Coming Soon • Spring 2026 (in Beta Testing now!)
Multi-factor mobile security with covert distress signaling, encrypted hidden workspaces, and post-quantum protection — encryption so strong that no known method can break it, even with years of dedicated computing power. Your data never touches our servers—ever.
Built for everyone
We've taken special consideration for the needs of everyone, including:
Core Features
Every security layer you need, built into one app with zero data collection and no connection to any outside server — LockLoom talks only to itself (unless you configure Gmail for SOS media delivery).
Biometric + PIN for device and app unlock. Configure per-app policies supporting fingerprint, face, pattern, and PIN combinations.
Silent SOS from the lock screen via special PIN entry. A brief green dot may appear in the status bar per Android policy. Automatic GPS tracking and evidence capture sent to your emergency contacts.
Choose between XChaCha20-Poly1305, AES-256-GCM, or NSI Encryption — proprietary white-box cryptography with FIPS 140-3 compliance where the key never exists as a whole piece in memory. Each encryption operation uses a unique one-time number (nonce) so the same data never produces the same output twice. Post-quantum ML-KEM-1024 encrypted Secure Vault — meaning no known method can crack it, even with months or years of dedicated server farms working together on nothing but your device's encryption. It's simply not worth anyone's time to try. Your bank accounts, personal files, and anything else inside the protected workspace stay safe.
Hide sensitive apps in an encrypted hidden workspace with a dedicated PIN. 96 bundled cloak icons disguise LockLoom on your home screen and in app folders — so if someone steals your phone while it's unlocked, they see nothing of value, buying you time to remotely lock or power off via codeword message.
Covert front/rear camera photos, audio, and video capture — all without flash, sound, or screen activity. Triggered by distress code or codewords.
USB insertion, SIM removal, and locked-device network isolation. Boot-time radio blocking prevents all data exfiltration before authentication.
Silence WiFi, Airplane Mode, Bluetooth, and NFC with one tap. Per-radio persistence with auto-restore on distress PIN activation. Trade-off: While radios are silenced, incoming codeword messages won't be received — ideal for when you want to go truly off-grid and recharge without disruptions while still using on-device tools like timers, alarms, and timed meditation sessions.
If someone steals your phone while you're using it, borrow any other phone and text your codeword to remotely trigger SOS — tracking the thief's location, capturing their photo, locking the device, or shutting it down. Works from SMS, RCS, WhatsApp, Telegram, Signal, and any notification-sending app. Three-layer detection with SHA-256 dedup.
Optional NFC tag or Bluetooth fob — device locks immediately if absent. Combines with USB blocking and SIM protection for full physical security. (Not yet implemented — coming in a future release.)
🚨 Life Safety
Designed with a zero data exfiltration policy — all SOS alerts go directly to your emergency contacts. No servers. No LockLoom infrastructure involved.
Embed the distress code in any longer credential attempt. The attacker sees a normal "wrong PIN" failure while the SOS beacon launches silently in the background.
15-minute tracking window sends 3 location updates (0, 5, 15 min) to establish direction of travel with GPS coordinates and direct-tap links for both Google Maps and Apple Maps — your emergency contacts can instantly see where you are on either platform.
Covert front and rear camera photos, audio recording, and video capture — all without flash, sound, or screen activity. A brief green dot appears per Android camera/mic policy. Configurable to automatically attach to SOS distress messages sent to your emergency contacts.
SMS dispatched to your emergency contacts (configured inside LockLoom) with location and evidence. Plus Gmail OAuth (a connection you set up yourself to let LockLoom send SOS media to your chosen email contacts) for email alerts — all sent directly from your device with no middleman.
GPS, barometric pressure, speed, heading, altitude, battery, network type, WiFi SSID, cell tower ID, ambient light, and proximity sensor status. Barometric pressure and altitude narrow your phone's location to within a few meters of elevation — in a 100-story building, that's roughly 1–3 floors.
Phone stolen while unlocked? Grab any nearby phone and send your secret codeword via text — LockLoom instantly triggers SOS to track the thief's location, snap their photo, and lock or shut down your device. Works from SMS, RCS, WhatsApp, Telegram, Signal, iMessage bridges, and any notification-sending app.
Getting Started
LockLoom uses Android's Device Owner mode for the strongest possible protection — no root required.
Start with a fresh device or factory reset. On the Android welcome screen, tap "Welcome" 6-7 times to enter provisioning mode.
Scan the LockLoom Device Owner provisioning QR code. Android automatically installs and configures LockLoom as the device administrator.
Set your biometric + PIN policies, configure emergency contacts, choose your distress code, and enable the features you need.
Your device is now hardened with multi-factor authentication, tamper detection, and covert distress capabilities. Zero data leaves your phone unless you configure recipients — and then only what you choose, only to them.
Tiered Pricing
No subscriptions. No recurring fees. No accounts. Every tier is a one-time purchase with lifetime updates.
Competitors charge $10+/month — that's $360 over 3 years.
LockLoom: $0.99 to start. All upgrades one-time. No subscriptions ever.
