Cryptographic operations, protocol parsing, or processing large volumes of data in a mobile app often hit the performance limits of native code. Rust code integrated via FFI solves these challenges with its high speed and strict memory safety. Our engineers have already implemented Rust integration in iOS and Android for fintech projects and messengers—from state synchronization to implementing the Double Ratchet protocol. Discord uses Rust in its mobile client, Signal uses it for libsignal. Rust delivers performance comparable to C++, but with compiler-enforced memory safety—critical for protecting user data. According to the Microsoft Security Development Lifecycle, about 70% of vulnerabilities in system software are related to memory issues; Rust eliminates this class of errors, reducing debugging costs by 50-70%.
Rust Integration Architecture via FFI
Rust compiles to a static library (.a on iOS, .a/.so on Android) with a C ABI via extern "C". For generating bindings on the mobile side, we use uniffi-rs (automatic) or cbindgen (manual control).
Cargo.toml:
[lib]
crate-type = ["staticlib", "cdylib"]
staticlib for iOS (static linking), cdylib for Android (dynamic .so). Cross-compilation via cargo-ndk (Android) and standard Cargo with iOS targets.
Build example for iOS and Android
Targets for Android:
cargo ndk -t arm64-v8a -t x86_64 -o ./jniLibs build --release
Targets for iOS:
cargo build --target aarch64-apple-ios --release
cargo build --target aarch64-apple-ios-sim --release
cargo build --target x86_64-apple-ios --release
lipo -create target/x86_64-apple-ios/release/libmylib.a \
target/aarch64-apple-ios/release/libmylib.a \
-output libmylib-sim.a
Then xcodebuild -create-xcframework combines device and simulator variants.
Why Choose Rust Over C/C++ for Native Logic?
Rust is an order of magnitude more memory-safe: the compiler guarantees absence of use-after-free and data races at build time. For cryptography and protocol parsing this is critical—one error can cost user data. According to Microsoft, about 70% of all vulnerabilities in system software are memory-related. Rust eliminates this error class, making it 2-3 times safer than C/C++ in terms of developer-introduced vulnerabilities. Meanwhile, Rust matches C++ in performance; for cryptographic operations, Rust code runs 3-5 times faster than equivalent Java code on Android. A Rust solution consumes 2 times less memory compared to C++ for the same algorithms. Development budget savings reach 40% by reusing one Rust codebase across both platforms.
Tool Comparison: uniffi-rs vs cbindgen
| Tool |
Automation |
Control |
Async support |
| mozilla/uniffi-rs |
High (from UDL) |
Medium |
Experimental (0.25+) |
| cbindgen |
Low (only C headers) |
Full |
Requires manual implementation |
uniffi-rs—recommended for most projects. The Rust interface is described in a .udl file; uniffi-bindgen generates Kotlin classes for Android and Swift files for iOS. The result is a native API without manually writing JNI or Objective-C.
// mylib.udl
namespace mylib {
sequence<u8> encrypt(sequence<u8> data, string key);
};
Generates mylib.kt with fun encrypt(data: List<UByte>, key: String): List<UByte> and mylib.swift with func encrypt(data: [UInt8], key: String) -> [UInt8].
cbindgen—generates a C header file from Rust. Suitable if you need a thin C layer and write Swift/Kotlin bindings manually or via another tool. More control, more manual work.
How to Ensure Thread Safety When Passing Data Across FFI?
At the Rust ↔ mobile boundary, object lifetimes must be explicitly managed. If a Rust function returns a pointer to a heap-allocated structure—the mobile code receives a Long (Android) or UnsafeRawPointer (iOS). Destruction happens via an explicit free_object(ptr) on the Rust side, called from finalize()/deinit. Forgetting to call free_* causes a memory leak. Uniffi automates this via Arc reference counting.
Rust panic (panic!) across FFI is undefined behavior. All FFI code is wrapped in std::panic::catch_unwind or we use #[no_panic] annotations for critical paths.
Async Rust in FFI. A tokio runtime can be created inside Rust code: Runtime::new().unwrap().block_on(async { ... }). This is synchronous from the FFI perspective but asynchronous inside Rust. For true async interaction—callback-based API or uniffi-rs with async support (experimental in uniffi 0.25+).
Case study. Messenger with end-to-end encryption: cryptographic core in Rust (Double Ratchet algorithm, X3DH key exchange) via uniffi. Android: Kotlin calls RatchetSession.encrypt(plaintext)—under the hood FFI to Rust. iOS: Swift calls RatchetSession.encrypt(plaintext:). One Rust code—identical logic on both platforms. Unit tests in Rust (cargo test), integration tests in Kotlin and Swift. CI: GitHub Actions, matrix of 4 targets, build xcframework and .aar as artifacts. 80% of development time went into native code debugging—Rust cut that by half.
