On-device enforcement · no root · no account

Something on this phone
is talking. We're listening back.

ENCLAY watches every connection your apps make and silently cuts off the ones headed toward stalkerware, spyware, and malware infrastructure, before the handshake finishes.

This isn't about hiding who you are. It's about stopping what's already on your phone from reporting your data to somewhere it shouldn't.
The threat
"It doesn't look like malware.
It looks like an app someone
installed on purpose,
because someone did."

Stalkerware is not a virus. It's a working product, sold openly, marketed as "parental monitoring" or "employee oversight," and installed by someone with physical access to a device: a partner, an ex, an employer. Once running, it reads messages, tracks location, and in some cases listens through the microphone, then quietly uploads what it finds.

That's exactly why signature-based antivirus mostly misses it. A scanner looks for code that shouldn't be there. Stalkerware isn't malicious code by that definition. It's doing precisely what it was installed to do. Nothing about its file signature looks wrong, because nothing about it is broken. It's working as intended, against the person carrying the phone.

There is one thing every app in this category cannot avoid, no matter how well it hides its icon or renames its process: it has to send what it collects somewhere. That outbound connection (to a command server, a collection endpoint, an operator's dashboard) is the one behavior detection doesn't need to know an app's name to catch.

This is also where ENCLAY draws a hard line around what it's for. It does not make you anonymous. It doesn't hide your IP, mask your identity, or route your traffic through anyone else's server. What it does is refuse to let something already on your device reach whoever it's reporting to: protection against intrusion, not a promise of invisibility.

How it works

Four steps, before every connection is allowed through.

No proxy server, no relay, nothing about the content of your traffic ever leaves the device. The block/allow decision happens locally, in milliseconds.

01

Claim the device's network

ENCLAY runs as a standard Android VpnService: no root, no system modification. Every app's traffic, IPv4 and IPv6 alike, is routed through a local TUN interface that ENCLAY, and only ENCLAY, can see.

02

Inspect at the protocol level

DNS queries, TLS ClientHello/ServerHello handshakes, SNI hostnames, certificate chains. Encrypted DNS (DoH/DoT) is deliberately forced back to plain DNS, so a domain rule can't be silently routed around.

03

Cross-reference against a local threat index

Built from 29 public intelligence feeds plus threat intelligence ENCLAY maintains privately, refreshed every 8 hours and merged into one on-device index. No lookup ever leaves the phone.

04

Decide before the handshake completes

A match is refused with an immediate RST, indistinguishable to the app from the destination simply refusing the connection. Everything else is quietly let through, and logged for you to see.

Capabilities

Everything ENCLAY actually does.

Not a feature list written for a store page. This is the real detection, visibility, and control surface running on-device today.

Detect

IP & domain blocking

76,000+ IPv4 and IPv6 ranges and 1.4M+ domains, merged from public and proprietary feeds into one local index.

JA3 passive fingerprinting

Flags a connection by the exact shape of its own outbound TLS handshake, catching known-bad clients even on an unlisted IP.

JARM active fingerprinting

Opt-in: actively probes a new TLS destination with ten crafted handshakes to identify C2 frameworks like Cobalt Strike or Metasploit by server fingerprint alone.

Encrypted-DNS override

DoH and DoT are forced back to plain UDP:53, so DNS-based evasion can't quietly slip past domain rules.

Country blocking

Refuse all traffic to or from an entire country, enforced against the same on-device GeoIP index used for display.

Known-stalkerware app scan

Cross-references every installed app, by package name and by APK signing certificate, against 646 packages from 158 known commercial stalkerware and monitoring-software vendors. Catches a dormant install with no suspicious traffic yet, and renamed variants that reuse a known vendor's signing key.

Watch

Beaconing detection

Command-and-control clients and most stalkerware "phone home" on a timer, not on demand: check in every few minutes, upload, wait, repeat. ENCLAY watches the interval between an app's connections to the same destination and flags the pattern when it's suspiciously regular, the way a person's real usage rarely is.

app.example → 10.2.4.19  ·  41 connections  ·  every ~4.0 min (σ 0.15)  ·  flagged: regular-interval beaconing

Redirect-chain detection

Clusters a browser's rapid burst of connections to different hosts into one navigation chain, and flags it if any hop led to known-malicious infrastructure. Scoped to actual browser apps, not background app traffic.

Permission-to-network correlation

Flags a new destination that appears within minutes of a sensitive permission grant (camera, microphone, or location), a common signature of data being collected and immediately shipped out.

Live Feed

Every connection, every app, in real time, searchable by host, IP, organization, country, or threat category.

App Profile

Per-app host history, data usage, and connection patterns, isolated from the rest of the device's traffic.

Domain age (RDAP)

Flags infrastructure registered days, not years, ago, one of the more reliable phishing and malware tells.

Reverse DNS & hosting class

Tells you when a destination sits on bare cloud/VPS infrastructure instead of a named, recognizable service.

Certificate inspection

Subject, issuer, expiry, and self-signed detection, read directly from the live TLS handshake.

DNS enrichment

Opt-in: resolves a blocked domain's real IP purely for display, so a DNS-level block still shows a real IP and ASN instead of the meaningless in-tunnel address.

Immediate new-install audit

A newly installed app gets its permission snapshot the moment it lands, not after waiting up to an hour for the periodic scan — no blind spot in that app's permission timeline from minute one.

Control & own your data

USB HID lockdown

A BadUSB attack arrives disguised as a charger or cable, registers itself as a keyboard the instant it's plugged in, then types out commands before anyone can react. ENCLAY watches for exactly that signature: the moment any keyboard- or mouse-class device attaches, every connection already open is severed and all new traffic is blocked, device-wide, in real time, with an alert that stays in the notification shade until it's resumed by hand. Opt-in, since a keyboard plugged in on purpose trips it too.

