Security & release integrity

Trust should be checkable.

ChildPhone publishes machine-readable evidence for the software it asks a family to test. These records make review easier; they are not a security certification, emergency-service promise, or approval for a family pilot.

Managed Android0.18.6

Signed binary inventory

The CycloneDX runtime graph is bound to the exact APK and permanent release certificate. Production compares its local and public bytes on every integrity check.

APK SHA-256
c5a401262d2de5ca467e77f2c0b3e0e451d9bb13f1e8bbb9854aade97f215332
SBOM SHA-256
12e0decf33d29ced7d2b487c09767c6236655b62b7814b80765ad861d5cbb7ef
Runtime components
6
Standalone weblock v3

Complete lockfile inventory

Every locked package and dependency edge is recorded. Runtime roots, optional platform alternatives, and build/test-only inputs remain visibly separated.

Lock SHA-256
d667c05efa4471f435702075888f60a16cc4859a7e80b38221c4c082417b62cf
SBOM SHA-256
c52364671b5c6eeb084cb9dca0e8a32958da642a4879ac318a91828937cd30ab
Locked components
728

Web inventory scope

Nothing is hidden in one total.

Counts come directly from the current hash-bound manifest and change only with an intentional lockfile update.

70

Required

Application packages and the Wrangler service runtime closure.

65

Optional

Platform alternatives reached only through optional dependency edges.

593

Excluded

Locked build and test inputs that are not classified as runtime.

What this evidence does not prove

Inventory is a starting point, not a verdict.