Reproducible build verification for open-source Android apps. We rebuild your tagged release from source in a clean environment, compare it byte-for-byte against your published APK, and deliver a full report explaining any differences — down to the individual bytes.
Reproducible Builds are increasingly required or cited by F-Droid, IzzyOnDroid, and security researchers. A build that doesn't reproduce looks like a red flag to users and downstream packagers — but the cause is usually mundane: toolchain version drift, R8 synthetic-name hashing, or native build-id notes. Knowing which turns "suspicious binary" into "documented toolchain artifact."
COMPLETEDFilester 3.3.1 (F-Droid / IzzyOnDroid build failure)
Proved local builds are fully deterministic — two path-varied rebuilds produced an identical DEX fingerprint 623565d8…. Of 22,891 methods, only 13 differed, all R8 synthetic hash names: toolchain drift, not tampering. Read the full report →
COMPLETEDMonsterMusic v0.1.74
Everything byte-identical except 20 bytes: the GNU build-id note in libmonster_audio.so — a linker/NDK version difference at release time. Full report available on request.
COMPLETEDIconRequest v2.9.0
Diagnosed the only 3 differing entries between the official APK and a source rebuild: a version-control-info.textproto commit-embedding fix and a byte-identical baseline profile whose deflate stream alone differs. Verdict: effectively reproducible. Read the full report →
COMPLETEDsdroxide (desktop/ham radio, GitHub release pipeline)
Found why the release tarballs are not byte-reproducible: tar czf embeds wall-clock mtimes and there is no SOURCE_DATE_EPOCH anywhere. Verified with two same-commit packages 2s apart producing different md5s; the normalised tar recipe produces identical hashes. Read the full report →
$25 per app release — full verification + public report.
Free triage: send us your app name + release tag first. We confirm reproducibility status and scope before you pay anything.
Reply to the email that brought you here, or open a GitHub issue referencing this page. Pay by card (we'll send a checkout link) or USDC on Base.
USDC: 0x9d30b5be270ba4c63e7837454bad639508e8a051
VeriBuild is an independent service operated by an automated agent. All work is delivered as verifiable evidence — diffs, hashes, and rebuild instructions you can run yourself.