The Appdome team attended Black Hat USA in Las Vegas, August 1–6, 2026, announcing two new products: Live Update and Appdome Test™. Beyond these exciting announcements, Black Hat highlighted the differences between how Appdome and the broader cybersecurity industry have approached AI.
It was notable how many vendors at Black Hat seemed focused on defending against AI’s potential by grafting guardrails, governance, and compliance onto frontier models.
In contrast, Appdome’s agentic threat defense model is built around real enterprise context and trained on a decade of mobile defense experience that’s yielded trillions of threat events from hundreds of thousands of live installations globally.
That’s a training set no off-the-shelf model has access to and compounds with every build. The era of agentic software is just beginning and the capabilities we released at Black Hat continue to advance Appdome’s vision of elevating human effort away from implementation and threat response and into defining cyber objectives. As development velocity increases, the need to streamline threat response processes becomes more important to ensure cyber doesn’t become a hurdle to maximizing these new capabilities. Additionally, maintaining the quality of releases across the range of possible environments becomes more complicated.
Our Black Hat announcements attack these constraints:
- Live Update extends Appdome’s build-time protection model into the post-release lifecycle, allowing security teams to update supported protection policies and configurations without requiring engineering to rebuild or republish.
- Appdome Test™ uses that same real-world deployment and device data to test against the devices users actually use.
Let’s dig into each of these announcements and what they unlock for mobile teams.
Live Update: Change Security Policy Without a New Build
Live Update is a new capability that allows security and engineering teams to update security, anti-fraud, and bot-defense policies already running in live, published apps without rebuilding or republishing. Update trust lists, rotate certificates, change a bot-defense profile, or adjust enforcement policies while an attack, fraud campaign, or operational risk is still active.
Today, even a narrow policy change requires engineering resources to produce a new build and carry it through the full development and release process before users adopt it. Live Update lets security teams make that change directly, without engaging engineering, waiting on a release, or going back through app store review.
Customers can use Live Update across four broad areas:
- Configuration: Keys, certificates, pinning, hosts, APIs, and related settings.
- Trust: Approved or blocked domains, endpoints, on-device applications, and threat-triggering conditions.
- Signaling: Device, application, payload, and risk data shared with backend systems.
- Enforcement: In-app actions, messages, data handling, and policy responses.
Live Update changes the configuration of protections already present in the app. It isn’t a code-distribution channel. New code continues through the normal build and release process.
AI-assisted guidance helps teams evaluate potential impact and identify conflicts before deployment; the production workflow remains human-governed. Every Live Update follows a Request-Approve-Deploy workflow, and every submission, approval, rejection, and deployment is captured in Appdome Vault™, the system of record for mobile security and compliance.
Availability: Live Update is available now to Appdome customers licensed for it.
Appdome Test™: Delivering an Accurate Mobile Test Fleet
Most mobile testing begins with a generic device bank, leaving brands to decide which devices and operating systems matter and manually map coverage to their user base. Secured builds are often exported to a separate test infrastructure, disconnecting quality assurance from the protection workflow and the production data that makes results relevant.
Appdome Test™ uses production deployment and device identity data already available in Appdome ThreatScope™ to provision tests that reflect the actual install base, then runs those tests in the same pipeline where the application was protected and signed. It runs inside the Appdome workflow between Sign and Deploy, giving development, DevOps, DevSecOps, and cyber teams a continuous way to verify each protected release before it reaches production.
Across the matched device set, Appdome Test™ supports standard mobile application tests, like:
- First Launch: Fresh install and first-run behavior.
- Warm Start: State restoration, interface rehydration, and session continuity.
- Stress Test: Repeated termination and relaunch to observe stability from a killed state.
- Reinstall Lifecycle: Clean-state initialization across deletion, reinstallation, and launch.
- Upgrade / Update: Data migration, session continuity, and backward compatibility.
Learn more about Appdome for mobile developers.
Frequently Asked Questions
What does Live Update let teams change without a new app release?
Teams can change configuration (keys, certificates, pinning, hosts, APIs), trust (approved or blocked domains, endpoints, on-device applications, threat-triggering conditions), signaling (device, application, payload, and risk data shared with backends), and enforcement (in-app actions, messages, data handling, policy responses). It does not distribute new code or features.
Who approves a Live Update?
Every change follows a Request-Approve-Deploy workflow: one team member submits the change and its reason, a designated approver reviews it, and an authorized administrator deploys it after approval. AI assists evaluation; humans govern the production workflow.
Where does Appdome Test™ get its device data?
Appdome Test pulls from production deployment and device identity data already available in Appdome ThreatScope™ and uses it to provision tests that reflect each brand’s actual install base rather than a generic device bank.
How is Appdome’s approach to AI different from other mobile security vendors?
Most vendors apply external guardrails, governance, and compliance to third-party frontier models. Appdome develops and runs its own cybersecurity AI and ML models, with user context and guardrails built in from the start.



