STARCRYPT / DOCUMENTATION
Protection that fits your code.
On this page
Starlight Nova 2.0 is the default. SupaCrypt 1.0 goes deeper for Lua and Luau, with a larger runtime cost. Choose by workload, then test in the environment where your code will run.
DEFAULT · ALL PLANSStarlight Nova 2.0
The upgraded protection baseline across 17 language targets. Lua and Luau combine two virtualization passes, encoded data, per-build variation and integrity checks. JavaScript and native languages use their own transformations.
Build with Nova ↗PREMIUM · DIAMOND AND ABOVESupaCrypt 1.0
Three virtualization passes for supported Lua and Luau, with an additional generated execution layer over the Nova baseline. Best considered for small, infrequently executed code where added runtime cost is acceptable.
Check compatibility ↗ What the model names mean
A model identifies a versioned protection preset. It does not mean every language uses the same engine. Nova selects the appropriate engine for your language; SupaCrypt currently supports only Lua and Luau. API identifiers remain nova and supacrypt. Response metadata reports the model name and version used for a build.
Protection by language
| Language family | Nova 2.0 | SupaCrypt 1.0 |
|---|
| Lua 5.1 / supported Luau | Layered VM protection, encoded data, integrity checks and per-build variation | Additional VM layer; higher startup and execution cost |
| JavaScript / TypeScript | AST transformations, encoded string storage and scoped naming; TypeScript produces JavaScript | Not available |
| C++, Python, C#, Go, Rust, Kotlin | Language-specific source protection with input and output syntax checks | Not available |
| Java, PHP, Ruby, C, Dart, Objective-C, Ada | Conservative source transforms without a runtime VM; eligible names and literals vary by language | Not available |
Build integrity
A required protection failure stops the job. StarCrypt does not silently choose a weaker model. Failed builds release reserved credits. Protection runs on our servers, with no external obfuscation API receiving your code.
More virtualization adds overhead. SupaCrypt can be substantially slower than Nova, especially in frequently called modules and loops. Test startup, memory and realistic workloads on your slowest supported device. No measured security multiplier is claimed. Distributed code remains inspectable; keep credentials and sensitive authorization on your server.
Read the release notes · View every language