Elyzium Security

Keeps secrets embedded in Android apps out of plain sight.

In development

The problem it solves

Many apps ship with API keys, tokens, configuration or valuable data files. Left as they are, anyone who downloads and unpacks the app can read them. Elyzium Security encrypts this information at build time, and the app decrypts it only at the moment it is actually needed, in a separate memory area isolated from the rest of the app.

Who it is for

Android developers whose apps contain service keys, internal passwords, configuration files or valuable assets that should not be readable when someone unpacks the app.

Use cases

  • Hide API keys and service tokens.
  • Protect configuration files, data or valuable assets bundled with the app.
  • Check passwords or internal codes without exposing the original value.
  • Detect signs that the app is being debugged or tampered with at run time.

Key features

Automatic encryption at build time

Declare the values and files to protect in your project configuration. When the app is packaged, the plugin encrypts them all, with no extra code to write.

Decrypt on demand, wipe after use

Values are decrypted in a separate native memory area and wiped once used, so the original content barely exists in the higher-level app code.

Compare without exposing

When you only need to check whether a password or token matches, or check its length, you can do so without ever taking the original value out.

Run-time tamper detection

The library recognises several signs that the app is being debugged, hooked or modified, giving you an extra layer of warning.

No server required

Everything runs on the user's device, with no network connection or extra infrastructure.

Ready for modern Android

Supports multiple CPU architectures and recent Android memory requirements.

How it is deployed

  1. Declare

    List the values and files to protect in your project configuration.

  2. Build

    The plugin encrypts them and generates reference code for you to call.

  3. Package

    The encrypted data ships inside the app together with the library.

  4. Use in your app

    Call the library when you need a value; it decrypts, returns and wipes it.

Technical details

StageIn development
PlatformAndroid
ComponentsGradle plugin (build time) and a runtime library shipped inside the app
ModelRuns entirely on the user's device, no server required

Known limitations

We state these clearly so you know what to expect:

  • Because it runs entirely on the user's device, a capable attacker with enough time may still recover the information. The product significantly raises the cost of an attack but does not remove the risk.
  • Tamper detection is tuned to avoid false alarms, so it does not catch every case.

Interested in Elyzium Security?

Send a request for a consultation and a quote tailored to your project.

Get a consultation & quote