Exact release-contract gate
Ten package, build, toolchain, extraction, compression, and symbol-policy fields must match. A different app, package stage, inspector, or build environment cannot receive a drift verdict.
This working preview compares a structured inventory from one accepted Android or iOS release with one candidate. It requires the platform, package format, application identifier, distribution stage, build mode, Unity version, platform toolchain, inspection profile, compression profile, and symbol policy to match before showing permission, entitlement, SDK, architecture, metadata, symbol, debug-content, and payload movement.
Contract before drift. Ten package, build, toolchain, and inspection fields must match. Every observable change remains visible; expected changes are labelled, not removed. Payload growth crosses a failure threshold only when both visible ceilings are exceeded.
Ten package, build, toolchain, extraction, compression, and symbol-policy fields must match. A different app, package stage, inspector, or build environment cannot receive a drift verdict.
Permission, entitlement, native dependency, architecture, metadata, symbol, and debug-content findings retain both observable values, inventory source, and SDK-identification confidence.
The release owner can declare expected change identifiers. Matching changes remain in the report with an expected label; declarations that never appear remain visible too.
The result can prioritize one package evidence source. It cannot predict store acceptance, establish compliance or vulnerability status, measure runtime SDK behavior, or identify root cause.
Android App Bundles expose module manifests, native libraries, resources, assets, DEX, and bundle metadata, while Google Play generates device-specific APKs from that publishing artifact. Apple documents final Info.plist contract values and inspection of entitlements embedded in a signed app. The preview consumes a narrow CI-generated inventory of those surfaces; it does not request the package itself.
The private pilot adds one versioned read-only extractor inside the studio's release CI, an accepted inventory lookup, studio-owned policies, a review destination, and an evaluator-owned success test. XeSoft does not request signing keys, store credentials, source, or production player data.
Discuss a private pilot →