Reap Guard by Venmara
On-device security and privacy

Your phone, made honest.

Most people never get two things: a clear picture of what every app is actually doing with their data, and real protection for the moment a phone is lost, stolen, or taken. Reap Guard gives you both, and it does all of it on the device itself. There is no Reap Guard server, and nothing it finds is ever uploaded.

0
servers your data touches
Per-app
connections, trackers, and leaks
500 KB
per-minute upload guard, on by default
On-device
encrypted at rest, no egress

What it does

Three jobs, one guardian.

Reap Guard is visible and on your own device by design. It is not hidden, and it is not built to be turned against anyone else. Everything it does is either something you can see, or something that activates only in response to a real security event.

01 / VISIBILITY

What it sees

Know what your apps are really doing.
  • Every app's connections and where its data goes
  • Automatic ad and tracker blocking, with per-app control
  • Personal data caught the moment it leaves the device
  • Background activity separated from what you actually did
  • Alerts when an app gains camera, microphone, or screen access
  • A full per-app dossier: usage, endpoints, leaks, and risk in one place
02 / PROTECTION

How it defends

Built for the moment the phone leaves your hands.
  • Locate, lock, and quietly gather proof of who has the device
  • Escalation on a schedule if you go silent or unreachable
  • Decoy files and tamper traps that fire when someone snoops
  • A duress unlock that appears to comply while it keeps defending
  • Resistant to being switched off, with every attempt recorded
  • A tamper-evident record built to survive a device wipe
03 / INTEGRITY

Guarding the ground

Notice when the device is being set up against you.
  • Flags the tell-tale signs of surveillance being prepared
  • New monitors, administrators, or debugging access called out
  • A new fingerprint or face added to unlock is treated as a signal
  • Root, rogue certificates, and instrumentation are checked for
  • Honest about its own blind spots instead of showing a false all-clear

How it works

All of it happens on the phone.

Reap Guard runs a local VPN on the device. Not to route your traffic through some remote server the way a commercial VPN does, but so Android will let it see, on the device itself, which apps talk to which destinations and what they carry.

STEP 01

It watches, in place

Traffic still goes wherever it was already going. Reap Guard reads it in passing, attributes every connection to the app that made it, and records the metadata: destination, port, protocol, byte counts, and the hostname from the handshake.

STEP 02

It decides, per flow

A policy engine reads each connection at the moment it opens and acts: allow it, block it, slow it, or send it nowhere. Known advertising, analytics, and tracking endpoints are cut automatically, out of the box.

STEP 03

It keeps the evidence

Findings are written to a local database encrypted with SQLCipher, its key sealed in the phone's hardware-backed Keystore. You read it in the dashboard or export it. We never see any of it, because there is nowhere for it to go.


Two editions

One engine, two levels of reach.

The same core engine ships in two configurations. They differ in how deep the tool is allowed to look and how far it is allowed to act. Choose by the phone you are protecting and the threat you are protecting it from.

Version 1 is the app store edition, and it is the only one published there. The Full instrument is a separate build you provision yourself on hardware you own. It is not distributed through the Google Play Store on any release track, and it is not an update, an in-app purchase, or a downloadable module of the version you install from the store. Nothing in the store edition turns into it.

Version 1 · shipping now · the Google Play edition

Reap Guard

The everyday guardian. Visibility and defense, without looking inside your traffic.

The full visibility and forensics engine, plus a recovery-passphrase lock on the app and a refusal to run on a rooted phone. It never reads your keystrokes, never captures your screen, and never decrypts your traffic.

  • On-device network capture and the Endpoint Atlas
  • Multi-layer blocking: DNS, TLS name, QUIC, and whole-app firewall
  • Upload guard, background-exfiltration forensics, and leak scanning
  • SIM and line-hijack checks, deep device and usage forensics
  • No keystroke capture, screen capture, or traffic decryption
  • No camera, microphone, SMS, or call-log access
Full · research and high-threat · not on any app store

Reap Guard Full

The complete instrument. Deep interception and an active kill-switch.

Everything in version 1, plus opt-in traffic decryption for apps that permit it, an active self-defense subsystem for a device that is out of your hands, and forensic capture. Provisioned on hardware you own and control.

  • Opt-in TLS decryption for apps that trust the local CA and do not pin
  • Dead-hand switch, decoy tripwires, and a staged doomsday response
  • Remote control over SMS, duress unlock, and incident autopsy
  • Keystroke and screen capture, both forced visible by Android
  • Anti-tamper: uninstall and force-stop resistance on a provisioned device
  • Provisioned by you on your own device. Not distributed on the Google Play Store or any other app store, on any track

The philosophy behind it

Three ideas run through everything.

01

Show the truth, not a comforting version of it.

Every alert can be traced back to why it fired. Where the tool cannot see something, it says so plainly, rather than showing a reassuring but empty result. Trust is a feature.

02

Prevention beats detection.

Where Reap Guard can simply stop something harmful from leaving the device, it does. You do not have to understand a threat to be protected from it.

03

On your own device, in the open.

Reap Guard defends the phone you own. It keeps its icon, shows a notification whenever it is monitoring, and never hides from you. That is the line between a security tool and spyware, and it stays on the right side of it.


Honest about the limits

What it cannot do, said plainly.

A security tool that oversells itself is a liability. Here is where the edges are.

Blocking by name is best-effort.

Encrypted DNS, Encrypted ClientHello, and connections to hard-coded IP addresses can slip a name-based block, and a socket already open before you blocked it is not cut. The whole-app firewall is the reliable option when you need one app fully stopped.

It does not break real encryption.

Version 1 sees where a connection is going, not what is inside it. In the Full instrument, decryption is opt-in, needs a certificate you install yourself, and works only for apps that permit it. Banks and messengers that pin their certificates stay opaque by design.

Some depth needs a provisioned device.

Kernel-level capture, per-process tracing, and blocking a force-stop from Settings require privileges Android will not hand a normal app. Those live in the Full instrument on hardware you have provisioned yourself.

Self-defense is bounded by the platform.

Locking, wiping, beaconing, and evidence capture run fine in the background. An alarm, a photo, or an audio clip may wait until the app is next opened, because Android restricts starting a camera or microphone from a background task, and it forces a visible indicator when either runs.

Read the full specification for both editions.