How to know if your phone is tapped
Look beyond battery drain and strange messages. SmartScan checks network behaviour for covert C2 traffic, DNS anomalies and TLS fingerprints that a file scanner cannot see.
SmartScan Forensic captures your device's network traffic through an encrypted WireGuard tunnel and analyses it against 200+ threat signatures — Pegasus, Predator, Graphite, Hermit, FinSpy, Candiru and hundreds more. No account required. Zero personal data collected.
Consumer antivirus apps scan the filesystem and installed packages. Nation-state spyware runs from kernel memory, leaves no artifacts on disk, and communicates through encrypted C2 channels. You cannot find it with a file scanner.
SmartScan is built for the moments when “maybe my phone is infected” is not enough. It targets the exact questions people ask after travel, legal pressure, stalking, corporate espionage, suspicious app behaviour or high-risk reporting work.
Look beyond battery drain and strange messages. SmartScan checks network behaviour for covert C2 traffic, DNS anomalies and TLS fingerprints that a file scanner cannot see.
Our engines look for spyware families used in state-level surveillance, including Pegasus by NSO Group, Predator by Intellexa/Cytrox, Graphite by Paragon and related zero-click infrastructure.
No jailbreak and no root required. The app captures traffic through platform-supported VPN APIs and sends it to the forensic engine for analysis.
Useful when you suspect commercial stalkerware, suspicious Android permissions, abnormal data usage, app-based tracking or coercive phone monitoring.
Designed for high-risk users: investigative journalists, lawyers, NGOs, politicians, executives, BYOD programmes and teams exposed to targeted surveillance.
Run a complete phone security analysis after border crossings, device seizure, buying a used phone, protest attendance, corporate travel or suspected tampering.
Battery drain, overheating or strange messages can have innocent causes. SmartScan turns suspicion into forensic network evidence by checking where the phone connects, how often, and with which TLS fingerprints.
Commercial spyware is a global industry — sold to governments, deployed against journalists, activists, executives and their families. Our engine tracks 200+ surveillance tools using JA3/JA4+ TLS fingerprinting, DNS pattern analysis, Suricata rules and behavioral heuristics.
The most infamous mobile spyware. Zero-click infection via iMessage, WhatsApp, and SMS. Documented use against 31,000+ journalists and human-rights defenders across 45+ countries.
Android and iOS exploitation platform. Documented targeting of EU politicians, US officials and investigative journalists. Persistent kernel-level access with covert data exfiltration.
Next-generation implant, RAM-resident with kernel-level persistence. Designed to bypass every consumer security stack. Recent WhatsApp campaign targeted 90+ journalists and civil society members.
Israeli zero-day marketplace vendor. Custom implants for high-value targets. Windows, macOS, iOS and Android exploitation with month-long persistence campaigns.
Hermit (RCS Lab), FinSpy (FinFisher), QuaDream, commercial stalkerware, MDM abuse, and hundreds of surveillance signatures tracked by our forensic engine — including previously unseen C2 infrastructure detected before it enters public threat feeds.
No rooting. No jailbreaking. No permanent VPN. The scan runs for 15 minutes, produces a report, and then your device goes back to normal.
Download from the App Store or Google Play. No account. No email. No login. A random Device ID is generated locally at first launch — your identity is never known to our servers.
Tap Start Scan. The app activates a WireGuard tunnel and captures your device's network traffic for a configurable window of 10 to 30 minutes. Use your phone normally while the scan runs — that improves detection.
The forensic engine analyses your capture against 200+ signatures and returns a PDF report with MITRE ATT&CK mapping, IOC tables, JA3 evidence, risk scoring and chain of custody metadata. Court-admissible.
Every scan runs the full stack. No pay-to-unlock tiers, no upgrade path — the same forensic depth for every user.
Zeek-based behavioral protocol parser. Extracts connections, files, TLS metadata.
Deep TLS handshake analysis. Cipher suites, versions, ALPN, SNI.
Client TLS fingerprinting to identify implant tooling by hash.
Server-side TLS fingerprinting to identify C2 infrastructure.
Suricata rules against known IOCs and exploit signatures.
Anomaly detection on communication patterns and volumes.
Cross-check IPs, domains and hashes against 70+ vendors.
Open Threat Exchange correlation for indicators of compromise.
Match traffic to installed apps by UID (Android) and SNI heuristics.
Extract and hash transferred files, cross-check with IOC feeds.
TLS certificate anomalies, short-lived certs, suspicious CAs.
Detect periodic beaconing intervals typical of C2 channels.
Suspicious DNS failover chains and covert channels.
Direct-to-IP connections that bypass name resolution.
HTTP/3 and QUIC anomalies where classic tools are blind.
Statistical detection of Cobalt-Strike-style C2 beaconing.
Port/protocol mismatch, tunneling over unexpected channels.
Stalkerware and MDM-abuse signatures specific to mobile.
ASN, country and hosting-provider risk scoring for endpoints.
Unsupervised anomaly detection on multi-dimensional traffic features.
Senior-analyst logic layer: correlates all findings into a risk narrative.
MITRE ATT&CK mapped, evidence-linked, court-ready PDF output.
The base scan is powerful, but any forensic engine produces false positives. If your report contains Critical or High alerts, the app offers a C-Level upgrade — a deeper Bayesian double-verification pass that separates real threats from noise. Available to every user, not just executives.
Available to every userThe app proposes the C-Level upgrade right after a base scan finds Critical or High alerts. No hidden menu, no upsell email — the offer appears exactly when it matters.
Every finding is re-examined by a second independent detection pass with different priors. Only threats confirmed by both passes make it into the C-Level report — cutting false positives without losing real signals.
Expanded TLS fingerprinting with JA4+, cross-referenced against 5,000+ additional signatures and proprietary deep-packet heuristics not present in the standard pipeline.
The C-Level upgrade costs 4 additional scan credits — pay only when you actually need it. No monthly fee, no invitation-only tier, no enterprise contract required.
We're giving the first 1,000 users a free forensic scan. One per device. Paste your Device ID from the app, prove you're human, and we'll credit your account.
Launch campaign
No personal data collected by default. Traffic captures are analyzed and destroyed within 24 hours.
Every alert mapped to a documented tactic and technique for defensible reporting.
Dual pinning to ISRG Root X1 and our Secure Path CA — the app refuses to talk to imposters.
A UK-registered private company. Full corporate identity in the footer.
Availability: Available worldwide except in: China, Russia, Iran, North Korea, Syria, Cuba, Myanmar.
Free to install. Free to explore. Free to claim your first scan. Then €49 per scan — pay only for what you need, no subscription trap.