Scope and authorize
We agree platforms, builds, test accounts and the window in writing before anything is installed.
A test of your iOS and Android apps on real devices — what they store, what they transmit, what they can be made to do when the device is not trustworthy — together with the backend services they depend on.
A mobile app runs on hardware you do not control, in the hands of someone who may be the attacker. Anything the app knows can be read, anything it checks can be patched out, and the API behind it is reachable without the app at all.
We test the app statically and on a live, instrumented device, and we always test the backend with it — because that is where the data actually lives.
Typically one to two weeks per platform, confirmed at scoping.
We agree platforms, builds, test accounts and the window in writing before anything is installed.
Static review of the binary and its resources: secrets, endpoints, third-party SDKs and the checks the app relies on.
On a rooted or jailbroken device we watch storage, traffic and runtime behaviour, and we test what happens when the app’s own defences are bypassed.
Every API the app calls is tested directly, without the app in the way.
Findings arrive with device evidence, followed by a walkthrough and a retest after your fixes.
Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.
Session tokens, personal data or card details written to unprotected local storage
API keys and internal endpoints recoverable from the shipped binary
Certificate pinning that stops a curious user but not an attacker
Deep links and exported components that trigger actions without authentication
Backend endpoints that trust checks the app was supposed to perform
Missing something on this list? Bring it to the call — we scope around what you have.
Find and prove the weaknesses in your web applications before attackers do.
Read moreKeep the APIs that connect your products, partners and data from becoming the way in.
Read moreConfidence that one of your customers can never reach another customer’s data.
Read moreMake sure your desktop apps, thick clients, browser extensions and agents don’t open a back door.
Read moreNot sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.
Free. No obligation.