Mobile and desktop app security

Android, iOS, macOS and Windows apps, tested on the device and through the APIs behind them. OWASP MASVS and MASTG for mobile, the same depth for desktop.

Anyone can download your app and take it apart. We’ll show you what they’d find.

What we test

Out of scope stays out. We ask first.

  • Local data

    What the app stores, where, and how well it is protected.

  • Network traffic

    TLS, certificate pinning, and what the app sends to whom.

  • Authentication

    Login, biometrics, token storage and sessions.

  • Platform interaction

    Intents, deep links, URL schemes, IPC and exported components.

  • Binary and build

    Hardening, secrets in the package, tamper checks, updates.

  • Back-end APIs

    The endpoints the app talks to, tested like any other API.

How we test

  1. Scoping

    Platforms, builds, test accounts, and which back end we may use.

  2. Static analysis

    The build unpacked and read, with MobSF and Ghidra.

  3. Dynamic analysis

    Instrumented devices, with Frida watching storage, IPC and crypto at runtime.

  4. Traffic and APIs

    Everything through Burp Suite, and the APIs behind the app tested in full.

  5. Proof

    Evidence for each finding, mapped to the MASVS control it breaks.

  6. Report and retest

    A walkthrough with your developers, then a free retest of the fixed builds.

A report your engineers can act on

  • Severity, evidence, reproduction steps and a fix for every finding.
  • Each finding mapped to its MASVS control, with notes per platform.
  • API findings in the same report, so nothing falls between teams.
  • A free retest of fixed builds in an agreed window.

How a finding reads

V-021ExampleSeverity: Medium

Session token stored in plain text on the device

Weakness
CWE-312
Where
Android app, local preferences file
Impact
Anyone with access to a backup or a compromised device could reuse the session.
Fix
Keep tokens in the Android Keystore or iOS Keychain, and shorten their lifetime.
Fixed · retested

Standards and tools

Findings mapped to
  • OWASP MASVS
  • OWASP MASTG
  • OWASP API Security Top 10
Tools we use
  • Frida
  • MobSF
  • Ghidra
  • Burp Suite
Which platforms do you cover?

Android, iOS, macOS and Windows. We build our own apps for Android and macOS, so we know them from the inside.

Do you need our source code?

No, a build is enough. Source lets us confirm issues faster and read paths the app rarely runs.

Do you test on rooted or jailbroken devices?

Yes, because a determined attacker will. We also check the app on an ordinary phone, where your users are.

Will you touch our production back end?

Only if you agree. We prefer staging. If it has to be production, limits and hours go in writing.

Tell us about your app

Send the scope and your deadline, and we’ll set up a call.