Fintech Security

A comprehensive, production-ready security plugin for Flutter applications. It provides robust protection against common security threats like Root/Jailbreak detection, VPN usage, Screen Recording, Mirroring, Casting, Developer Mode, and Emulators.

Features

  • Root/Jailbreak Detection: Detects if the device has been rooted (Android) or jailbroken (iOS).
  • VPN Detection: Identifies active VPN connections to prevent geo-spoofing or traffic interception.
  • Screen Protection:
    • Prevents screenshots and screen recordings using the Secure Flag.
    • Detects active screen recording, mirroring, or casting sessions.
  • Environment Integrity:
    • Detects if the app is running on an Emulator.
    • Identifies if Developer Mode (Android) is enabled.
    • Detects Accessibility Services that might be used for malicious automation or overlay attacks.
  • Flexible Controls: Ability to enable/disable specific checks based on build modes (e.g., Debug vs. Release).
  • Easy Integration: Provides a SecurityBlocker widget and SecurityDialog for quick, out-of-the-box UI protection.

Installation

Add fintech_security to your pubspec.yaml:

dependencies:
  fintech_security: ^1.0.2

Usage

1. Initialize the Security Guard

It is recommended to initialize SecurityGuard early in your app lifecycle. You can listen to events even before initialization to catch initial security checks.

import 'package:fintech_security/fintech_security.dart';
import 'package:flutter/foundation.dart';

Future<void> initSecurity() async {
  // 1. Listen to events early
  SecurityGuard.instance.onSecurityEvent.listen((event) {
    print("Security Event: ${event.type} - ${event.message}");
  });

  // 2. Initialize with environment-aware configuration
  await SecurityGuard.instance.init(
    SecurityConfig(
      enableRootCheck: true,
      enableVPNCheck: true,
      enableScreenRecCheck: true,
      enableSecureFlag: true,
      enableCastingCheck: true,
      enableMirroringCheck: true,
      enableAccessibilityCheck: true,
      // Disable these checks in debug mode for developer convenience
      enableEmulatorCheck: !kDebugMode,
      enableDevModeCheck: !kDebugMode,
    ),
  );
}

2. Protect Your UI with SecurityBlocker

The SecurityBlocker can be wrapped around your MaterialApp using the builder property. This ensures the protection covers the entire application regardless of the navigation state.

MaterialApp(
  // ... other properties
  builder: (context, child) {
    return SecurityBlocker(
      blockingEvents: const [
        SecurityEventType.rootDetected,
        SecurityEventType.vpnDetected,
        SecurityEventType.emulatorDetected,
        SecurityEventType.devModeDetected,
        SecurityEventType.screenRecordingDetected,
        SecurityEventType.mirroringDetected,
        SecurityEventType.castingDetected,
        SecurityEventType.accessibilityDetected,
      ],
      blockerBuilder: (context, event) {
        return SecurityDialog(
          event: event,
          canPop: false, // Prevent dismissing the dialog for critical threats
          primaryColor: Colors.blue, // Customize to match your theme
        );
      },
      child: child!,
    );
  },
  home: const MyHomePage(),
);

Security Event Types

The following events can be detected and handled:

  • rootDetected: Device is rooted or jailbroken.
  • vpnDetected: An active VPN connection is detected.
  • emulatorDetected: App is running on an emulator.
  • devModeDetected: Developer Mode/Options is enabled (Android).
  • screenRecordingDetected: Screen is being recorded.
  • mirroringDetected: Screen is being mirrored.
  • castingDetected: Screen is being cast to another device.
  • accessibilityDetected: Potentially dangerous accessibility services are enabled.

License

This project is licensed under the MIT License - see the LICENSE file for details.