x360 / app provenance
ENRU

Android apps, checked by their data

Not a file dump. Every card carries the facts extracted from the APK itself: who signed it and whether the key ever changed, the SHA-256 of the exact file, which Android version it runs on, and what permissions each release added or removed.

What every card gives you

Signature and certificate history SHA-256 of the file we serve Compatibility from minSdk Permission diff between versions