked at resolution, with a user-visible block log.

Scam call screening

Reputation verdicts before answer, plus a one-tap post-call Spam / Scam / OK report.

SIM-swap detection

Device-side carrier and slot monitoring, with out-of-band alerting on change.

Permission risk scanning

Installed-app grants ranked by fraud-abuse likelihood, with holder attribution.

Location safety zones

User-defined geofences with enter/exit events and impossible-travel analysis.

Identity monitoring

Continuous breach exposure checks against registered emails and numbers.

Device trust

Root, emulator, patch-level and integrity attestation feeding the composite score.

Wi-Fi security

SSID risk scoring for open, captive and known-hostile networks.

Composite safety score

One 0–100 number, a delta, and a ranked remediation queue behind it.

Wired in under a day

Initialise once, subscribe to the signals you care about, and either drop in the reference UI or bind the data to your own components.

GuardianSetup.kt
// 1 — initialise once, in Application.onCreate()
Guardian.init(
    context  = this,
    apiKey   = BuildConfig.GUARDIAN_KEY,
    modules  = setOf(SAFE_BROWSING, CALLS, SIM, PERMISSIONS, ZONES, IDENTITY),
    branding = Branding(accent = "#3BB586", logo = R.drawable.operator_mark)
)

// 2 — the composite score, and everything behind it
Guardian.score.observe(lifecycleOwner) { s ->
    scoreRing.bind(s.value, s.delta)        // 93, +12
    moduleList.submit(s.breakdown)          // per-module status + reason
}

// 3 — react to a live DNS block
Guardian.safeBrowsing.onBlock { event ->
    log("blocked " + event.domain + " · " + event.category)
}

// 4 — or skip the UI entirely and forward signals to your fraud platform
Guardian.webhook(url = "https://fraud.operator.net/guardian", events = ALL)

Put Guardian in your app

Get SDK access, the Figma reference kit, and a sandbox tenant with synthetic threat traffic.