Reshape the control flow.
Turn straightforward branches into a less direct execution path. Apply flattening and flow transformations to the code each engine supports.
CONTROL-FLOW TRANSFORMATIONYour most valuable logic ships with your application. Make it harder to reconstruct, with layered protection and behavior checks built into the engineering process.
Find your engine Explore the verification approach// A small method with a clear intention.
private static int CalculateScore(
int points, int bonus)
{
return unchecked(points + bonus);
}private static int x7(int a, int b)
{
int r = 0, s = 0x21;
while (true)
{
switch (s ^ 0x5A)
{
case 0x7B:
r = unchecked((a ^ b) + ((a & b) << 1));
s = 0x4D; break;
case 0x17: return r;
}
}
}// The same small piece of business logic.
int calculateScore(int points, int bonus) {
return points + bonus;
}int _a7(int a, int b) {
var s = 0x36, r = 0;
while (true) {
switch (s ^ 0x2F) {
case 0x19:
r = a + b;
s = 0x4C;
break;
case 0x63:
return r;
default:
throw StateError('unreachable');
}
}
}A readable illustration of transformation techniques, not captured engine output. The sample comparison evaluates browser equivalents; it does not run either protection engine.
01 / THE PROTECTION STACK
Names are only the surface. Put more distance between the software you distribute and the logic someone can recover from it.
Turn straightforward branches into a less direct execution path. Apply flattening and flow transformations to the code each engine supports.
CONTROL-FLOW TRANSFORMATIONVirtualize selected methods instead of exposing their original instruction sequence. Choose the boundary deliberately: supported constructs and execution costs differ by engine.
SELECTIVE VIRTUALIZATIONLayer renaming, string protection and constant hiding. Add mixed Boolean-arithmetic transformations in .NET to obscure familiar expressions.
NAMES / STRINGS / CONSTANTSSpecify which methods must receive protection. Inspect what applied, what was preserved and why a required transformation could not proceed.
EXPLICIT PROTECTION CONTRACTS02 / CHOOSE YOUR ENGINE
One standard for protecting valuable logic.
Two engines that respect different runtimes.
Transform selected .NET IL with control-flow protection, virtualization and arithmetic obfuscation. Make JIT verification and sampled original-versus-protected comparisons part of your build.
Target and construct support are explicit. Native protection is Android-specific; AOT compatibility is assessed for your application.
dotnet build -c Release /p:ControlFlowVerify=true /p:ControlFlowReference=trueWith ControlFlow's build integration installed. Early access uses a private feed or source checkout.
Protect selected Dart logic with an isolated, SDK-matched Kernel engine. Combine eligible flow transformations with string and constant obfuscation, coverage contracts and an opt-in VM for a restricted subset.
Per-function behavioral equivalence is in development. Host AOT checks do not establish mobile or Web qualification.
controlflow init
controlflow doctor --config controlflow.yaml --release --jsonWith the local CLI installed. Doctor checks prerequisites; protection and package qualification are separate steps.
03 / THE CONTROLFLOW STANDARD
A transformed binary is the beginning. Our shared direction connects the code you protect to the behavior you test and the release you deliver.
referencecandidateExplicit coverage contracts make missing required protection a build failure, with reasons you can act on.
Compare original and protected executions within declared input and observation limits. Keep failures and incomplete checks visible.
The roadmap brings exact-build evidence, target-runtime scenarios and private diagnostics into a coherent release workflow.
.NET provides bounded method-level checks today. Flutter is expanding per-function equivalence. Unified release qualification is part of the product roadmap; evidence always has a defined scope.
See the direction04 / AN INFORMED CHOICE
Protection depth matters. So do integration, diagnostics and the way a tool helps you validate its output.
| Product | Protection model | Documented workflow | Reference |
|---|---|---|---|
| ControlFlow.NetEARLY ACCESS | IL transformations, selected-method VM, renaming, strings and arithmetic obfuscation. | Required method coverage; JIT and sampled A/B checks. Unified release qualification is planned. | Our direction ↗ |
| Babel Obfuscator | Renaming, strings, control flow and VM-based code encryption. | Documented MAUI integration and application testing. VM code encryption excludes MAUI and Blazor. | MAUI guide ↗VM scope ↗ |
| Dotfuscator | Renaming, control-flow obfuscation, string encryption and runtime checks. | Protection for .NET, MAUI, Blazor and Xamarin. Guidance covers testing normal and detected runtime conditions. | Protection guide ↗ |
| .NET Reactor | Renaming, strings, control-flow obfuscation and code virtualization. | Vendor-documented protection options and a stack-trace deobfuscator for diagnostics. | Feature reference ↗ |
| Product | Protection model | Documented workflow | Reference |
|---|---|---|---|
| ControlFlow.FlutterTECHNICAL PREVIEW | Source/Kernel transformations, constant and string obfuscation, eligible flattening and restricted opt-in VM. | Reference checks, coverage requirements and locally qualified Android release paths. Broader per-function equivalence is in development. | Our direction ↗ |
| Flutter built-inSDK BASELINE | Dart symbol renaming for supported native release targets. Resource encryption is outside its documented scope. | Keep symbol information and maps for crash decoding with Flutter's symbolication tools. | Flutter guide ↗ |
Official sources reviewed 7 October 2026. Capabilities vary by edition and target. This compares documented approaches, not independently measured protection strength; omitted features are not claims of absence.
Our focus: protection you can inspect, behavior you can compare, releases you can trace.
05 / THE ROAD AHEAD
We're building toward a connected protection and verification workflow across .NET and Flutter.
This is the product direction. Availability is specific to each engine; future work is not a release commitment or delivery date.
Help shape it with your applicationExpand typed input generation, supported state observations and minimum-case contracts. .NET's method checks are a foundation; Flutter's per-function equivalence is in development.
Bind target-runtime scenarios, toolchain identity and artifact hashes into one release record. Flutter has scoped Android paths; the integrated .NET workflow is planned.
Bring private, immutable build-bound archives to .NET. Expand Flutter's locally qualified Android archives to broader targets. Provider integration remains future work.
Develop clearer preflight guidance, final-package privacy audits and representative performance budgets. Build on existing checks with explicit limits and actionable reports.
06 / ENGINEERING QUESTIONS
LET'S TALK ABOUT YOUR BUILD
Bring a target platform and a piece of logic worth protecting. We'll start with scope, integration and what a useful evaluation needs to establish.
A high-level description is enough. Keep source code, credentials and signing keys private.
To make changes, edit the fields above and prepare the draft again.
A straightforward read.