// Mobile

Mobile app penetration testing

The store listing is not the threat model. We assess the iOS and Android clients and the APIs they call, on-device and on the wire, mapped to OWASP MASVS.

Smartphone home screen

What this engagement is

A mobile application stores tokens, caches records, talks to APIs, and runs on a device you do not control. Testing only the web backend leaves the client, the local storage and the pinning story unexamined. Testing only the IPA or APK leaves the authorisation model on the server untouched.

We test both. On-device for storage, logging, backup, clipboard, screenshot and jailbreak/root detection. On the wire for TLS, pinning bypass, and the same API issues we hunt in a dedicated API test.

Engagements are mapped to OWASP MASVS so the report is usable as evidence, not as a museum of screenshots.

// Coverage

What we actually look for

[mob]

Local storage and secrets

Keychain, Keystore, Realm, SharedPreferences, backups, logs, and the plaintext token in a debug build that shipped.

[mob]

Transport

Certificate pinning, TLS versions, proxy bypass, and cleartext leftovers.

[mob]

Platform misuse

Deep links, exported activities/providers, URL schemes, pasteboard, screenshots in recents.

[mob]

Binary and reverse engineering

Hardcoded keys, hidden admin, obfuscation that does not survive a determined afternoon.

[mob]

Backend APIs

Everything in our API methodology, because that is where the data actually lives.

[mob]

Authn on device

Biometrics as theatre, PIN bypass, session lifetime, and rooted/jailbroken device policy.

// FAQ

Questions buyers ask before they sign

Do you need TestFlight / internal APK builds?

Yes. Store builds with pinning and no debug often slow the work without changing the findings. We will take production builds if that is all you can give us.

iOS and Android as one test?

Usually. Shared backends mean shared API findings. Client issues are platform-specific and we report them separately.

Do you need source code?

No. It shortens time-to-finding on crypto and storage. Grey-box is still the default.

Scope this test

Send the target, the roles and the deadline. You will get a fixed quote in AUD, usually within two business days.

Get a fixed quote