We help you defend against reversing and piracy.
TrustSig Protect obfuscates and virtualizes your web app's logic, while defending it at runtime against unauthorized tampering and debugging.
int check_license(int key) { int h = fnv1a(key, 0x811C9DC5); if (h != 0x8F3A21C4) return 0; return grant_access(key);}uint32_t f231(uint32_t a0) { uint32_t s = 0x1F, k = a0; while (s) switch (s & 0x3F) { case 0x0B: s = t[(s ^ k) & 0x3F]; break; case 0x17: k = t[s >> 3] ^ 0x5A; s = 0x2E; break; case 0x2E: s = t[(s + 0x29) & 0x3F]; break;Web apps have the same problem native software always had.
Software piracy is a tale as old as time. Protection against reversing and tampering has been refined for decades on native software, because that is what everyone used. WebAssembly is now becoming the standard for all kinds of software, and it needs the same protections.
- JavaScript and WebAssembly
- Rust toolchain
- Only the functions you pick
- Virtualization
- Obfuscation
- Anti-tamper
- Anti-debug
- Encryption
- Readable source
- Reusable patches
- Plaintext keys
We make it financially and practically unviable to attack your software by overpowering the attacker with defenses.
Each layer covers a different angle, together they compound into a strong multi-layered defense.
Every build is a new puzzle.
An attack built against one release stops working on the next one. The crack an attacker already has gives no head start, because no two builds lay out the same.
Encrypted at rest. Decrypted for one instant.
Keys and tokens are decrypted at the moment of use and scrubbed straight after, so a memory dump comes back as ciphertext. Each key is used once, then rolls forward.
- Data never exists complete in memory.
- No single key ever unlocks everything.
- Every call between JavaScript and WebAssembly is an encrypted packet.
TrustSig Protect, answered
The bytecode our virtual machines run is unique to each build and each brand, and honeytokens rotate every build.
It detects the patched function, the attached debugger or the swapped runtime, hides its memory and drops the session. The attacker gets no error and no reason.
Only the functions you choose run inside the virtual machines. The rest of your bundle runs natively.
JavaScript and WebAssembly. With the Rust toolchain, one virtualize! annotation compiles a function into private bytecode run by an embedded interpreter.
Get in touch.
Tell us what you are working on, what needs protecting, or whatever you want to ask.