← All services
Penetration testing service
Mobile Application Penetration Test
Android or iOS testing against the OWASP MASVS, covering the client binary, local storage and the backend it talks to. Priced per platform.
What the test covers
- Static analysis of the binary, including hardcoded secrets and weak cryptography
- Local data storage, keychain and keystore handling
- Certificate pinning, TLS validation and traffic interception resistance
- Runtime manipulation, root and jailbreak detection resilience
- Inter-process communication and deep link handling
- The backing API, tested to the same standard as a standalone API engagement
Deliverables
- Executive summary
- CVSS-scored findings with reproduction steps
- MASVS coverage mapping
- One retest round with a signed closure letter
Out of scope
- Testing on physical devices you do not supply
- App store review process