Help with Nemesis Labs products.
Every request below reaches a human. We answer within two business days, and usually the same day. There is no phone queue and no chatbot in front of us.
1. Nemesis Blue for iPhone and Android
What the app does
Nemesis Blue on mobile checks the security posture of your own device and reports threats it finds. It looks for signs that the device has been jailbroken or rooted, checks installed applications against threat intelligence, and on supported platforms blocks known malicious and phishing domains before they load. Mobile operating systems do not let any application inspect other applications' files, memory, or processes, so the mobile app is deliberately scoped to what the platform actually permits. It is not a reduced copy of our desktop agent.
Plans, and why there is no purchase inside the app
The mobile app has two plans and neither is bought inside the app.
- Free: the default. Full on-device protection for your personal device. No account, no payment, no trial timer.
- Business:activated by entering an enrollment token issued by your organization's administrator. This links the device to your company fleet so administrators can see its status and respond to incidents. Your organization arranges billing with us directly, so there is nothing to purchase on the device.
If you were given a token and it is rejected, it has most likely expired or already been used. Ask your administrator to issue a new one from the console at app.nemesislabs.xyz.
Why the app asks for VPN permission
Network protection needs a local VPN connection because that is the only mechanism either mobile OS provides for an application to inspect its own device's network traffic. Your traffic is not sent to us and is not routed through any remote server. The connection terminates on your device. Domain lookups are checked against the on-device threat list and malicious ones are refused locally. Everything else takes its normal route. You can decline the permission and keep using the rest of the app, and you can revoke it at any time in system settings.
Both operating systems allow only one VPN to be active at a time, so this feature conflicts with a corporate VPN or another VPN app. If you need both, turn network protection off and the other protections keep running.
App lock
You can require Face ID, Touch ID, or your Android biometric to open the app. Turn it on with the App lock switch on the main screen. If biometrics fail, your device passcode works as the fallback. This protects the app on an unlocked phone. It does not stop protection from running, which continues in the background whether the app is open or not.
Reading the main screen
- Device integrity: Clean means we found no evidence of jailbreak or root. Compromisedmeans we did, and the operating system's own protections can no longer be relied on.
- Threats detected: how many findings this install has recorded.
- Network protection: shown only on devices where it is supported and installed. Its absence is not a fault.
Removing the app
Delete it the normal way for your platform (press and hold the icon on iPhone, or uninstall from Settings on Android). Everything stored on the device goes with it. If you also want your cloud records erased, follow account and data deletion.
2. Nemesis Blue for macOS, Linux and Windows
Installers for every supported platform are on the download page. Agents update themselves on the stable channel, so a manual reinstall is rarely needed.
The agent shows as offline
Confirm the device can reach app.nemesislabs.xyz over HTTPS, then check that the agent is enrolled to the right account. On macOS run nemesisctl status. If it reports enrolled but the console disagrees, send us that output and we will trace it from our side.
Real-time blocking is not active on macOS
Blocking a process before it executes requires Apple's Endpoint Security entitlement. Where that is not yet active on a build, the agent still scans, detects, and quarantines, and the in-app panel states plainly which capabilities are live and which are waiting. We would rather show you that distinction than imply protection we do not have.
Uninstalling
- macOS:
nemesisctl uninstall - Linux:
sudo /opt/nemesis-blue/uninstall.sh - Windows: Settings → Apps → Nemesis Blue → Uninstall
3. Reporting a false positive
If we flagged something you believe is safe, tell us. False positive reports are the single most useful thing you can send us, and they feed directly into the next model release.
Email [email protected] with the subject False positive report and include the detection name shown in the app, the file path or domain involved, and the platform. Do not attach the sample itself unless we ask. We will reply with a verdict, and if we were wrong we will say so and correct the rule.
4. Nemesis Red
Nemesis Red is licensed, not downloaded. Licensing, scoping, and pilot questions go to [email protected]. Existing license holders with a technical issue should use [email protected] and quote the license identifier from your welcome email.
Read the Acceptable Use Policy before running any engagement. Authorization and consent attestation are conditions of the license, not formalities.
5. Privacy and data
What we collect and why is set out in full in the Privacy Policy. In short, we collect the minimum needed to operate the product: a per-install device identifier, the agent version, device health signals, and details of detections. We do not sell personal data and we do not use it for advertising or cross-app tracking.
6. Still stuck
Email [email protected] and describe what you expected and what happened instead. Your platform, product version, and a screenshot get us to an answer fastest. If you are reporting something time-sensitive on a business fleet, put URGENT in the subject and we will prioritize it.