Virtual iOS and Android devices for security research, driven by AI agents
Jailbroken virtual iOS devices for security research and rooted Android, hosted in the cloud. AI agents and an MCP server are built in.
Access is reviewed. Authorized security testing only.See an AI agent work a virtual device
An AI agent gets one plain-English task: check how a demo app stores its session. It starts a virtual iPhone from a clean snapshot, installs the app, explores each screen and captures network traffic. Then it maps the app’s local storage, flags a token kept in plain text and drafts a finding with the evidence attached, ready for a human to confirm.
AI agents for iOS and Android, out of the box
No glue code between your agent and the device. The agent does the repetitive work, and you review the evidence and decide.
Agents that operate the device
An agent installs the app, navigates it, inspects what it does and collects evidence as it goes, on a jailbroken or rooted virtual device.
MCP server built in
Connect an MCP-capable client or agent, and the devices show up as tools it can call. Tell us which client you use and we’ll confirm the fit in the demo.
Natural-language scenarios
Describe the goal of a test or a research task in plain English. The agent plans the steps and runs them.
Automated reports
Every run ends with a record of what the agent did and what it found, with the supporting evidence, for a human to review.
Start a jailbroken iOS device from the snapshot "clean". Install demo-app and open every screen you can reach. Capture network traffic while you explore. Check whether the app stores session data unencrypted. Report each finding with the evidence you collected.
Virtual iPhone and Android devices with jailbreak and root
The access you’d get from a research phone on your desk, minus the drawer of phones and the restore loops.
Jailbreak and root
Work on a virtual iPhone with jailbreak or a virtual Android device with root.
Snapshots
Save a device state, restore it in one step, or clone it to try something else from the same point.
Traffic inspection
See the network traffic an app actually sends and receives.
Kernel and app debugging
Debug the app you’re testing, or go down to the kernel.
CI integration
Run the same devices and agent scenarios from your pipeline.
Managed in the cloud
Nothing to install on your Mac, and no SIP or AMFI changes to your own machine.
Built for mobile security research
Virtual devices vs. physical, emulators, and DIY
| Capability | Physical devices | Simulators / emulators | Legacy virtualization platforms | DIY open source | recuritylab |
|---|---|---|---|---|---|
| iOS and Android in one platform | Separate hardware | Separate tools per platform | Varies by vendor | Usually one platform per project | Yes |
| Jailbreak / root access | Depends on device and OS version | Root on some Android images; no iOS jailbreak | Yes | iOS jailbreak, set up by you | Jailbreak on iOS, root on Android |
| Snapshots and cloning | No | Partial | Yes | Manual | Yes |
| AI agents built in | No | IDE coding assistants, not device testing | Not for mobile security (public materials, Oct 2026) | No | Yes |
| MCP server built in | No | IDE-level or third-party servers | Not for mobile devices (public materials, Oct 2026) | Varies by project | Yes |
| Managed, no changes to your own machine | You maintain a device lab | Runs on your workstation | Yes | Needs an Apple Silicon Mac with relaxed SIP/AMFI | Yes, managed cloud |
Every approach above has its place. If you need iOS and Android, jailbreak and root, snapshots and an AI agent on one platform, that’s what we built. If you’re weighing a Corellium alternative, read the full comparison.
See all comparisonsIsolated and secure by design
Your binaries, traffic and findings deserve straight answers, not slogans.
Security and data handlingAn isolated environment per device
Apps, samples and agents run inside virtual devices that you can revert to a clean snapshot or delete, not on a phone you have to scrub by hand.
Data handling, in plain words
Ask what is stored, where, and how it is deleted before you upload a single binary. We go through it with your security team.
Compliance
Bring your security questionnaire to the demo. Our security page explains how we approach isolation and data.
Deployment
Devices run in our managed cloud. If you need something else, tell us about your deployment requirements.
Lawful use only
Every account is reviewed before access is granted, and use is governed by our acceptable use policy.
Frequently asked questions
What is a virtual iOS device, and how is it different from the iOS Simulator?
A virtual iOS device runs iOS itself in a virtual machine, so you can inspect the system the way you would on a jailbroken iPhone: processes, files, network and kernel. The iOS Simulator runs apps built for your Mac on top of simulator frameworks. It’s useful for development, but there is no device kernel to inspect and no jailbreak. For security research, that difference decides what you can actually see.
Can I get a jailbroken iPhone or a rooted Android device?
Yes. Jailbreak on virtual iOS devices and root on virtual Android devices are part of the platform, so you don’t need to hunt for a phone on the right OS version or keep a jailbreak working. We walk through how devices are set up for your work in the demo.
Which iOS and Android versions are supported?
We don’t publish a version list on the site. Tell us which iOS and Android versions your research or test plan depends on when you book a demo, and we’ll tell you plainly whether we can support them today.
Which AI agents or MCP clients can I connect?
The platform includes its own AI agents and an MCP server, so an MCP-capable client can work with the devices as tools. We cover client support and model choices in the demo. Bring the agent setup you use today and we’ll check the fit with you.
Do I need a Mac or any local setup to use virtual iOS devices for security research?
No. The devices run in our managed cloud, so there’s no Apple Silicon Mac to dedicate, no SIP or AMFI changes to your own machine, and no restore loops to babysit. You reach devices over the network with the tools you already use, or through the API and MCP.
Is it legal to use virtual iOS devices for security research?
Virtual iOS research tools have been the subject of litigation in the US, and the law differs between countries. Whether a specific project is lawful depends on what you test, on whose behalf and where. This answer isn’t legal advice: check with your counsel. On our side, every account is reviewed, and use is governed by our acceptable use policy.
How do I get access? Is there a trial?
There’s no self-serve signup and no public pricing. Every account starts with a demo: tell us about your team and your work, we review the request, and we set up access that fits, including an evaluation if you need one. Book a demo.
Book a demo
Virtual iOS and Android devices with AI agents built in, for security research. Access is by request, and every request is reviewed.
Book a demo