Overview
An Android app that catches NFC taps via Foreground Dispatch, identifies the chip, parses every NDEF record and runs deterministic URL heuristics before anything opens.
The problem
Phones blindly open whatever an NFC sticker points to. TapTrust inspects the tag first and explains exactly why it is safe or risky.
How it works
NFC stickers on menus, posters and parking meters are cheap to swap, and phones open whatever they point to. TapTrust puts an inspection step in between: it catches the tap before Android or the browser acts on it.
It identifies the chip, parses every record on the tag, then checks the link against clear rules: insecure HTTP, raw IP hosts, odd ports, login-harvesting paths, URL shorteners, lookalike domains and suspicious top-level domains.
The result is a 0–100 risk score where every point is explained, an evidence chain showing how a tag leads to a credential request, and a side-by-side comparison of two tags. Opening the destination is blocked by default, and all analysis happens on the phone.
What it does
- Intercepts NFC taps before the OS opens anything
- Identifies chip type: NTAG213, NTAG215, MIFARE Ultralight and more
- Parses every NDEF record, with hex and ASCII inspectors
- Explainable 0–100 risk score with a point breakdown
- Evidence chain from tag to URL to domain to credential request
- Tag A vs Tag B comparison, demoed with a Flipper Zero
- Offline-first: nothing is sent off the device
Built with
- Kotlin
- Jetpack Compose
- Android NFC
- Flipper Zero
In numbers
Demo tag A scores 08/100 (low risk); tag B scores 87/100 (high risk)
Try it
TapTrust is an Android app, so there is no web demo to open. Android app, no web demo.