← Knowledge base

Android

Android’s Conscrypt module provides platform cryptographic functionality, while applications may bundle another TLS stack. OS and app behavior must be assessed separately.

Evidence to collect

  1. Record the Android build, security updates, and application version.
  2. Identify whether the application uses Conscrypt, a browser stack, or a bundled library.
  3. Use the browser check for one browser connection; it cannot establish the algorithms used by every native application.

Record the scope and result

Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.

Official references

Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.