Coming soon to iPhone and Mac

Capture. Investigate. Prove.

Don't just watch the network. Intervene in it.

Hollowport is an on-device network debugging platform for iPhone and Mac. Go from a failing request to an evidence-backed explanation — capture it, investigate why it happened, intervene to test a theory, and prove what actually went wrong — entirely on the device you're testing.

Why Hollowport

Interception happens on the device generating the traffic — not a machine in between.

Hollowport takes a different approach: the entire iPhone debugging workflow is built around the device itself. Built around a Network Extension and a single trusted certificate, Hollowport requires no separate device or desktop software for the iPhone workflow.

Once the certificate is trusted, supported traffic from Safari and native apps alike appears as individual requests — decrypted and readable, right on the phone where it actually happens.

Built around the device you're debugging

iPhone / Mac→ Network Extension→ Internet

Hollowport runs its interception layer directly on the device generating the traffic, so requests are captured in the same environment where the problem occurs — not by routing them through a separate proxy machine.

No Wi-Fi proxy configuration. No companion machine. No desktop process to keep running.

A native Mac app is launching alongside the iPhone app — its own Network Extension for capturing directly on Mac, or pairing with your iPhone to bring its live traffic into that same investigation workspace. One product, two places to capture from, both coming at the same time.

A look inside Hollowport

Every request, laid bare

Not a packet count or a connection log — complete request metadata for every request Hollowport captures: method, host, path, status, headers, and timing, decrypted and readable. Bodies are shown in full and clearly marked whenever a capture limit trims a large one.

Intervene in real time

Breakpoints: pause a live request, then decide what happens to it

A Breakpoint catches a matching request — or its response — before it's delivered. Inspect it in full: edit a request's method, path, query parameters, headers, or body; edit a response's status, headers, or body. Then choose what happens next — forward it as edited, reset it back to exactly what was captured, or abort the exchange outright.

1

Live request

A request — or response — matching your Breakpoint rule is caught in flight.

→
2

Pause

It's held before delivery. Nothing reaches the server, or your app, until you decide.

→
3

Inspect / Edit

Read it in full, then change headers, body, status, or query parameters — or reset back to the original.

→
4

Forward / Abort

Forward it — edited or unmodified — or abort the exchange outright.

→
5

Observe result

Watch exactly how your app handles what you just did. No guessing.

Breakpoints work on both sides of the exchange — pause a request before it leaves, or pause its response before your app ever sees it.

Control the network

Four ways to change what your app actually experiences

Traditional proxy tools mostly answer "what happened?" Hollowport also answers "what happens if I change it?" — with four distinct ways to intervene in live traffic on purpose.

Breakpoints

Pause it, by hand, once.

Catch one live request or response before delivery. Inspect, edit, reset, then forward or abort — a single, deliberate intervention.

Rules

The same intervention, automated.

Redirect, block, throttle, or rewrite headers on every matching request, by wildcard or full regex — without tapping through it live each time.

Mocking

Replace the response entirely.

Answer with a response you control instead of the real server's — test against a server state you can't actually produce on demand.

Chaos

Simulate a bad network, in one tap.

Bundled presets for latency, packet loss, and server errors — resilience testing without hand-building a Rule first.

Evidence, not guesses

See exactly what changed — and whether that's actually why

Remember that 401 from the top of the page? Replay it with a fix, compare the two attempts, and get a conclusion you can stand behind — not just a feeling that it's probably fixed now.

Attempt 1 — Failing

GETapi.example.com/v1/profile
status401 Unauthorized
authorizationBearer …4a1c (expired)
{ "error": "invalid_token", "error_description": "Access token expired" }

Attempt 2 — Fixed

GETapi.example.com/v1/profile
status200 OK
authorizationBearer …9f3e (refreshed)
{ "id": "usr_482", "name": "Jordan Rivera", "plan": "pro" }

What Compare actually shows

Confirmed: the Authorization header changed, and the status went from 401 to 200.

