DoveRunner Mobile App Security for Android · User Guide
Create, manage, and apply localized response messages shown to end users when threats are detected.
| Plan: Enterprise |
| Platform: Android Mobile App Security |
In this article
- About Threat Response Messages
- Where to find the feature
- The 16 supported languages
- Creating a template
- Managing templates (Edit · Duplicate · Delete)
- Viewing template messages (Live Preview)
- Using a template in the Sealing flow
- Bundling a template with a Preset
- Historical Information
- FAQ and important notes
1. About Threat Response Messages
Threat Response Messages are the messages shown to end users when Doverunner AppSecurity detects a security threat (such as a rooted device, emulator, debugger, or app tampering) and decides to respond. By default, the solution provides a set of standard, generic messages in the device language. The Threat Response Messages feature lets you replace those defaults with your own messages, styling, and branding.
Each template is a reusable bundle containing up to three languages. For each language, you can configure:
- Threat messages — the text shown for each detected threat (Root Detection, Debugger Detected, Emulator Detection, App Tampering, Hooking Framework, and others)
- Appearance — button text, button color, button shape, and supported HTML formatting tags inside messages
- Branding — company logo (referenced by Android drawable resource name), dialog title text, and visibility toggles for the title and logo
Why use templates instead of configuring messages per sealing?
Previously, every sealing required filling in error messages from scratch — slow and error-prone for teams that seal multiple builds per week. Templates let you configure once and apply many times, either by selecting the template directly during sealing or by attaching it to a Preset.
Important: This is an opt-in Enterprise feature. If you do nothing, your apps continue to use the solution-provided default messages exactly as they do today. Nothing changes for existing builds, and there is no risk of regression.
At a glance
| Feature name | Threat Response Messages |
| Where to find it | Mobile App Security → Android App Security → Threat Response Messages tab |
| Plan availability | Enterprise only |
| Platform | Android (iOS parity planned) |
| Languages supported | 16 locale codes (de, en, es, fr, id, it, ja, ko, pt, pt_PT, ru, th, tr, vi, zh, zh_TW) |
| Languages per template | Up to 3 |
| Where templates apply | Sealing wizard (Step 5 — Advanced Detection) and Presets |
| Default behavior | If no template is selected, solution-provided default messages are used |
2. Where to find the feature
From the DoveRunner console, navigate to:
Mobile App Security → Android App Security → Threat Response Messages tab
The tab sits alongside
- Apply AppSealing — the sealing wizard where you upload an APK or AAB and seal it
- Preset — reusable sealing configurations that can bundle a template
- Historical Information — audit trail of past sealings, including which template was used
- App Configuration, Manage Keystore — other Android security settings
Don’t see the tab?
The Threat Response Messages tab is visible only for accounts on the Enterprise plan. If your organization is on a different plan and you would like to evaluate this feature, contact your DoveRunner account manager or reach out through the in-product Help menu.
3. The 16 supported languages
Each template can configure up to three languages, drawn from the 16 locale codes supported by the AppSecurity runtime. Languages are identified by locale codes, not country names — this avoids confusion in regions where multiple variants might exist. For example, German (de) applies to German speakers in Germany, Austria, and Switzerland alike, while Portuguese is split into Brazilian (pt) and European (pt_PT) variants because the backend supports both.
| Locale code | Language | Notes |
|---|---|---|
de |
German | |
en |
English | Used as fallback if a selected language is unavailable on the device |
es |
Spanish | |
fr |
French | |
id |
Indonesian | |
it |
Italian | |
ja |
Japanese | |
ko |
Korean | |
pt |
Portuguese (Brazil) | |
pt_PT |
Portuguese (Portugal) | |
ru |
Russian | |
th |
Thai | |
tr |
Turkish | |
vi |
Vietnamese | |
zh |
Chinese (Simplified) | |
zh_TW |
Chinese (Traditional) |
Why a 3-language limit?
The limit keeps templates focused and manageable. In practice, most apps target a small set of priority markets, and message quality (translation accuracy, tone, length) suffers when teams stretch a single template across too many locales. If you need more than three, create multiple templates — one per market or product line — and apply them through different Presets.
