SafeHaven-Store

Introduction: Open-Source alternative app store for Android aimed to provide a secure Google Play alternative, offering verified, open-source apps with built-in malware protection.
More: Author   ReportBugs   OfficialWebsite   
Tags:

SafeHaven logo

SafeHaven

Want a specific app on SafeHaven? Submit it here!

Submit an app you've found

Or if you are a developer:

Submit your own app

Where open Android apps belong.

SafeHaven is an Android app store that is focused on trust, source visibility, and very clear app metadata. Apps can be linked to their source repositories, verified against developer ownership, scanned before release, and rechecked after being made available.

Release Downloads License

Buy me a coffee

What is SafeHaven?

SafeHaven is an Android app distribution platform built around transparency. Instead of using the 'trust me bro' methology, SafeHaven aims to show where the app comes from, whether the source has been verified, and if it has passed all malware checks.

Trust layers

Layer What it does
Source linked Apps can include a public source repository.
Verified Source The developer proves control of the linked repository by adding a .safehaven file in their repo during setup.
Unverified listings Community/imported apps can be listed without claiming developer ownership.
APK scanning Submitted APKs are scanned before being approved.
Rechecks Apps can be rescanned after release to keep metadata fresh.

Screenshots

SafeHaven home screen SafeHaven app details
SafeHaven categories SafeHaven security signals

App submissions

  • Developers can register and manage their apps. SafeHaven checks submitted APKs through its scan pipeline before they become available in the public catalog.
  • Community/imported listings are kept separate from verified developer listings.

Want to suggest an app? Use the App Suggestions discussion.

Repository structure

Area What it contains
Android client Store browsing, app pages, install flow, and UI.
Store logic Catalog parsing, categories, app metadata, and listing display.
server_code Backend/store server code for submissions, scanning, storage, and catalog generation.

APK signature verification

Official Android APKs published by ColourSwift are signed with the following certificate:

SHA-256: 9c67f4224888f60e093cf7eab9b194e6d4cd73bb11313638c47b17f0d5f34ec4

You can also verify a downloaded APK with the Android SDK Build Tools command:

apksigner verify --print-certs app-arm64-v8a-release.apk

Building the app

Make sure Flutter is installed, then run:

flutter pub get
flutter run

For a release APK:

flutter build apk --release

For an app bundle:

flutter build appbundle --release

Current status

SafeHaven is still in early development.

How 'safe' is SafeHaven

Nobody can claim to be perfectly safe. However, SafeHaven leverages commercial security software in the live build to ensure malware doesnt slip through. Along with the work in progress BEP (build evaluation process), to ensure apps riddled with ads and trackers remain off the store.

Discord

Licence

MIT

Apps
About Me
GitHub: Trinea
Facebook: Dev Tools
AI Daily Digest