USB device attached → HID class detected → network locked device-wide → active sessions closed → alert posted

Safety report export

Every detected finding, threat-feed matches, beaconing, permission-to-network correlations, known-stalkerware app matches, exports as one PDF with a single tap: built for handing to a shelter, a lawyer, or law enforcement, not just for your own reading.

One-tap host & app rules

Block or allow any host, app, or country the instant you see it. No separate settings screen required.

Per-app VPN exceptions

Let one app, a banking app that refuses to run under any VPN, bypass the tunnel entirely, without turning protection off for everything else.

Quick Settings tile

Start or stop protection straight from the notification shade. No need to open the app.

Private DNS conflict warning

Flags it up front when Android's strict Private DNS mode would silently break all connectivity the moment protection turns on, before you find out the hard way.

System kill switch

Pairs with Android's own "Block connections without VPN" setting for a true kill switch: if the tunnel ever drops, nothing gets through until it's back, instead of silently failing open.

Quiet hours

Block everything on a schedule: no traffic in or out while the device should be asleep.

Status awareness

A notification confirms protection is active for as long as the firewall runs, and can't be swiped away while it's on. If the tunnel ever drops unexpectedly, you're flagged immediately instead of silently failing open.

CSV export

Take your own connection history with you, per app, whenever you want it.

Local enforcement

No account or cloud dashboard needed to use ENCLAY. Every block/allow decision is made on-device.

In practice

What it actually looks like.

Real screens from a device running ENCLAY, not mockups.

ENCLAY's Live Feed screen showing protection status, packet/session counts, blocked count, and a list of apps with their connections, allowed and blocked, in real time.
Live Feed: every app, every connection, in real time
ENCLAY's Findings screen listing apps with automatically detected issues: threat feed matches and regular-interval beaconing, each with a severity tag.
Findings: threat feed matches and beaconing, surfaced automatically
ENCLAY's Settings screen showing threat intel sync status, DNS block mode, quiet hours, and the opt-in JARM active TLS fingerprint scanning toggle.
Settings: JARM scanning, quiet hours, DNS mode, all visible and toggleable
Per-app profile screen for Google Services Framework showing allowed/blocked counts, data uploaded/downloaded, and a searchable host list with threat category tags.
App Profile: per-app host history and data usage
Connection detail sheet for a single host showing domain age, hosting classification, JA3 and JA3S TLS fingerprints, and certificate subject, issuer, and expiry.
Connection detail: JA3, JA3S, and certificate info for one host
Is & isn't

Said plainly, both ways.

Security tools oversell constantly. Here's exactly what ENCLAY is built to do, and just as deliberately, what it is not.

ISBuilt to stop intrusion: an app on your device reaching out with your data without your knowledge.
IS NOTBuilt to protect your identity. It doesn't anonymize you, mask your IP, or hide who you are from the services you use.
ISA firewall that blocks outbound connections to known-bad infrastructure, by IP, domain, and TLS fingerprint.
IS NOTAn antivirus. It never scans files or app code, and it can't remove an installed app.
ISAble to cut a stalkerware app's connection to whoever is watching through it.
IS NOTAble to safely uninstall that app for you. Doing so can alert an abuser. Cutting its network access, and exporting a safety report as evidence, is the safer first move.
ISEnforcing entirely on-device: the block/allow decision never leaves the phone.
IS NOTA VPN for privacy or anonymity. There's no exit server, and it doesn't hide your IP from sites you visit.
ISBuilt on protocol-level inspection: DNS, TLS handshakes, SNI, certificates.
IS NOTA signature-based malware scanner. Nothing is detected by matching file hashes.
ISA standard Android VpnService: installs and runs with no special access.
IS NOTRoot-requiring, and it never modifies the system or installs a kernel module.
ISAn egress firewall: it governs what your apps are allowed to reach.
IS NOTAn inbound firewall. Phones don't sit on open inbound ports, so there's nothing there to block.
Sources

Every list ENCLAY's index is built from.

Refreshed every 8 hours, categorized, and cross-referenced against a real-world popularity list before anything is trusted enough to block.

Plus proprietary intelligence. Alongside the 29 public feeds below, ENCLAY layers in threat intelligence maintained privately in-house, not publicly listed, refreshed on the same 8-hour cycle.

Abuse & C2 intelligence

  • Spamhaus DROP & DROPv6
  • FireHOL Level 1
  • DShield
  • blocklist.de
  • CINS Army
  • Emerging Threats compromised IPs
  • GreenSnow
  • Feodo Tracker
  • ThreatFox (abuse.ch)
  • URLhaus (abuse.ch)

TLS fingerprints

  • SSLBL JA3 blacklist
  • cedowens / C2-JARM
  • myceliumbroker / jarm
  • JARMGuard (malicious)
  • JARMGuard (ad-trackers)

Phishing

  • OpenPhish
  • PhishTank
  • Phishing.Database (domains)
  • Phishing.Database (IPs)

Ad & tracker blocklists

  • AdAway
  • StevenBlack hosts
  • oisd
  • HaGeZi (light + ultimate)
  • AdGuard DNS filter
  • Disconnect.me
  • developerdan hosts

Stalkerware intelligence

  • AssoEchap stalkerware-indicators (CC BY 4.0)

Geography

  • DB-IP country & ASN data (CC BY 4.0)
29Public sources merged
1.4M+Domains indexed
76,000+IP ranges (IPv4 & IPv6)
8hRefresh cycle
On-device. Always.

Your phone talks to a lot of places. Know which ones, and stop the ones that shouldn't hear from it.

No account to create, nothing to configure before it starts working. Just a firewall that actually reads the traffic it's protecting.