Possible: the original token had expired. The evidence supports this — but it's presented as a conclusion, not dressed up as an additional fact.

Where people actually start: Debug a 401 · Simulate a 500 · Test an offline backend · Reproduce a flaky request

The investigation workflow

Capture is just the beginning.

See the request. Inspect the response. Change the request. Send it again. Then go further.

Hollowport helps you organize the investigation itself — connecting problems to evidence, intervening in traffic to test a hypothesis, comparing attempts, and preserving what you learned.

From capture to proof.

1

Observe

See the actual traffic, decrypted on-device.

→
2

Understand

Read the real headers and body — JSON, gRPC, protobuf, all decoded.

→
3

Intervene

Pause a request, rewrite a rule, or fake a failure — deliberately, not by accident.

→
4

Reproduce

Replay a request — as captured, or as changed — to see if it happens again.

→
5

Experiment

Change the request or conditions and test your hypothesis.

→
6

Compare

See exactly what changed between two attempts, and whether that's what explains it.

→
7

Verify

Turn the fix into a repeatable check, so a regression doesn't slip back in.

→
8

Prove

Build a conclusion you can support with evidence.

The path isn't always linear. If the evidence doesn't fit, go back and look closer.

How Hollowport is different

Built for a different workflow

Charles and Proxyman are excellent desktop debugging tools. Hollowport is built around a different idea: the device you're debugging is where the debugging happens — every stage, not just decryption. Observe, Understand, Intervene, Reproduce, Experiment, Compare, Verify, Prove all run on that same device, in the same session, without switching tools.

Already using Charles or Proxyman? Hollowport isn't trying to replace your entire desktop workflow — it's built for the moments when staying entirely on-device is faster and simpler: less setup, fewer moving parts, and nothing standing between you and the traffic.

A quick look

Four moments this is actually built for

Capture

See what your apps actually send.

HTTP/1.1, HTTP/2, HTTP/3, GraphQL, gRPC, and decrypted WebSocket frames — captured and decoded on-device, not just a connection log.

Investigate

Stop guessing why a request failed.

Problems groups failures by cause, and correlates related ones into a single incident — not ten identical-looking rows.

Replay & Compare

Change it. Send it again. See if that's why.

Edit and resend a request, then get a hedged, evidence-backed read on whether your change actually explains the result.

Control

Don't just watch it fail. Change it.

Pause, edit, mock, or inject chaos into live traffic — Breakpoints, Rules, Mocking, and Chaos, working on real requests as they happen.

See every capability →

Who it's for

Built for people who debug the real world

iOS Developers

Debug API calls without leaving the device you're already testing on.

QA & Testers

Investigate failures that only happen on a real device, on a real network.

Security Researchers

Inspect exactly what an app sends over the wire, TLS included.

Solo & Indie Developers

A real traffic inspector without a lab setup or a second machine.

Privacy

Nothing you capture ever leaves your device

No account, no server

There's nothing to sign in to. Captured traffic is stored locally on the device and never uploaded to Hollowport or anyone else.

AI stays on-device

"Explain with AI" runs on Apple's on-device model only — never Apple's Private Cloud Compute, never a third-party service — and credentials or personal data are stripped from the request before it's given to the model.

Gone when you remove it

Delete the app and your capture history, certificate, and settings go with it. Nothing lingers on a server, because there isn't one.

What Hollowport can't decrypt

Certificate-pinned traffic — banking apps, and Apple's own push notifications and iCloud Private Relay — is visible at the connection level but can't be decrypted. That's a platform limitation that interception tools can't bypass, stated plainly rather than glossed over. See Capabilities & Limitations for the full technical picture, including HTTP/3, DNS-over-HTTPS, and DNS-over-TLS.

Coming soon

Capture the problem. Investigate the cause. Prove what happened.

Hollowport is a network debugging platform for developers and QA, coming soon to iPhone and Mac. Leave your email and we'll let you know the moment it's live.