Applications

Mobile application pentest

A test of your iOS and Android apps on real devices — what they store, what they transmit, what they can be made to do when the device is not trustworthy — together with the backend services they depend on.

8
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

A mobile app runs on hardware you do not control, in the hands of someone who may be the attacker. Anything the app knows can be read, anything it checks can be patched out, and the API behind it is reachable without the app at all.

We test the app statically and on a live, instrumented device, and we always test the backend with it — because that is where the data actually lives.

OWASP MASVS OWASP Mobile Application Security Testing Guide OWASP API Security Top 10

What we test

  • Data at rest: local databases, caches, logs, backups and screenshots
  • Keychain and Keystore use, and how cryptographic keys are protected
  • Transport security, certificate validation and pinning — and whether pinning can be removed
  • Reverse engineering: hardcoded secrets, API keys and hidden endpoints in the binary
  • Inter-process communication, deep links, custom URL schemes and exported components
  • WebView configuration and anything loaded into it
  • Root and jailbreak detection, tamper and debugger checks — and what they are protecting
  • The backend APIs the app talks to, tested as their own surface
How it runs

From scoping call to retest, here’s what happens.

Typically one to two weeks per platform, confirmed at scoping.

1

Scope and authorize

We agree platforms, builds, test accounts and the window in writing before anything is installed.

2

Take the app apart

Static review of the binary and its resources: secrets, endpoints, third-party SDKs and the checks the app relies on.

3

Run it instrumented

On a rooted or jailbroken device we watch storage, traffic and runtime behaviour, and we test what happens when the app’s own defences are bypassed.

4

Test the backend

Every API the app calls is tested directly, without the app in the way.

5

Report, readout and retest

Findings arrive with device evidence, followed by a walkthrough and a retest after your fixes.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

Session tokens, personal data or card details written to unprotected local storage

API keys and internal endpoints recoverable from the shipped binary

Certificate pinning that stops a curious user but not an attacker

Deep links and exported components that trigger actions without authentication

Backend endpoints that trust checks the app was supposed to perform

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • Installable builds for each platform in scope (IPA and APK, or TestFlight and internal track access)
  • Test accounts, at least two per role
  • Any backend documentation you have
  • Confirmation of which backend environment we may test against

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.