Architecture Decision Guide
Standalone SDK vs. Sentinel Enterprise
Choose the right integration tier for your requirements: from zero-backend, offline on-device scanning to centralized cloud risk intelligence and remote hardware attestation.
TIER 1 · FREE CORE SDK
Aegis Guardian (Standalone)
Embed directly into your mobile app. Executes local runtime checks on the device with zero network calls and complete offline independence.
- ✓ App-scoped Unique Device ID (Widevine/Android ID & iOS Keychain)
- ✓ On-device Root & Jailbreak detection
- ✓ Frida hooking & debugger attachment detection
- ✓ App signature & certificate fingerprint verification
- ✓ Screen privacy overlay (Android secure flag, iOS blur)
- ✓ 100% offline-capable, zero external server dependency
- ✓ Free to use via Maven Central, CocoaPods, and pub.dev
ENTERPRISE GRADE
TIER 2 · RISK INTELLIGENCE PLATFORM
Guardian + Sentinel Enterprise
Pair the SDK with Sentinel backend for cryptographic attestation, central threat telemetry, real-time risk policies, and automated blocking.
- ✓ App-scoped Unique Device ID + Device 360° forensic inventory
- ✓ All Guardian local checks + hardware-backed key enrollment
- ✓ Google Play Integrity & Apple App Attest cryptographic verification
- ✓ Backend
POST /api/v1/assessdecision enforcement - ✓ Real-time Sentinel Web Console (Live Threats, Fleet Inventory)
- ✓ Dynamic rule tuning, tenant quotas, and instant device blocklisting
- ✓ Automated SIEM / SOC webhooks for incident response
Detailed Capability Matrix
Side-by-side comparison of runtime guarantees and infrastructure requirements.
| Capability | Aegis Guardian (Standalone) | Guardian + Sentinel Enterprise |
|---|---|---|
| Unique Device ID | ✓ Local App-Scoped ID (Offline) | ✓ App-Scoped ID + Device 360° Tracking |
| Root & Jailbreak Detection | ✓ Local Signal | ✓ Local + Remote Risk Score |
| Frida / Hooking Detection | ✓ Memory & Process Scan | ✓ Dynamic Threat Rule Trigger |
| Hardware Key Attestation | ✕ Not Enforced | ✓ Play Integrity & App Attest |
| Server-side Enforcement | Custom App Logic | ✓ Verified Token Assessment API |
| Central Dashboard & Telemetry | ✕ None (Self-contained) | ✓ Sentinel Real-time Console |
| Device Blocklisting / Allowlisting | ✕ Manual | ✓ Instant Fleet Enforcement |
| SIEM / SOC Webhooks | ✕ None | ✓ Automated Incident Feeds |