~/services/mobile-application-testingService
Mobile application testing
Assessment of Android and iOS applications and the APIs they depend on: how the client stores data, how it talks to the backend, and what an attacker with the app in hand can reach.
What we look for
- Full coverage of the OWASP Mobile Top 10 and MASVS, on the client and its backend
- Data stored and handled on the device
- Transport security, certificate validation and pinning
- Backend API authorization, tested with the app as the client
- Reverse engineering, secrets and anti-tampering where required
- Platform hardening, inter-process communication and third-party SDKs
- Coverage spans the whole mobile attack surface, not a single layer
What you receive
- Executive summary
- Technical findings with reproduction steps
- Working proof of exploit per finding
- Developer-ready remediation
- Report walkthrough call
- Retest included
Get a fixed price for mobile application testing.
A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.