Offensive testing

Mobile App Pentest

A manual test of your mobile application on real devices, treating the binary as something an attacker already holds. We look at what the app stores, what it trusts, what it leaks over the wire, and whether the backend enforces anything the client believes it is enforcing. The API behind the app is in scope, because that is usually where the real finding is.

At a glance

Timeline

Two to four weeks per platform: a few days to scope and get builds, one to two weeks of static and runtime testing, and the report within three business days of the last test day.

You get

  • Written report covering the app, the device and the backend
  • Reproduction steps and evidence for every finding
  • The list of secrets, endpoints and SDKs recoverable from the binary
Who needs this

If any of these is your week, this is the service.

Your app handles payments, health or identity data

Regulated data on a device you do not control raises questions about storage, key handling and what survives a lost phone.

What we do

A test focused on at-rest storage, keychain and keystore use, and what an attacker recovers from a rooted or jailbroken device.

The app is about to go on a store for the first time

Once it ships, the binary is public, and anything hardcoded inside it is public with it.

What we do

Static analysis of the shipped artefact plus a runtime test, before the version that carries a secret is downloadable.

Your backend trusts the app to enforce rules

Client-side checks are guidance, not a control — an attacker talks to your API directly and never runs your UI.

What we do

We work the API without the app in the path, to find every rule that exists only in the client.

How it works

Every step, and what leaves our hands at the end of it.

  1. 01

    Scope & builds

    We agree the platforms, versions and backend environments, and you supply installable builds and test accounts.

    → Signed scope & authorisation

  2. 02

    Static analysis

    Decompile the shipped artefact: hardcoded secrets, endpoints, third-party SDKs, debug surfaces and what the manifest permits.

    → Static findings

  3. 03

    Runtime testing

    On rooted and jailbroken devices: at-rest storage, keychain and keystore, transport security, certificate pinning and its bypass.

  4. 04

    Backend testing

    The API worked directly, without the app in the path, to find every rule enforced only on the client.

    → Findings with reproduction steps

  5. 05

    Report & walkthrough

    A written report plus a live session with your mobile and backend engineers together, since the fix usually spans both.

    → Full report + attestation letter

  6. 06

    Retest

    We re-run every finding against your fixed build and reissue the report with each one marked closed.

    → Retest addendum

What you get

Deliverables.

  • Written report covering the app, the device and the backend
  • Reproduction steps and evidence for every finding
  • The list of secrets, endpoints and SDKs recoverable from the binary
  • Severity, business impact and a recommended fix per finding
  • Letterheaded attestation letter for customers and auditors
  • One free retest within 90 days against your fixed build
What we need

Before we can quote.

  • 01Installable builds — IPA and APK, or TestFlight and internal-track access
  • 02Which platforms and OS versions you support
  • 03Test accounts in every role, and the backend environment to point at
  • 04Whether pinning is in place, and whether we may bypass it
  • 05Any third-party SDK you are contractually barred from having tested

Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.

Questions

Mobile App Pentest, answered.

Do you need our source code?

No. We test the compiled artefact, because that is what an attacker has. Source access speeds up root-cause analysis and we will use it if you offer it, but it is never a prerequisite.

Is the backend really included?

Yes, and it is usually where the serious findings are. An app is a client; if the server trusts it, that is the finding.

We use certificate pinning — does that block you?

It stops casual interception, which is what it is for. We bypass it on a test device with your consent, because an attacker will. Pinning is worth keeping; it is not a control you can rely on alone.

Next step

Scope a Mobile App Pentest.

Mobile App Pentest is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.

Scope a Mobile App Pentest1 business day

By submitting you agree to be contacted about your enquiry. We never share your details.