Mobile app penetration testing
The store listing is not the threat model. We assess the iOS and Android clients and the APIs they call, on-device and on the wire, mapped to OWASP MASVS.
What this engagement is
A mobile application stores tokens, caches records, talks to APIs, and runs on a device you do not control. Testing only the web backend leaves the client, the local storage and the pinning story unexamined. Testing only the IPA or APK leaves the authorisation model on the server untouched.
We test both. On-device for storage, logging, backup, clipboard, screenshot and jailbreak/root detection. On the wire for TLS, pinning bypass, and the same API issues we hunt in a dedicated API test.
Engagements are mapped to OWASP MASVS so the report is usable as evidence, not as a museum of screenshots.
What we actually look for
Local storage and secrets
Keychain, Keystore, Realm, SharedPreferences, backups, logs, and the plaintext token in a debug build that shipped.
Transport
Certificate pinning, TLS versions, proxy bypass, and cleartext leftovers.
Platform misuse
Deep links, exported activities/providers, URL schemes, pasteboard, screenshots in recents.
Binary and reverse engineering
Hardcoded keys, hidden admin, obfuscation that does not survive a determined afternoon.
Backend APIs
Everything in our API methodology, because that is where the data actually lives.
Authn on device
Biometrics as theatre, PIN bypass, session lifetime, and rooted/jailbroken device policy.
Questions buyers ask before they sign
Do you need TestFlight / internal APK builds?
Yes. Store builds with pinning and no debug often slow the work without changing the findings. We will take production builds if that is all you can give us.
iOS and Android as one test?
Usually. Shared backends mean shared API findings. Client issues are platform-specific and we report them separately.
Do you need source code?
No. It shortens time-to-finding on crypto and storage. Grey-box is still the default.
Often scoped alongside
Web application penetration testing
Your web app is the front door to customer data, payments and admin. We test it logged in, role-aware, reading the JavaScript and probing th…
Learn more > [api]API penetration testing
Your SPA is a skin. The API is the product. We test REST, GraphQL and internal service APIs for the authorisation bugs that turn one user's …
Learn more > [cld]Cloud security review
Most cloud incidents are not zero-days. They are a public bucket, an over-privileged role, a key in a repo, and no logging when it matters. …
Learn more >Scope this test
Send the target, the roles and the deadline. You will get a fixed quote in AUD, usually within two business days.