Audit an app: nothing to install, nothing to configure.
From declaring the app to behavioral analysis on a real phone, through to the detailed report.
Let’s scope your need.
Let’s frame what you want to audit: a one-off analysis or ongoing monitoring. We open your access, with no integration and nothing to install on your side.
Sign in to your workspace.
Once your access is open, sign in to launch analyses and find all your reports in one place.
Declare the app.
A Google Play Store link is enough, or a .apk file if the app isn’t published yet. No integration to set up, no source code access.
Launch an analysis, with a journey.
Define the journey to play: accept consent, refuse it, browse, log in. Skanopy replays it on a real phone and records every action, to see which third-party actors fire, and when.
Explore the analysis report.
As soon as the analysis is done, the report is available in your workspace: active third-party actors, the server map, decrypted requests, identifiers and personal data transmitted, the gap with the consent banner, and device-storage accesses.
Your questions, answered
No. A Google Play Store link or a .apk file is enough. The analysis is black box.
You submit the app, Skanopy analyzes it across real user paths (refusing consent, accepting, logging in, navigating) and you receive a full technical report. Nothing to install, no imposed process.
Skanopy analyses Android apps, from a Google Play Store link or a .apk file.
A tool that observes what an app actually does: third-party actors contacted, identifiers and personal data transmitted, whether a consent refusal is respected. Skanopy is that deep mobile behavioral analysis platform, automated: the app runs on a real phone and every finding is documented, reproducible, with no access to the source code.
No. Skanopy provides reproducible technical findings, mapped to the CNIL recommendation. Legal qualification is yours to make: Skanopy gives the evidence, you decide.
Yes. Your reports are visible only to you, and your data is hosted in the European Union.
Every signal is documented in the report: a clear explanation, an exposure level and a technical pointer. You have what you need to qualify and act.
Both. A one-off analysis, or ongoing tracking that re-analyzes each new release and hands you an updated report.
Keeping compliance under watch over time: every new release of the app is re-analyzed, and new third-party actors or behaviors are flagged against the previous version. A one-off audit only covers the version analyzed. Compliance monitoring follows the app release after release.
By watching the app run, not its code. Skanopy runs it on a real phone, captures the domains it contacts and ties each to the third-party actor behind it, then flags those that fire before consent or despite a refusal. You get the list of third-party actors actually active, with the evidence for each.
By replaying the real paths, refusal as well as acceptance, and comparing what the consent banner declares against what actually fires. Skanopy surfaces the third-party actors active despite a refusal, and those collecting without appearing in the CMP. Every finding is reproducible and dated.
Skanopy maps its technical findings to the CNIL recommendation for mobile apps: prior consent, respect for refusal, identifiers read on the device. It provides the evidence; the legal qualification remains yours.
Is the app’s source code required?
No. A Google Play Store link or a .apk file is enough. The analysis is black box.
A question before you get started?