Mobile application penetration testing.
iOS and Android, tested to the OWASP mobile standards — on the device and the backend behind it.
We secure the Czech tech companies that made it globally.
Mobile application penetration testing
A mobile app ships to devices you don't control, in the hands of users you can't vet — so anything it stores, caches, or trusts locally is fair game for an attacker who owns the phone. Mobile application penetration testing covers both iOS and Android against the OWASP mobile standards (MASVS, the Mobile Security Testing Guide, and the Mobile Top 10), starting from what the app does and what data it protects, then testing both the app on the device and the server-side it talks to. The backend is in scope by default — most real mobile compromises happen there, not on the handset.
What we test
A mobile application penetration test covers the whole picture — the app on the device and the backend behind it:
- Analysis — what the app handles: sensitive data, business-specific risks, inputs, external services, the functions worth attacking.
- On-device security — data at rest in the IPA/APK, secrets left in memory, side-channel leaks through logs, weak or home-grown cryptography, and how easily the app is unpacked.
- Authentication, authorization & session handling — on the device, where a stolen or rooted handset lets an attacker break every assumption the mobile application makes.
- Server-side protection — the backend/API the app talks to, tested in the same engagement so the app↔server trust boundary is actually exercised.
What you get
A report in four parts: a scope recap, a management summary with an expert opinion on your security standing, an audit-findings checklist sorted by severity, and detailed findings — each with description, impact, CVSSv3 severity, and a concrete proposed fix. Every finding is peer-reviewed so your team can reproduce and fix it fast.
Every test is run by certified senior specialists — no junior hands learning on your systems.
Use the test results toward NIS2, DORA, ISO 27001, and PCI-DSS.
Pricing
Every mobile application penetration test is scoped by the app, its platforms, and the backend in scope. We'll confirm scope and price on a short call.
Our insight.
Do not try to devise your own secure storage of sensitive data. Use standard OS components such as Keychain on iOS and Android.
Frequently asked, always answered.
What will be included in the test report?
A report includes the list of vulnerabilities discovered with severity rating. Additionally, there is a managerial summary which outlines how these vulnerabilities correspond to a business risk, and a technical write up, so developers can reproduce and correct the issues.
What about the backend API that talks to the mobile application?
Depending on the selected scope, backend testing can be done in conjunction with a mobile application test and/or a web application test. This will allow for the communications between the backend and user to be properly tested.
What types of mobile applications can you test?
We can test android, windows, iOS, and their respective backend APIs.
Do you need source code, or do you test the released app?
Either — black-box on the shipped binary, or grey-box with source/build access for deeper coverage; we recommend the depth on the scoping call.
Let's talk it through.
Tell us what you need tested — we'll set up a no-obligation call and propose a scope.
Book a free consultation ›