Skip to content
Your phone holds more of your life than your wallet does

Bachao Guardian — Android Device Security & Network Monitor

See what's actually happening on your Android device — not what an app claims.

Free device-security app for Android. Checks your device's hygiene, audits which permissions apps were actually granted, and shows which servers your apps are contacting — with the option to block.

Freefor everyone
Android7.0+
On-deviceall checks run locally
Nocontent inspection
Free appAndroid APKEmail sign-in onlyOn-device checksTransparent telemetry
Free Android app

Get Bachao Guardian

Check your device's security hygiene, audit granted app permissions, and watch your network egress — free, sign in with your email.

Android 7.0+ · v1.0.0 · Google Play listing coming soon. Direct APK by Dhisattva AI Pvt Ltd, a DPIIT-recognised startup.

  1. 1.Tap Download APK.
  2. 2.Open the file & allow install from this source.
  3. 3.Sign in with your email (one-time code).
  4. 4.Review your device & app posture.

How it works

Three checks, all running on your device — hygiene, permissions, and network egress.

1Install & open

Download the free Android app and sign in with your email — no password, one-time code. Guardian runs its device-hygiene checks immediately, on-device.

2Review your device & app posture

See your patch age, root/debugger status, and a per-app breakdown of granted permissions — the things you approved, possibly months ago and forgotten since.

3Watch the network monitor, block what you don't want

See which app is contacting which domain in real time, and block a domain or an app directly from that view.

Guardian CAN see — connection metadataWhich appWhich domainWhen / how oftenGuardian CANNOT see — encrypted contentMessage / form contentsFiles, photos sentLogin credentials,payment detailsBecause that traffic is encrypted end-to-end (TLS) — the same reason your bank app is safe on public Wi-Fi.
The network monitor sees connection metadata, never encrypted content. This is a real limit, not a marketing footnote.

Device hygiene — what Guardian checks

Everything below runs on your device. Nothing here requires network access to compute.

Root / jailbreak detection

Flags common root indicators (su binaries, root-manager packages, altered system paths) that weaken the OS security model for every app on the device.

Debugger & Frida detection

Detects an attached debugger or a running Frida server — the toolset used to instrument and tamper with apps at runtime, including banking and payment apps.

SSL-pinning-bypass detection

Flags tooling (Xposed/Frida modules, known bypass frameworks) commonly used to defeat certificate pinning and intercept traffic that's meant to be protected.

Emulator detection

Flags when the app itself is running inside an emulator/virtualized environment rather than physical hardware — relevant for anyone side-loading or testing builds.

Security patch age

Reads the device's Android security patch level and tells you how many months behind it is — the single biggest predictor of exploitable OS vulnerabilities.

Android version

Shows your installed Android version against the current supported releases, so you know if you're on a version still receiving security updates at all.

Developer options & USB debugging

Flags when Developer Options or ADB/USB debugging is left enabled — a legitimate power-user setting, but also a larger attack surface if forgotten on.

Screen lock status

Checks whether a screen lock (PIN/pattern/biometric) is configured at all — the first line of defense if the device is lost or stolen.

Unknown sources / install provenance

Shows whether installs from outside the Play Store are allowed, and for each app, which installer actually put it there (Play Store, another app, a sideload).

Hidden-app detection

Surfaces apps that hide their own launcher icon — a pattern used by both legitimate utilities and stalkerware, so it's worth knowing about either way.

Permission audit — what you actually approved

Not the wish-list an app declares in its manifest. The permissions Android currently has marked GRANTED, per app.

  • Per-app audit shows GRANTED permissions — the current, actual state — not the list of permissions an app merely declared in its manifest.
  • Covers the sensitive groups: Camera, Microphone, Location (including background location), Contacts, SMS, Storage, Phone, Call Log.
  • One screen per app, so you can see at a glance which of your apps can see your camera or your location right now — and revisit permissions you approved once and forgot about.
  • Guardian only reads permission state via Android's own APIs — it does not access the contents of your contacts, photos, messages, or files to produce this list.

Network egress monitor

See which app contacts which domain — and block a domain or an app. Read the limits below before you rely on it.

Which app contacted which domain

Per-app attribution of outbound connections — you see the app name next to the domain it reached, not just an anonymous IP address.

Block a domain, or block an app

Once you see a connection you don't want, block it at the domain level or cut off the app's network access entirely — your call, per app.

What it cannot see

Encrypted (HTTPS/TLS) traffic content is invisible to Guardian, the same as it is to every other on-device monitor that isn't breaking your connection's security. It sees the destination, not the payload.

What blocking doesn't cover

A block you add doesn't retroactively close connections that were already open, doesn't invalidate a DNS answer already cached by the OS, and can't stop an app that talks to a hardcoded IP address instead of a domain name.

Device support status

Guardian flags when your manufacturer has stopped shipping security updates for your specific model — a common and easy-to-miss situation a few years after a phone's release, and one that leaves every known future vulnerability permanently unpatched.

