Actinis AOSP Consulting
Services · Professional engagement

Code-level review for your Android platform.

Architecture reviews, security reviews, and bring-up triage for teams shipping Android on custom hardware. We review the code, configuration, logs, and build artifacts behind the issue, then write a report with prioritised findings, reproduction steps, and references.

What we do
// aosp-consulting.md

Architecture reviews covering the full stack — bootloader, kernel, HAL, framework, and app layer — with prioritised findings, reproduction steps, and references to the AOSP commits and vendor docs behind each recommendation.

Security reviews: SELinux policy, verified-boot chain, keystore and attestation behaviour, OTA/update paths, and third-party SDK exposure — scoped to platform risks rather than CTS/VTS pass-fail alone.

Bring-up triage on stuck hardware — kernel, init sequence, HAL, or first-boot regressions — delivered as a short, targeted engagement rather than an open-ended retainer.

Technical due diligence for vendor, SDK, or codebase evaluation: repo reads, risk summaries, and references you can hand to stakeholders.

Who it's for

Fit and scope,
up front

Good fit when
  • Your team owns an AOSP device and needs an outside read on architecture, security, or performance before a release.
  • You are about to ship and need an independent release review focused on platform risks.
  • A new SoC or BSP is blocking a release and you need focused triage, not more headcount.
  • You are evaluating a vendor, SDK, or codebase and need a written technical assessment with references to the reviewed material.
Not a fit when
  • You need a long-term embedded team — see Custom AOSP Development.
  • You want generic mobile-app advice with no platform or device angle — see Mobile App Development.
  • You are looking for broad platform opinions without a concrete product or device in mind. This work is scoped around code, logs, builds, or device behaviour.
How we engage

Clear scope,
documented handoffs

01

Discovery call

A 45-minute scoping call. When you can share it, we review the architecture doc, repo README, or specific ticket before the call. If the work is not a fit, we say that before proposing a scope.

02

Written scope

Within two to three business days: objectives, deliverables, hourly estimate, and a fixed ceiling. You approve or adjust the scope before work starts.

03

Execution with progress pings

We read, test, and reproduce. You get short updates every two to three days with current findings, affected files or components, and open questions.

04

Report and handoff

A written report with prioritised findings, reproduction steps, and references to AOSP, CVE, and vendor documentation. One hour of follow-up Q&A included; remediation is optional and scoped separately.

Where it lands

Where this work lands

01

Pre-launch review

Before an AOSP device ships we read the security posture — SELinux policy, verified-boot chain, keystore, attestation — plus the OTA pipeline. You get a written report with prioritised findings and reproduction steps.

02

Stuck bring-up

When a new board or SoC is blocking a release, we do focused triage: kernel config, init, HAL, first-boot. Written findings with reproduction steps, not an open-ended retainer.

03

Fleet security review

Device-owner posture, verified boot, attestation chain, and third-party SDK triage across a deployed fleet. Output is a prioritised findings list with remediation notes.

Contact

Let's scope your project

Tell us what you're building and where you're stuck. We reply with the scope we think fits, including when a smaller engagement or a different path is better.