← MOBILE RELEASE AUDITOR / LOCAL LAB
LOCAL TECHNICAL PREVIEW
No package upload. No signing secrets. No store-clearance theatre.

Match the release contract.
Then review what shipped.

This working preview compares a structured inventory from one accepted Android or iOS release with one candidate. It requires the platform, package format, application identifier, distribution stage, build mode, Unity version, platform toolchain, inspection profile, compression profile, and symbol policy to match before showing permission, entitlement, SDK, architecture, metadata, symbol, debug-content, and payload movement.

EXECUTION
Entirely in your browser
INPUT
Structured inventory pair
POLICY
Visible change + size rules
FAIL-CLOSED
Contract mismatch becomes unknown
LOCAL WORKBENCH / MOBILE-RELEASE-V0.1

Compare one accepted package inventory with one candidate.

VISIBLE POLICY / MOBILE-RELEASE-REVIEW-V0.1

Contract before drift. Ten package, build, toolchain, and inspection fields must match. Every observable change remains visible; expected changes are labelled, not removed. Payload growth crosses a failure threshold only when both visible ceilings are exceeded.

Compressed artifact+15 MiBAND +5%
Unpacked artifact+30 MiBAND +5%
Native payload+10 MiBAND +10%
Managed payload+5 MiBAND +10%
Asset payload+15 MiBAND +10%
Resource payload+5 MiBAND +10%
Symbol payload+10 MiBAND +20%

Nothing in either inventory leaves this browser. This preview does not open or upload packages. Use only sanitized manifest, entitlement, dependency, architecture, symbol, and payload inventory values. Do not paste package contents, paths, hashes, credentials, personal data, or confidential names.

WHAT THIS PREVIEW PROVES
01

Exact release-contract gate

Ten package, build, toolchain, extraction, compression, and symbol-policy fields must match. A different app, package stage, inspector, or build environment cannot receive a drift verdict.

02

Traceable contract movement

Permission, entitlement, native dependency, architecture, metadata, symbol, and debug-content findings retain both observable values, inventory source, and SDK-identification confidence.

03

Expected does not mean hidden

The release owner can declare expected change identifiers. Matching changes remain in the report with an expected label; declarations that never appear remain visible too.

04

Bounded inference

The result can prioritize one package evidence source. It cannot predict store acceptance, establish compliance or vulnerability status, measure runtime SDK behavior, or identify root cause.

Android App Bundles expose module manifests, native libraries, resources, assets, DEX, and bundle metadata, while Google Play generates device-specific APKs from that publishing artifact. Apple documents final Info.plist contract values and inspection of entitlements embedded in a signed app. The preview consumes a narrow CI-generated inventory of those surfaces; it does not request the package itself.

Android App Bundle format ↗Apple entitlement inspection ↗Apple Info.plist contract ↗Unity iOS build stages ↗
PRIVATE PILOT

Need the inventory produced from the real package?

The private pilot adds one versioned read-only extractor inside the studio's release CI, an accepted inventory lookup, studio-owned policies, a review destination, and an evaluator-owned success test. XeSoft does not request signing keys, store credentials, source, or production player data.

Discuss a private pilot