Synthworks OnlineComparison library

Comparisons

Android, iOS and Windows side by side

The operating system sets the ceiling on what any security application can do. The same subscription, installed on three devices, is running three materially different products.

The constraint nobody advertises

Security software does its work through permissions granted by the operating system. Those permissions differ by platform, and the differences are not small adjustments — they change which components can exist at all. A product page listing "real-time protection" across Android, iOS and Windows is describing one label attached to three different sets of capabilities.

This page compares the three platforms on the same four criteria used throughout the library: what a third-party application may inspect, what protection the platform already provides, which paid components remain meaningful, and what actually reduces risk on that platform.

What a third-party security application can and cannot do on each platform.
Criterion Windows Android iOS and iPadOS
Scan other applications Yes — broad file system and process access Partly — installed packages and accessible storage No — sandboxing prevents it
Built-in protection Microsoft Defender, included and on by default Google Play Protect, included on devices with Play services Application review and sandboxing, plus Safari warnings
Paid components that still apply Scanning, filtering, VPN, password manager, monitoring Scanning, filtering, VPN, password manager, monitoring Filtering, VPN, password manager, monitoring
Main practical risk Downloaded executables and stale software Applications installed from outside the store, and over-broad permissions Phishing, account compromise and configuration profiles

Windows

Windows is the platform where the phrase "antivirus" retains its original meaning. A security application can read the file system, watch processes as they start, inspect archives and intervene before a program executes. Every component of a bundle can operate.

It is also the platform with a capable protection layer already switched on. Microsoft Defender ships with Windows, updates through the same channel as the operating system and requires no subscription. A paid product on Windows is therefore not filling an empty space; it is offering something in addition to what is already running, and the reasonable question is what that addition is. Common answers include filtering across more applications, a bundled VPN, a password manager and monitoring — which is to say the additions are frequently not the scanner at all.

Two habits do more for a Windows machine than any purchase. Keep the operating system and installed applications current, because unpatched software is the most frequently exploited weakness on the platform. Keep a backup that you have tested restoring from, because that is the only measure that reliably defeats ransomware after the fact. The Australian Cyber Security Centre publishes step-by-step guidance for individuals and small businesses covering both.

Android

Android permits a meaningful subset of what Windows allows. A security application can enumerate installed packages, examine files in storage it has been granted access to, and use accessibility and overlay permissions to warn about suspicious behaviour. It cannot reach inside another application's private storage, which is a deliberate and sensible boundary.

Devices shipping with Google Play services include Play Protect, which scans applications on the device and checks new installations. The paid case on Android generally rests on the surrounding components — link filtering beyond the browser, a VPN, a password manager — plus scanning of applications installed from outside the official store.

What to watch out for on Android

  • Applications installed from a link in a message rather than from an app store. This is the route most Android compromises take, and no scanner reliably compensates for an install you authorised.
  • Requests for Accessibility Service access from an application that has no reason to need it. That permission can observe and act on screen content.
  • Device administrator rights requested by something that is not a workplace management tool.
  • An application asking for permissions unrelated to its stated purpose — a torch wanting your contacts, for instance.

Android's permission manager lets you review what each application has been granted and withdraw it. Working through that list once is free, takes a few minutes, and routinely turns up access granted years ago to software no longer in use.

iOS and iPadOS

On iOS, applications run in sandboxes that prevent one application from reading another's data or inspecting its code. A third-party security application cannot scan your iPhone for malware in the sense people mean by the phrase, because the platform does not expose the necessary access to any third party.

That is not a gap in the product. It is the security model working: the same restriction that blocks a scanner also blocks the malicious application the scanner would be looking for. Applications are reviewed before distribution, updates arrive through a single channel, and the practical attack surface for ordinary users sits elsewhere.

A security subscription installed on an iPhone is doing the components that remain available: filtering addresses, providing a VPN, managing passwords, and monitoring breach data for an address you nominate. Those are real functions, and describing them accurately is different from implying an iPhone scanner exists.

Where iOS risk actually sits

Phishing and account compromise, rather than malicious applications. An attacker who obtains your Apple Account credentials and passes the second factor has access to a great deal without installing anything. Configuration profiles, installed from a web page under some pretext, are the other route worth knowing about: check Settings for any profile you did not deliberately install for a workplace or school.

Tablets

An iPad follows iOS. An Android tablet follows Android. A Windows tablet follows Windows. Tablets are frequently shared within a household and frequently kept for longer than phones, which raises two questions worth asking: whether the device still receives security updates from its manufacturer, and whether separate user profiles would be more appropriate than a single shared one. A device no longer receiving updates is the strongest practical argument for replacement, and no subscription substitutes for patches that are no longer issued.

Buying across a mixed household

Most Australian households run a mixture — a Windows laptop, two Android phones, an iPad. A multi-device licence covers them all, and the honest expectation is that its value varies sharply from device to device: most on Windows, less on Android where the platform already scans, and least on iOS where scanning is not available to anyone. The product covered here is sold for mobile devices, tablets and Windows; what is included on each platform is a question for the vendor's own current documentation rather than something to infer from a marketing page.

Before comparing licences, count the devices that genuinely need covering and check what each already has. That count, rather than the number of devices a plan permits, is what determines whether a licence is priced sensibly for you. How those prices move between the first term and the second is covered in subscriptions, renewals and refunds.