4. Creating a template
Follow these steps to create your first template.
| 1 | Open the Threat Response Messages tab |
| Navigate to Mobile App Security → Android App Security → Threat Response Messages. You will see a table of existing templates (system + custom) and a + New Template button at the top-right. |
| 2 | Click + New Template |
| A new untitled template opens in the editor. Give it a descriptive name (for example, “Banking — Production” or “Gaming — Asia rollout”) and an optional description. Both can be edited later. |
| 3 | Add up to three languages |
In the left panel, use the + Add language dropdown to select a locale (for example, en, ja, zh_TW). You can add up to three. Click an added language to switch the editor to that language. |
| 4 | Configure messages and appearance |
|
In the Messages & Appearance tab you can configure:
|
| 5 | Configure branding |
|
In the Branding tab:
|
| 6 | Save the template |
| Click Save Template in the editor header. The template appears in the Threat Response Messages list and is immediately available for selection during sealing or inside a Preset. |
HTML formatting in messages
You can use a small set of HTML tags inside any message to style the text shown to end users.
Supported: <b> <i> <u> <br> <font color="#…"> <big> <small>
Not supported: animations, clickable links, custom CSS, and JavaScript. These will be stripped before display.
5. Managing templates (Edit · Duplicate · Delete)
The Threat Response Messages list supports the following actions for each row.
| Action | Icon | What it does |
|---|---|---|
| View messages | Opens a read-only preview of the template, including messages for each configured language and branding settings. Useful before applying it to a sealing. | |
| Edit | Opens the template in the editor. Change name, description, languages, messages, appearance, and branding. Changes apply to future sealings, not past ones. | |
| Duplicate | Creates a copy of the template with “ (Copy)” appended to the name. The duplicate is a custom template and can be edited freely. | |
| Delete | Permanently removes the template. System templates cannot be deleted. Past sealings that used the template are unaffected — they continue to reference its messages through Historical Information. |
System vs. Custom templates
Templates are tagged in the list:
- System— a default template provided by DoveRunner. Can be viewed, duplicated, and used as-is, but cannot be edited or deleted. The “Default Security Template” is a System template.
- Custom— a template you or another user in your organization created. All actions (view, edit, duplicate, delete) are available.
Editing a template that is in use
Editing a template affects future sealings, not past ones. If a sealing was completed with version A of a template, and you later edit the template to version B, builds already in production continue to ship version A. Only sealings performed after the edit pick up version B.
To preserve a known-good template, duplicate it before making experimental changes — keep the original as a safe fallback.
6. Viewing template messages (Live Preview)
Three different places in the console let you open a View Messages preview before committing to a template:
- From the Threat Response Messages list — click the 👁 icon in any row.
- From the Apply AppSealing wizard, Step 5 — after turning on the opt-in toggle and selecting a template, the template card shows a View Messages button.
- From the Preset drawer — after attaching a template to the preset, the preview card includes a View Messages button.
The View Messages dialog shows:
- Language tabs — one tab per configured language. Switch between them to inspect each locale.
- Branding & Appearance summary — the dialog title text, button text, logo resource name, and button color preview.
- Threat messages — every threat-detection message grouped by category (Device Security, App Integrity, Runtime Protection, Data Protection), with a Customized or Default badge so you can see at a glance which messages have been tailored.
Read-only by design
The View Messages dialog is intentionally read-only. To make changes, close the dialog and click Edit on the template (or open it from the Threat Response Messages tab). This separation prevents accidental edits when you only meant to confirm what the template contains.
7. Using a template in the Sealing flow
Threat Response Messages are applied during Step 5 — Advanced Detection of the Apply AppSealing wizard. The feature is opt-in: by default, the solution-provided messages are used. To customize, follow these steps.
| 1 | Open the Apply AppSealing wizard |
| Upload your APK or AAB and step through the wizard as you do today. Steps 1 through 4 are unchanged. |
| 2 | Reach Step 5 — Advanced Detection |
| You will see the existing settings (Screen Mirroring & Capture, Data Sealing, Over the Air Update) followed by a new card titled Customize Threat Response Messages marked with an ENTERPRISE badge. |
| 3 | Turn on the opt-in toggle |
| By default the toggle is off and an information note explains that the solution-provided default messages will be used. Turn the toggle on to reveal the template selector. |
| 4 | Select a template |
| Choose a template from the dropdown. A summary card appears with the template name, configured languages, count of customized messages, and last-updated date. Click View Messages to verify the contents. |
| 5 | Complete the sealing |
| Click START APPSEALING in the right panel. The sealed build will use the selected template for any threat responses shown to end users. The selection is recorded in Historical Information for audit. |
Don’t want to customize for this build?
