See what the device
won't show you.
Ansteroid builds observation instruments for the mobile edge — precise, deterministic tooling that reveals what an app is really doing, and what a user is really choosing. Two instruments, one discipline: watch the layers others can't reach.
The behaviour that matters is the behaviour you can't see.
On a modern phone, the decisive moment happens out of sight — deep inside a running app, or fleeting on a screen you don't control. Each Ansteroid instrument closes one of those blind spots.
Threats don't sit on the surface anymore.
Modern Android threats load code at runtime, execute inside native libraries, and cross into the system through JNI — where permission audits, static scanners and emulator-based tools cannot follow. The behaviour that matters happens while the app is running, and most tooling never sees it.
The moment passes before you can respond.
A customer choosing, a victim being coerced, an account being taken over — it happens inside an app you don't own, and it's gone in seconds. Adding an SDK means changing the app; interrupting the user breaks the flow; server logs arrive too late. The signal is right there on the device, and nothing safe is listening for it.
One brand, two vantage points on the same device.
FA³ looks inside — down through every runtime layer of an Android app. Outsight looks beside — reading the CPU's side channel to know what a user chose, without ever touching the app.
FA³ Fine-Grained Android Application Analysis
Deterministic, on-device runtime tracing across Java · ART · JNI · Native — no emulator, no root, no app modification.
Outsight External Side-Channel Action Detection
Real-time, consent-based insight into in-app user actions from outside the app — reported as a plain-language, timestamped label.
The same discipline under both products.
FA³ and Outsight look at different things — but they're built on the same four commitments. It's what makes either one credible in front of an agency or a bank.
Born in a university lab. Trusted at agency scale.
The engineering is public where it can be.
Ansteroid's methods are grounded in peer-reviewed research from SMU. The public record below is a starting point — deeper technical material is shared under NDA.
What is this app actually
doing on the device?
FA³ answers that question deterministically — by tracing a real app on a real handset, all the way down. No emulator. No root. No modification to the app under test. Every layer, every call, reconstructed.
The apps people trust are leaking.
Independent analysis of mobile financial apps keeps surfacing the same gaps — the kind only device-level tracing reveals.
Static analysis stops at the waterline. FA³ doesn't.
An Android app runs across four layers. Most tools see one or two — the visible tip. FA³ instruments every layer, from managed Java down to native code, on the live device.
Five properties, always together.
None of these is remarkable alone. Held as a set, on an unrooted retail handset, they're what makes FA³ different.
// FA³ is deterministic — it is not an AI/ML classifier.
Four steps, one deterministic trace.
Deployed where the stakes are real.
See FA³ trace a live app.
Bring an app you're curious about. We'll run it on a real handset and show you what it does underneath.
Know what your customer chose —
before they're done choosing.
Outsight reads the device's own CPU side channel to detect what a user is doing inside another app — in real time, with no app modification and no root. It's the one-way mirror: you see the choice, the app never changes.
Observe the action. Never touch the app.
On one side, an ordinary app running on an ordinary unrooted phone. On the other, Outsight — turning micro-patterns in CPU behaviour into a clear, timestamped account of what just happened.
Insight on one side, protection on the other.
Think of a one-way mirror. One party can see clearly; the other is shielded, and both know the arrangement and have agreed to it. That is how Outsight works. It reveals the action a user has taken so a business can respond in the moment — while the user's data, credentials and content stay on their side of the glass. This is consent-based insight, established and disclosed up front. It is not surveillance, and it is not covert.
Observed from the outside.
Outsight runs in the background on Android and detects the actions a user takes inside another app. There is no change to the target app: no SDK, no code modification, no root. Each detected action is reported as a timestamped, plain-language label, and fires a phone notification immediately — so nothing has to stay open for the signal to arrive.
The decisive moment is over in seconds.
Fraud, coercion and account takeover don't announce themselves in a report — they happen live, inside an app, and are gone. Value comes from seeing the action while it's still unfolding.
Not just which screen — which choice within it.
Which screen the user is on
Detects context — e.g. the "Add Card" flow has begun.
Which option they picked within it
Distinguishes stored value from Credit/Debit from a bank transfer — the choice, not just the page.
Four steps, from signal to label.
One signal, many jobs to be done.
The same consent-based, real-time action signal supports very different outcomes — from serving a customer better to stopping harm before it lands.
Shown working on a live, unmodified consumer app, on a real, unrooted device — detecting the in-app choice with no changes to the app and no root access.
See if there's a fit.
Outsight is research from SMU and Ansteroid. If it maps to something you're building, we'd like to talk.
The record, where it's public.
Ansteroid grew out of peer-reviewed work at SMU. This page collects the public-facing research; classified and commercial detail is shared separately under NDA.
A university lab that ships.
Ansteroid is a research spin-out from SMU's Centre on Security, Mobile Applications and Cryptography — turning deep mobile-security research into instruments that agencies and enterprises can actually deploy.
Research first, engineered for the field.
The Centre on Security, Mobile Applications and Cryptography (SMC) at Singapore Management University studies how mobile software really behaves — below the interface, below the runtime. FA³ and Outsight are that research made operational.
We work at the layer most tools skip: the live device. That's a deliberate choice, and it's why our instruments hold up in front of the people who rely on them.
The people behind the instruments.
Led by our Principal Investigator, with research engineers building on the device and commercialisation taking it to market.
Start a conversation.
For briefings, evaluations, or research enquiries about FA³ and Outsight, reach the team directly. We respond to qualified agency and enterprise enquiries.
10 Canning Rise, Level B2,
Singapore 179873.
Email the team directly. To help us route your enquiry, it helps to include:
- Your organisation and role
- Which instrument — FA³, Outsight, or research collaboration
- What you are evaluating, and any timeline
Enquiries go straight to the research team — no ticketing system in between.