Frequently asked questions

Straight answers, including the limits — especially the limits.

Does Guardian see what data my apps send, or just where they connect?

Just where they connect. Guardian sees connection metadata — which app opened a connection, to which domain, and when — the same kind of information any on-device firewall/monitor can see. It cannot see inside encrypted (HTTPS/TLS) traffic, so it never sees the actual data being sent: not your messages, not form contents, not files. Anything claiming to show you "what an app is sending" over HTTPS without breaking that connection's security is either wrong or doing something you wouldn't want.

If I block a domain, am I fully protected from that app reaching it?

Blocking stops new connection attempts to that domain going forward. It does not retroactively close a connection the app already had open before you blocked it, it does not un-cache a DNS answer the OS already resolved and cached, and it cannot stop an app that connects to a hardcoded IP address instead of a domain name. Treat it as a strong control, not an absolute guarantee.

What does "GRANTED permissions" mean, versus what an app asks for?

Every Android app declares in its manifest the permissions it might ever want. Guardian ignores that wish-list and instead reads the permissions Android's OS currently has as GRANTED for that app — the actual, present-tense state after you approved (or Android auto-approved) a prompt. That's the number that matters for your actual exposure.

Is it safe to use — does Guardian phone home too?

Yes, and we tell you exactly what it sends: an anonymous install ID, the app version, your Android version, and which feature you used (e.g. "scan completed") — never the domains you browse, never your app list, never scan contents, never your location. Full breakdown at bachao.ai/guardian/privacy — if Guardian's own network monitor shows it phoning home, that page is what you're seeing.

Will this tell me if a specific app is malicious?

No — Guardian isn't an antivirus signature scanner and doesn't claim to identify malware. It gives you the raw signals (root state, patch age, granted permissions, network destinations) that a security-aware person uses to judge risk for themselves. If something looks wrong, that's your cue to investigate or uninstall — Guardian surfaces the evidence, you make the call.

Does rooting or an old patch level mean my phone is already compromised?

Not necessarily — plenty of people root deliberately and safely. But both weaken the protections Android relies on: root removes app sandboxing guarantees, and a stale patch level means known, publicly disclosed vulnerabilities are unpatched on your device. Guardian flags both so you can make an informed decision, not to alarm you.

Know what's actually on, and reaching out from, your phone.

Download the free Android app — hygiene checks, permission audit, and a network monitor you can act on.

Download for Android

Read exactly what Guardian transmits →

Android device security — what to know

Why "granted permissions" matters more than "declared permissions"

Most people check an app's permissions once — at install, in the Play Store listing — and never again. That listing shows what the app might ask for, not what it currently has. Permissions get granted incrementally (a runtime prompt six months after install), inherited across app updates, or left over from a feature you tried once. Guardian re-reads the live, current state from Android's own permission manager for every app on your device, so what you see is what's true right now — not what was true, or theoretically possible, at install time.

What a network egress monitor can and cannot tell you

A network monitor sees connection metadata: source app, destination domain, timestamp, roughly how often. On a modern Android device, virtually all of that traffic is encrypted (TLS), which means the monitor sees the address on the envelope, not the letter inside it. That's still a genuinely useful signal — an app you installed for a flashlight shouldn't be talking to an analytics domain in a country you've never heard of — but it is not content inspection, and any product claiming otherwise over HTTPS is either misrepresenting itself or actively breaking your connection's security to get there, which is a worse outcome than not knowing.

The limits of blocking — read this before you rely on it

Blocking a domain or an app in Guardian changes what happens going forward. It has three real limits worth knowing: (1) a connection the app already had open when you hit block stays open until it naturally closes or the app restarts; (2) Android's DNS cache may already hold a resolved IP for a blocked domain, letting a connection through until that cache entry expires; (3) an app that connects directly to a hardcoded IP address, bypassing DNS entirely, is unaffected by a domain-level block. None of this means blocking is pointless — it's a strong, immediate control for future connections — just don't treat it as an instant, retroactive kill switch.

Security patch age — the number that predicts real risk

Android security patches fix specific, publicly disclosed vulnerabilities — the kind that are documented, sometimes with working exploit code, once the patch ships. A device sitting six or twelve months behind isn't hypothetically at risk; it's running with known, named holes that a patched device doesn't have. Guardian reads your device's reported patch level directly from the OS and shows you the gap in months, plus whether your manufacturer has stopped shipping updates for your model entirely — increasingly common a few years after a phone's release.

For businesses — the same posture engine, at scale

Employee-owned and company-issued Android devices carry the same hygiene, permission, and network-egress risks that Guardian surfaces for consumers — at a scale where a single compromised or badly-configured device can be an entry point into company systems. The same detection engine is available as an API/SDK with a fleet dashboard for BYOD and MDM-adjacent visibility. Book a call to scope a pilot.

Find your vulnerabilitiesStart free scan →