Leave the opt-in toggle off. The sealing proceeds exactly as it does today, with solution-provided default messages. There is no functional difference between an opted-out enterprise customer and a non-enterprise customer for this feature.
8. Bundling a template with a Preset
Presets bundle sealing configuration for reuse. If your team seals the same kind of app frequently — for example, multiple builds of a banking app, or weekly QA releases — attaching a template to a Preset removes a step from every sealing.
How it works
- Open the Preset tab and create a new preset (or edit an existing one).
- Inside the preset drawer, find the Customize Threat Response Messages card. It uses the same opt-in toggle pattern as Step 5.
- Turn the toggle on, choose a template, and save the preset.
- When that preset is selected in the wizard right panel during a sealing, Step 5 automatically opens with the template applied. You can still override the choice at the moment of sealing if needed.
What you’ll see in the Preset list
The Preset table includes a Threat Response Message Template column. For each preset you will see one of two states:
- Banking — Production Template name pill (purple) — the preset has an attached template.
- Default messages (grey) — no template is attached. Sealings using this preset will show the solution-provided defaults.
Override at sealing time
The template chosen by a Preset is a default, not a lock. During an individual sealing, you can switch to a different template (or turn the opt-in off entirely) in Step 5 without modifying the underlying Preset. This is useful for one-off builds that need a different message set without changing the team’s standard configuration.
9. Historical Information
Every sealed build is recorded in the Historical Information tab. Each entry shows the timestamp, package name, user, AppSealing version, and completion status. Clicking a row expands a detail panel with two sections — Service Version and Creation Information.
The Threat Response Messages field
Inside Creation Information, the Threat Response Messages field captures which template was applied to that specific sealing:
- Template name — if the build was sealed with the opt-in turned on and a template selected, the template name is shown in plain text.
-
NA — if the build was sealed with the opt-in turned off, with no template attached, or before this feature existed in the platform, the field shows
NAin muted grey.
Audit and compliance
Because the field is part of Historical Information, every sealing has a permanent record of which threat response messages were active when it was sealed. This is useful for compliance audits, customer support escalations, and reproducing user-reported behavior from production builds.
Note: Editing or deleting a template after a sealing does not change the Historical Information record. The historical entry continues to reference the template name as it stood at the time of sealing.
10. FAQ and important notes
Is this feature available on all plans?
No. Threat Response Messages is an Enterprise-only feature. If your account is on a different plan, the Customize Threat Response Messages card in Step 5 is disabled, and the Preset drawer does not show the template-selection section. The solution-provided default messages continue to be used.
Does this change anything for my existing builds?
No. Existing builds are unaffected, and new builds without an explicit opt-in continue to use solution-provided default messages. The feature is fully additive.
Can I import or export templates?
Templates live inside the DoveRunner console and can be duplicated within your organization. Cross-organization import/export is on the roadmap; reach out through the in-product Help menu if this is important to your workflow.
What happens if a user’s device language isn’t in my template?
The English (en) variant is used as the fallback. If en is not configured in the template, the solution-provided default messages for the device language are used.
Can I preview what the dialog will look like on a real device?
A live in-editor preview shows the dialog as it will appear, including button color, dialog title visibility, message text, and basic typography. The preview is approximate — final rendering depends on the device, OS version, and active accessibility settings.
What HTML tags are supported in messages?
Inline formatting only: <b>, <i>, <u>, <br>, <font color="#…">, <big>, <small>. Animations, clickable links, custom CSS, and JavaScript are not supported and will be stripped.
Is iOS supported?
Android is the initial target. iOS parity is planned in a follow-up release; the data model is shared, so templates created today will be reusable on iOS once support lands.
Need help?
For product questions, reach out through the in-product Help menu (the ? icon in the top bar) or visit https://docs.doverunner.com.
For Enterprise plan questions or to request access to this feature, contact your DoveRunner account manager.