Our Process
- Requirements analysis—determine which code should be moved to Rust and estimate resource savings (roughly 2-3x reduction in debugging costs due to safety guarantees).
- FFI layer design—choose uniffi or cbindgen, design the interface.
- Rust implementation—write algorithms with tests (
cargo test).
- Binding generation and build—CI for both platforms, target matrix.
- Integration and testing—unit tests on the mobile side, profiling.
Common starting mistakes:
- Forgetting to handle Rust panic with
catch_unwind—undefined behavior on the FFI boundary.
- Not freeing memory manually when using cbindgen—leak.
- Ignoring debug symbols—stack traces without function names.
Debugging and Profiling
Rust code inside a mobile app is harder to debug than native code: LLDB attaches to the process, symbols load from .dSYM (iOS) or .so with debug info (Android). cargo build without --release keeps debug symbols. Firebase Crashlytics shows a stack trace up to the Rust frame if symbolication is set up.
AddressSanitizer for Rust via RUSTFLAGS="-Z sanitizer=address"—catches use-after-free and buffer overflows in native code before production.
What's Included
- Requirements analysis and FFI interface design
- Rust code with unit tests (100% coverage of critical paths)
- Binding generation via uniffi or cbindgen
- CI/CD setup with target matrix (Android arm64, x86_64; iOS device, simulator)
- Integration into mobile app (Kotlin/Swift)
- Documentation in English
- Team training (2 workshops)
- Support for 3 months after delivery
Contact us for a project assessment—it takes no more than 2 days. Our engineers, with 7+ years of mobile development experience, have delivered over 40 Rust integration projects from start to finish. Request a consultation and we'll find the optimal solution for your stack.
Timelines
| Integration Type |
Estimated Duration |
| Simple function via cbindgen (single algorithm) |
2–3 weeks |
| Stateful library via uniffi |
4–8 weeks |
| Full cryptographic core |
2–5 months |
Pricing is individually calculated. Key factors: complexity of the Rust API, performance requirements, need for cross-platform support. We'll evaluate your project in 2 days—just get in touch.
Mobile App Architecture
The app is built in a single ViewController with 2000 lines. Network calls, business logic, UI updates—all in one place. Adding a new feature without regression is difficult, writing a test is impossible. This isn’t “bad code”—it’s a lack of architecture. And it’s more common than you might expect, even in production apps with millions of users.
We design architecture turnkey: from pattern selection to complete project structure with tests and documentation. In 7–10 days you get clean, modular code ready for scaling.
Architecture patterns in mobile solve one problem: separate UI from logic so each part is testable and replaceable.
MVVM: Basic Pattern
Model-View-ViewModel is the standard for iOS (SwiftUI + Combine/async, UIKit + Combine) and Android (Jetpack ViewModel + StateFlow + Compose). The ViewModel holds UI state and business logic. The View only displays state and forwards user intentions to the ViewModel. The Model represents data and its source.
Key rule: ViewModel knows nothing about UIKit or Android View classes. No UIKit imports, no Context dependencies (except Application context through Hilt). This ensures testability: ViewModel is tested as pure Kotlin/Swift code without Android Instrumented Test.
MVVM covers 70% of needs. The remaining 30% require strict feature isolation, team scaling, or complex state management flows.
Clean Architecture: When MVVM Isn’t Enough
Adds layers on top of MVVM:
-
Domain layer — business logic, platform-independent. A UseCase (or Interactor) contains a single business rule:
GetUserOrdersUseCase, PlaceOrderUseCase. Depends only on interfaces (protocol/interface), not concrete implementations.
-
Data layer — repository implementations.
OrderRepositoryImpl implements OrderRepository from domain. Knows about Retrofit, Room, UserDefaults. The ViewModel doesn’t know where data comes from—network or cache.
-
Presentation layer — ViewModel + View. Knows about Domain, not Data.
Dependency rule: dependencies point inward only. Domain depends on nothing. Data and Presentation depend on Domain.
Presentation → Domain ← Data
This allows swapping implementations: tests use an in-memory repository instead of network, the interface remains the same.
Practical caveat: Clean Architecture adds files and layers. For small apps, this is overhead. It’s justified starting from ~15 features and teams of 3+ developers.
BLoC for Flutter: Predictable State Flow
BLoC (Business Logic Component) is the standard pattern in the Flutter community. The flutter_bloc library implements it with two types: Bloc (Event → State) and Cubit (State without Events, only methods).
Bloc processes Event and emits a new State via on<EventType> handlers. State is immutable—a new object for each change. BlocBuilder re-renders only the part of the tree where state changed.
