Skip to content
← All services

Penetration testing service

Mobile Application Penetration Test

Android or iOS testing against the OWASP MASVS, covering the client binary, local storage and the backend it talks to. Priced per platform.

What the test covers

  • Static analysis of the binary, including hardcoded secrets and weak cryptography
  • Local data storage, keychain and keystore handling
  • Certificate pinning, TLS validation and traffic interception resistance
  • Runtime manipulation, root and jailbreak detection resilience
  • Inter-process communication and deep link handling
  • The backing API, tested to the same standard as a standalone API engagement

Deliverables

  • Executive summary
  • CVSS-scored findings with reproduction steps
  • MASVS coverage mapping
  • One retest round with a signed closure letter

Out of scope

  • Testing on physical devices you do not supply
  • App store review process