~/services/mobile-application-testingService

Mobile application testing

Assessment of Android and iOS applications and the APIs they depend on: how the client stores data, how it talks to the backend, and what an attacker with the app in hand can reach.

Typical duration5 to 10 working days
RetestIncluded

What we look for

  • Full coverage of the OWASP Mobile Top 10 and MASVS, on the client and its backend
  • Data stored and handled on the device
  • Transport security, certificate validation and pinning
  • Backend API authorization, tested with the app as the client
  • Reverse engineering, secrets and anti-tampering where required
  • Platform hardening, inter-process communication and third-party SDKs
  • Coverage spans the whole mobile attack surface, not a single layer

What you receive

  • Executive summary
  • Technical findings with reproduction steps
  • Working proof of exploit per finding
  • Developer-ready remediation
  • Report walkthrough call
  • Retest included

Get a fixed price for mobile application testing.

A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.

Contact
contact.log

No form, no sales desk. The person who answers is the person who would run your engagement.

Profiles
XLinkedIn
Book a scoping call

30 minutes, fixed price after. No questionnaire.