ANDROID 12–15 · NO ACCOUNT REQUIRED

Every app on your phone,
audited on your phone.

ThreatSweep reads permissions, checks for root and live USB debugging, and turns the mess into a single risk score — 41.2 or 96.7, whatever it actually is. The scan runs locally. Nothing about your app list leaves the device unless you ask it to check a hash against VirusTotal.

0
PII fields collected
32B
sent per hash lookup
100%
audits run on-device
DEVICE_SCAN.LOG
DEVICE RISK SCORE
63.4
ROOT: DETECTED
ADB: off
com.batteryboost.fast12 permissions
com.flashlight.pro7SYSTEM_ALERT_WINDOW
com.weather.today5 permissions
org.signal.messenger9 permissions
hashing com.batteryboost.fast → sha256:8f14e4… → VirusTotal
NO PII COLLECTED·NO AUDIT DATA UPLOADED·SHA-256 HASHES ONLY·VIRUSTOTAL + GOOGLE PLAY BILLING
01 / TRANSPARENCY MISSION

Real system calls.
Not a progress bar for show.

A lot of "cleaner" and "security" apps on the Play Store fake their work — a spinning wheel, a countdown, then a suspiciously round number. ThreatSweep doesn't animate anything it hasn't actually measured.

PackageManager, not theater

Permission lists come straight from Android's PackageManager for every installed app. If the audit says an app holds 14 permissions, that's a count, not a guess.

Root & ADB checks are real tests

Root detection runs actual binary and build-tag checks (su binaries, test-keys, known root packages). USB debugging status is read from the live system settings, not inferred.

The risk score is arithmetic

Every score is a weighted sum of dangerous-permission counts, exposed components, and known-risk signals — recomputed fresh each time, never cached to look busy.

Storage & battery links are real shortcuts

The 'clean storage' and 'battery' buttons open Android's own system screens — we don't run a fake optimization pass and take credit for it.

02 / HOW REPUTATION CHECKS WORK

We fingerprint the app. We never touch the file.

01
APK on device

An installed package sits in local storage, untouched.

02
SHA-256 fingerprint

ThreatSweep computes a one-way hash of the APK — a fixed 64-character fingerprint, not a copy.

03
VirusTotal lookup

Only that 64-character string is sent over HTTPS to check against VirusTotal's reputation database.

// what actually goes over the wire
POST https://www.virustotal.com/api/v3/files/8f14e45fceea167a5a36dedd4bea2543...
body: { "hash": "8f14e45f..." } — 64 bytes. No APK, no filename, no device identifier.
03 / FREE VS PREMIUM

The full audit is free. Premium buys automation.

Free Tier

$0

Essential auditing for basic device awareness.

Monthly Premium

$7.99/month

Full protection and advanced tools.

BEST VALUE

Yearly Premium

$59.99/year

Save over 35% compared to the monthly plan.

Feature comparison

FEATUREFREEPREMIUM
Permission Audit
Limited scan — shows top 3 riskiest apps only
Full system audit of every installed application
Deep Virus Scan
Basic reputation alerts
On-demand deep analysis using the professional VirusTotal threat database
Uninstaller Utility
Basic flagging of hidden or overlay apps — 1 per category
Advanced uninstaller with high-risk prioritization and full visibility into suspicious system modifications
System Security Audit
Detects root access, active USB debugging, and system vulnerabilities
Detects root access, active USB debugging, and system vulnerabilities
Storage & Battery Tools
Direct integration with Android's native management tools
Direct integration with Android's native management tools
Real-Time Protection Status
Standard alerts
Persistent 'Phone Protected' status and priority real-time monitoring

Billed and processed by Google Play Billing. ThreatSweep never sees or stores your payment details.

04 / PERMISSIONS, JUSTIFIED

Every permission ThreatSweep asks for, and why.

QUERY_ALL_PACKAGES
Enumerates installed apps so the audit engine can score every package on the device — not a sample.
REQUEST_DELETE_PACKAGES
Lets you uninstall a flagged app in one tap from the results screen instead of hunting through Settings.
POST_NOTIFICATIONS
Surfaces an alert the moment a new app is installed, before it has a chance to sit unaudited.
INTERNET
Carries two things only: Play Billing receipt checks, and a SHA-256 hash sent to VirusTotal. Never file contents.

Know what's actually installed on your phone.

Free to install. Full audit, zero setup, nothing uploaded.

GET THREATSWEEP