No Ads. No Data Collection to a backend. No Telemetry to 3rd-party servers.
Your Device. Your Data. Your Security.
Why we do this: We understand the need for you to have security — real security that doesn't come with surveillance strings attached.
What we know about you: We forgot that you existed.
Special Programs (Expected 2027)
We partner with advocacy organizations to distribute free Shield-tier licenses for domestic violence survivors, at-risk journalists, and NGO workers operating under threat. Licenses are distributed through vetted partner organizations — we do not accept direct requests. While App Stores limit the number of promotional codes we can generate each quarter, these advocacy groups can accept donations to procure additional licenses if our quarterly limits are exhausted.
🌍 Internationalization
Full localization with native script display. Regional discounts auto-applied for global accessibility.
Technical Details
| Specification | Details |
|---|---|
| Platforms | Android (production) • iOS (in development) |
| Architecture | Kotlin Multiplatform (KMP) shared core • Jetpack Compose UI |
| Android Mode | Device Owner (strongest protection, no root required) |
| Encryption | XChaCha20-Poly1305 (default) or AES-256-GCM • ML-KEM-1024 post-quantum for Vault (no known method can crack it, even with years of dedicated computing power) |
| Biometrics | Fingerprint • Face • Pattern • PIN • Multi-factor chains |
| Backend | None — LockLoom isn't connected to anything outside of itself. All processing stays on-device. Optional Gmail OAuth for SOS media delivery is the only external connection, and only if you configure it. |
| Data Collection | None — no telemetry, no analytics, no accounts |
| Alert Dispatch | SMS • Gmail OAuth (a connection you set up to let LockLoom send SOS media to your email contacts) • SMTP • Direct to your configured recipients only |
| Codeword Detection | SMS broadcast + ContentObserver + NotificationListener (3-layer) |
| Languages | 144 locales with native script display • Per-app language API |
| Minimum Android | API 33 (Android 13+) • Target API 36 |
| Intended Use | 18+ • Designed for adults |
| Purchase Model | $0.99 entry (First Step tier) • Premium tier upgrades available • No subscriptions |
Documentation
Transparency is fundamental to trust. Read our policies and technical documentation.
LockLoom isn't connected to anything outside of itself — zero data collection, zero tracking, zero backend. Read exactly what LockLoom does (and doesn't) collect.
Full disclosure of all Device Owner capabilities used, when they activate, and how to disable them.
Every permission LockLoom requests, why it's needed, and what happens if you deny it.
Free licenses distributed through advocacy partner organizations for DV survivors, at-risk journalists, and NGOs. Bulk licensing for organizations. (Expected 2027)
Contact us for technical support, free license programs, or bulk organizational pricing.
Scan the Device Owner provisioning QR code on Android 13+ setup screen to install LockLoom.
FAQ
Device Owner is Android's enterprise-grade administration mode that gives LockLoom the deepest possible device protection — including the ability to enforce lock policies, block USB data transfer, control radios, and auto-grant permissions. It requires enrolling during device setup (factory reset) but does not require root access.
No. LockLoom isn't connected to anything outside of LockLoom. There are no servers, no accounts, no analytics, no telemetry, and no crash reporting that leaves your device. The only optional external connection is Gmail OAuth — and only if you configure it yourself for SOS media delivery. All distress alerts go directly from your phone to your emergency contacts via SMS/email. We never see them.
Subscriptions require accounts. Accounts require data. Data is a liability. LockLoom's zero-data-collection promise is incompatible with subscription billing. The app costs $0.99 on Google Play (First Step tier), and optional upgrades to Shield ($49), Sentinel ($99), or Guardian ($119) are one-time in-app purchases. Every payment is lifetime — we forget you exist.
LockLoom includes 96 bundled cloak icons to disguise itself on your home screen and in app folders as a family-friendly app (calculator, weather, game, etc.). If someone grabs your phone while it's unlocked, they see nothing of value — giving you time to borrow any nearby phone and text your codeword to remotely lock, shut down, or trigger SOS. When you trigger a distress code, there are zero visual indicators — no popups, no sounds, no screen changes. The attacker sees a normal authentication failure.
LockLoom is currently production-ready on Android. The iOS version is in active development using Kotlin Multiplatform with a shared core library. The shared security logic, biometric contracts, and distress management are already cross-platform.
Free licenses are distributed through our advocacy partner organizations — we do not accept direct requests. Partner orgs include CPJ, RSF, EFF, Access Now, and qualifying NGOs. These organizations vet applicants and distribute licenses for domestic violence survivors, at-risk journalists, and NGO workers operating under threat. While App Stores limit promotional codes per quarter, our partner organizations can accept donations to procure additional licenses beyond those limits. (Expected 2027)
Your purchase is tied to your Google Play account. Use "Restore Purchase" on your new device after enrolling in Device Owner mode. Since LockLoom stores no data on our servers, your configurations are device-local — you'll need to re-configure security settings on the new device.
Starting at $0.99. Every tier is a one-time purchase. Lifetime updates. Zero data collection.
Get LockLoom on Google Play