Mobile application penetration testing
Testing of your iOS and Android apps, and the back end they talk to, by people who take the app apart the way an attacker would.
Your app runs on someone els’s device
A mobile app runs on a device you do not control. Anyone can download it, decompile it, intercept its traffic and replay its requests. Anything shipped inside the app, from API keys to business rules, should be treated as public.
Most serious mobile findings are not in the app itself but in the API behind it, which often trusts the app to enforce rules it cannot enforce. We test both together.
What we test
Data on the device
What is stored in files, databases, logs, caches and the keychain or keystore, and whether it survives logout.
Network traffic
TLS configuration, certificate pinning, and what can be read or changed in transit.
Authentication and sessions
Login, biometrics, token storage and refresh, and session expiry.
Back-end APIs
Access control, data exposure and business logic in the services behind the app.
Code and binary
Secrets in the build, debug features left enabled, obfuscation, and how easily root or jailbreak detection is bypassed.
Platform interaction
Permissions, deep links, intents, exported components and WebViews.
How the engagement runs
Builds and accounts
You send test builds (an IPA and an APK, or TestFlight and internal track access) and accounts for each user role.
Static analysis
We decompile the app and review its configuration, libraries and code for secrets and weak points.
Dynamic testing
We run the app on test devices, intercept and modify its traffic, and test the API behind it.
Report and retest
Findings mapped to OWASP MASVS, the report within five working days, and a retest on your fixed build.
What you get
- Findings mapped to OWASP MASVS controls, so you can see coverage as well as issues.
- Separate actions for app developers and back-end developers.
- Retest results against your next build.
When to commission it
- Before a first public release, or a release that adds payments, health data or account recovery.
- When an app store, partner or regulator asks for security testing.
- After changing authentication, storage or networking libraries.
- Yearly for apps that handle personal data, and more often if you release frequently.
Questions we get asked
Do you need our source code?
Do you test both iOS and Android?
Can you test an app with certificate pinning or root detection?
What is OWASP MASVS?
Related
Web applications and APIs
Manual web application and API penetration testing. We find the authentication, access control and business logic flaws that automated scanners miss.
Read more →Cloud: AWS, Azure, Google Cloud
Cloud security assessments and penetration testing for AWS, Azure, Google Cloud and Microsoft 365: identity, storage, network and real attack paths.
Read more →Penetration testing
Manual testing of applications, networks, cloud, mobile and wireless, the way a real attacker works.
Read more →SavountFrom Perimeter to Identity: The New SaaS Attack Frontier
Single sign-on, session tokens and MFA fatigue: why identity is now the main attack surface for SaaS, and how to defend it.
Read the article →