What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
- Current product names and how the portfolio is packaged: confirm against vendor site
- Cross platform framework support: confirm against vendor docs
- Integration catalog: confirm against vendor docs
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Guardsquare is best known through ProGuard, the open source Java and Kotlin shrinker and obfuscator that became part of standard Android build tooling. ProGuard removes unused code and renames classes, methods and fields to short meaningless identifiers, which shrinks the artifact and makes decompiled output harder to read. The commercial products go considerably further.
On Android, the commercial obfuscator adds name obfuscation across a wider surface, string and asset encryption, control flow transformation that rewrites method bodies so they no longer map back to source structure, and native code protection. On iOS the equivalent product applies comparable transformations at compile time to Swift and Objective C. Both inject runtime self protection: checks for rooted and jailbroken devices, attached debuggers, hooking frameworks, emulators and repackaged binaries, with configurable responses. Because protections are injected at build time rather than bolted onto a finished artifact, they are woven through the application rather than sitting at its edge. The vendor also offers a scanning product and a monitoring service that reports protection triggers from the installed base.
Where it fits
Protection is applied during the build, configured by the platform or security team and living in the build files developers use daily. Scanning runs earlier, against candidate builds, and monitoring runs continuously in production. You need a controlled build, since protection configuration has to be maintained as the codebase changes, and a plan for crash reporting, because obfuscated stack traces are unreadable without mapping files.
Strengths
- Build time injection produces protection distributed through the application rather than a single detectable layer.
- Covers both major platforms with one vendor and a consistent posture, valuable for teams shipping paired apps.
- Runtime telemetry from the installed base shows which attacks are actually happening to your app, not just which controls exist.
- ProGuard gives a well understood open source baseline, so teams can start there and see what the commercial tier adds.
Limitations
- Obfuscation configuration is ongoing work. Reflection, serialization and dynamic class loading break under renaming, and keeping the rules correct is a recurring maintenance tax.
- Protected builds are harder to debug and support. Mapping file discipline is mandatory, and losing one makes production crashes unreadable.
- Obfuscation raises the cost of analysis, it does not prevent it. A determined analyst with instrumentation gets there anyway, so this buys time, not immunity.
Who it suits
Teams whose apps hold value on the device and face attackers with physical access: banking, payments, gaming and anything with licensing to enforce. Teams whose risk sits in backend APIs, or who lack the build discipline to maintain obfuscation rules, will spend effort here for little return.
Used Guardsquare? Recommend it under your own name and title.
Recommend this tool