LiveBirdify is live for Flutter and React Native. Start free with 2,000 patch installs a monthStart free on Flutter & React Native
Security model

Signed, verified and reversible by default.

Shipping code over the air shouldn't mean trusting it blindly. Every Birdify bundle is cryptographically signed, verified on the device before it runs, and revertible in one command, and no native code is ever downloaded.

  • Signed bundles
  • No native code
  • Fail-open rollback
  • Self-hostable
›_on device
fetch bundle → patch #3 (4.2 MB)verify sha256 … ok 9f2c…a71bverify signature … ok key birdify:shop_appapply on next launch ✓

Verified on the device

Bundles are signed with your project key at publish time and delivered over TLS 1.3. Before applying an update, the SDK re-computes its SHA-256 checksum and checks the signature; anything that doesn't match is dropped, and the app keeps the last good bundle.

  • TLS 1.3
  • Ed25519 signature
  • SHA-256
patch #3withheld
patch #2live · restored
↩ fleet reverting to #2

Fail-open rollback

A patch that fails to boot auto-reverts on device, and one command pulls it from the whole fleet. Broken updates never strand your users.

How rollback works
Encrypted transport
TLS 1.3
Per-project keys
Scoped
Self-hosting
Supported

Access and delivery

Publishing is scoped per project and gated by API keys you control. Bundles are served from edge storage over encrypted transport, and you can self-host so they never leave your infrastructure.

›_birdify verify
$ birdify verify patch#3 checksum 9f2c…a71b signer birdify:shop_app signature valid ✓ native code none safe to apply ✓

Signed at publish time

Every release and patch is signed the moment it's cut. Verify any artifact yourself, the same check the SDK runs on device before it applies an update.

Read the full security model

The docs walk through signing, on-device verification, the rollback state machine, and how to run Birdify self-hosted, with the exact commands.

Read the security docs
Security FAQs

Questions about trust.

How signing, verification and rollback work, and where Birdify stands on compliance.

Still have a question?Talk to the people who build it

No. Birdify only pushes managed bundles, Dart for Flutter and the JS bundle for React Native, and a Server-Driven-UI description for the native iOS and native Android runtimes in development. No compiled native binaries are ever downloaded or executed, which is exactly what keeps over-the-air updates within App Store and Play Store policy.

Ship updates your users get instantly.

Install the CLI and start shipping over the air on Flutter and React Native. No rebuilds, no store review, no waiting.

2,000 patch installs a month free · no card

$curl -fsSL https://cli.birdify.dev/install.sh | sh

Read the docsTalk to the team