Elyzium Security
Keeps secrets embedded in Android apps out of plain sight.
In development
↓ Elyzium Security (at build time)
Encrypted inside the app
↓
Decrypted only when needed, wiped after useIllustrative diagram.
The problem it solves
Many apps ship with API keys, tokens, configuration or valuable data files. Left as they are, anyone who downloads and unpacks the app can read them. Elyzium Security encrypts this information at build time, and the app decrypts it only at the moment it is actually needed, in a separate memory area isolated from the rest of the app.
Who it is for
Android developers whose apps contain service keys, internal passwords, configuration files or valuable assets that should not be readable when someone unpacks the app.
Use cases
- Hide API keys and service tokens.
- Protect configuration files, data or valuable assets bundled with the app.
- Check passwords or internal codes without exposing the original value.
- Detect signs that the app is being debugged or tampered with at run time.
Key features
Automatic encryption at build time
Declare the values and files to protect in your project configuration. When the app is packaged, the plugin encrypts them all, with no extra code to write.
Decrypt on demand, wipe after use
Values are decrypted in a separate native memory area and wiped once used, so the original content barely exists in the higher-level app code.
Compare without exposing
When you only need to check whether a password or token matches, or check its length, you can do so without ever taking the original value out.
Run-time tamper detection
The library recognises several signs that the app is being debugged, hooked or modified, giving you an extra layer of warning.
No server required
Everything runs on the user's device, with no network connection or extra infrastructure.
Ready for modern Android
Supports multiple CPU architectures and recent Android memory requirements.
How it is deployed
Declare
List the values and files to protect in your project configuration.
Build
The plugin encrypts them and generates reference code for you to call.
Package
The encrypted data ships inside the app together with the library.
Use in your app
Call the library when you need a value; it decrypts, returns and wipes it.
Technical details
| Stage | In development |
|---|---|
| Platform | Android |
| Components | Gradle plugin (build time) and a runtime library shipped inside the app |
| Model | Runs entirely on the user's device, no server required |
Known limitations
We state these clearly so you know what to expect:
- Because it runs entirely on the user's device, a capable attacker with enough time may still recover the information. The product significantly raises the cost of an attack but does not remove the risk.
- Tamper detection is tuned to avoid false alarms, so it does not catch every case.
Interested in Elyzium Security?
Send a request for a consultation and a quote tailored to your project.