1. Home
  2. Services
  3. Penetration testing

Mobile application penetration testing

We test your mobile apps on real devices, including jailbroken and rooted ones: what they store, what they send, and what an attacker can do with a copy of the app. The backend API is tested in the same engagement so nothing falls between two scopes.

What we test

  • Local data storage, keychain, and keystore use
  • Certificate pinning and transport security
  • Authentication, session, and biometric bypass
  • Reverse engineering, tampering, and runtime instrumentation
  • Hardcoded secrets, API keys, and hidden endpoints
  • Deep links, intents, and WebView abuse
  • Authorization on the backend API
  • Privacy leakage through third-party SDKs

How we approach it

We combine static analysis of the app package with dynamic testing on instrumented devices, hooking the app at runtime to bypass client-side controls and observe exactly what reaches your servers.

What you get

  • Executive summary written for leadership and customers
  • Technical findings with CVSS scores, evidence, and reproduction steps
  • Specific remediation guidance for each finding
  • One retest of reported findings within 90 days, with an updated report
  • Attestation letter you can share with customers and auditors

Typical use cases

  • Apps that handle payments, health, or identity data
  • Public app store or enterprise distribution
  • Customer security questionnaires and vendor reviews
  • Before a major release

Tell us what you need tested.

Send a few details and we'll set up a short scoping call, then follow up with a fixed-fee proposal.

Request a quote