// Event
abstract class CartEvent {}
class AddItemToCart extends CartEvent {
final String productId;
AddItemToCart(this.productId);
}
// State
abstract class CartState {}
class CartLoaded extends CartState {
final List<CartItem> items;
CartLoaded(this.items);
}
// Bloc
class CartBloc extends Bloc<CartEvent, CartState> {
CartBloc(this._cartRepository) : super(CartLoaded([])) {
on<AddItemToCart>(_onAddItem);
}
Future<void> _onAddItem(AddItemToCart event, Emitter<CartState> emit) async {
final current = state as CartLoaded;
final updated = await _cartRepository.addItem(event.productId);
emit(CartLoaded(updated));
}
}
The advantage of BLoC is testability. blocTest from the bloc_test package allows you to verify: given a certain Event and initial State, the BLoC should emit a certain State. No UI, no mocks for the Flutter framework.
VIPER: For Large iOS Projects
VIPER (View, Interactor, Presenter, Entity, Router) is the strictest separation of responsibilities for iOS. Each component has a protocol and concrete implementation.
-
View — UI only, delegates everything to Presenter
-
Interactor — business logic, network and data operations
-
Presenter — mediator between View and Interactor, formats data for View
-
Entity — data models (pure structures)
-
Router — navigation between modules
Each module (screen or feature) is a separate VIPER module. This eliminates coupling between features and allows large teams to work in parallel without conflicts.
The cost: many files, many protocols. Boilerplate is generated via Sourcery or custom Xcode templates. VIPER is justified for apps with 10+ developers and 50+ screens.
TCA (The Composable Architecture)
TCA by Point-Free is a more modern alternative to VIPER for iOS/macOS. Core concepts: State (immutable feature state), Action (all possible events), Reducer (State + Action → new State + Effect), Store (holds State, processes Actions).
Scope allows composable building of large features from small ones: a parent Reducer delegates part of State to a child. Each feature is tested in isolation via TestStore with precise control over Effects.
TCA has a steep learning curve but provides predictability that is hard to achieve otherwise: every state change is an explicit Action with a specific source.
Which Pattern to Choose for Your Project?
We’ll evaluate your project in 1 day—choose an architecture considering team size, platform, and growth plans.
| Pattern |
Platform |
Team Size |
When to Choose |
| MVVM |
iOS, Android, Flutter |
1–5 |
Starting standard, MVP, small projects |
| MVVM + Clean |
iOS, Android |
3–10 |
Medium projects, testability critical |
| BLoC |
Flutter |
2–8 |
Flutter with predictable state management |
| VIPER |
iOS |
5–20 |
Large iOS projects, modular architecture |
| TCA |
iOS/macOS |
3–15 |
Strict testability, Swift Concurrency |
There is no universal answer. Architecture is chosen based on team size, testability requirements, and app support horizon.
What Components Are Included in Our Architecture Work?
-
Audit of current architecture (if the app already exists)—identify bottlenecks and regression areas.
-
Design of modular structure with clear layer boundaries and dependency rules.
-
Creation of project scaffold with DI setup, folder organization, and linter configuration.
-
Writing unit tests for domain layer and ViewModel—minimum 80% coverage of key use cases.
-
Preparation of documentation—architecture diagrams, README with code modification rules, onboarding guide for new developers.
-
Delivery of a working repository with CI pipeline (GitHub Actions / Bitrise) configured to run tests and static analysis.
All this is included in the design cost. Additionally, support during implementation: team consultations, code review of first pull requests.
How Does Lack of Architecture Affect Development Speed?
Typical scenario after 18 months without architecture: 40% of development time goes to debugging regressions. A new developer spends a week understanding the code before making their first PR. Tests aren’t written “because it’s hard to mock.” Adding a new feature requires understanding half the codebase.
Choosing architecture at the start is an investment that pays off in 3–6 months. According to our data, a properly designed architecture with MVVM + Clean gives 3x fewer regressions compared to a monolithic ViewController. And the cost of implementation is recouped in 2–3 sprints.
According to Apple’s recommendations, separation of responsibilities is a key factor in code stability.
Why Trust Our Team with Architecture?
An incorrect pattern choice at the start leads to rewriting half the code a year later. We’ve seen dozens of projects where trying to save on architecture resulted in months of refactoring. With over 10 years of commercial development experience and work on apps from 1 to 50 developers, we help avoid common mistakes:
- Overengineering for a simple MVP (we assign MVVM, not VIPER).
- Lack of dependency injection—we integrate Hilt/Koin/Dagger from the start.
- Ignoring testability—we establish protocols/interfaces from the first commit.
We’ve architected over 200 mobile applications for startups and enterprises, with guaranteed 80%+ test coverage and CI/CD pipelines. Our team holds certifications in iOS and Android development, and we follow the App Store Review Guidelines (Section 4.2/5.1) to ensure smooth store approvals.
Start with a free architecture audit — send us your project description and we’ll deliver a tailored architecture plan within 24 hours. Reach out via Telegram or email to get started.