Some of these differences are Apple platform constraints that no engineering on our
side would change. Others are gaps in our own iOS sensor, which is at an earlier stage
than the Android one. The distinction matters when you are reasoning about what an
absence of findings means, so it is stated per row.
| Observation | Android | iOS |
| Installed application inventory | Full inventory, with install source, signing details and usage timeline | Not available — iOS provides no mechanism for it |
| Permissions held by applications | Recorded, including which are granted and which are sensitive | Not available |
| Device security posture | Lock-screen state, VPN and proxy configuration, indications of rooting | Not available |
| Name resolution — queries | Recorded | Recorded |
| Name resolution — answers | Recorded | Not currently recorded — a gap in our iOS sensor, not a platform restriction |
| Network flows | Recorded, with directional byte counts | Recorded, with directional byte counts and per-flow packet counts |
| Encrypted-session fingerprinting | Recorded in the fuller collection mode | Not available |
| Per-application attribution | Partial | Not available — an Apple platform constraint |
| Indicator matching on the device | Supported, against signed indicator packages | Not available — matching happens at the Lab Station |
| Export integrity | Export carries a per-file hash manifest | Export is signed on the device using its hardware secure element |
| Unattended collection | Continues automatically once a session is started | Not supported — every session is started and stopped on the device |