For the complete documentation index, see llms.txt. This page is also available as Markdown.

How do I handle VAPT findings against the SDK?

Common VAPT findings on the SDK, and how to handle each

Common VAPT findings on the SDK, and how to handle each:

  • Hardcoded secrets: usually the API key / dev ID passed during init from your own code. Keep the API key on your backend, not in the client.

  • allowBackup=true in the SDK module: override it by setting android:allowBackup=false with tools:replace in your app manifest.

  • Flagged cipher modes: these belong to a deprecated, inactive feature.

  • V2/V3 certificate signing: controlled by your app's signingConfigs, not the SDK.

Last updated

Was this helpful?