Mobile application penetration testing
We test your mobile apps on real devices, including jailbroken and rooted ones: what they store, what they send, and what an attacker can do with a copy of the app. The backend API is tested in the same engagement so nothing falls between two scopes.
What we test
- Local data storage, keychain, and keystore use
- Certificate pinning and transport security
- Authentication, session, and biometric bypass
- Reverse engineering, tampering, and runtime instrumentation
- Hardcoded secrets, API keys, and hidden endpoints
- Deep links, intents, and WebView abuse
- Authorization on the backend API
- Privacy leakage through third-party SDKs
How we approach it
We combine static analysis of the app package with dynamic testing on instrumented devices, hooking the app at runtime to bypass client-side controls and observe exactly what reaches your servers.
What you get
- Executive summary written for leadership and customers
- Technical findings with CVSS scores, evidence, and reproduction steps
- Specific remediation guidance for each finding
- One retest of reported findings within 90 days, with an updated report
- Attestation letter you can share with customers and auditors
Typical use cases
- Apps that handle payments, health, or identity data
- Public app store or enterprise distribution
- Customer security questionnaires and vendor reviews
- Before a major release
Often paired with
Tell us what you need tested.
Send a few details and we'll set up a short scoping call, then follow up with a fixed-fee proposal.