Mobile App Pentest
A manual test of your mobile application on real devices, treating the binary as something an attacker already holds. We look at what the app stores, what it trusts, what it leaks over the wire, and whether the backend enforces anything the client believes it is enforcing. The API behind the app is in scope, because that is usually where the real finding is.
Timeline
Two to four weeks per platform: a few days to scope and get builds, one to two weeks of static and runtime testing, and the report within three business days of the last test day.
You get
- Written report covering the app, the device and the backend
- Reproduction steps and evidence for every finding
- The list of secrets, endpoints and SDKs recoverable from the binary
If any of these is your week, this is the service.
Your app handles payments, health or identity data
Regulated data on a device you do not control raises questions about storage, key handling and what survives a lost phone.
What we do
A test focused on at-rest storage, keychain and keystore use, and what an attacker recovers from a rooted or jailbroken device.
The app is about to go on a store for the first time
Once it ships, the binary is public, and anything hardcoded inside it is public with it.
What we do
Static analysis of the shipped artefact plus a runtime test, before the version that carries a secret is downloadable.
Your backend trusts the app to enforce rules
Client-side checks are guidance, not a control — an attacker talks to your API directly and never runs your UI.
What we do
We work the API without the app in the path, to find every rule that exists only in the client.
Every step, and what leaves our hands at the end of it.
- 01
Scope & builds
We agree the platforms, versions and backend environments, and you supply installable builds and test accounts.
→ Signed scope & authorisation
- 02
Static analysis
Decompile the shipped artefact: hardcoded secrets, endpoints, third-party SDKs, debug surfaces and what the manifest permits.
→ Static findings
- 03
Runtime testing
On rooted and jailbroken devices: at-rest storage, keychain and keystore, transport security, certificate pinning and its bypass.
- 04
Backend testing
The API worked directly, without the app in the path, to find every rule enforced only on the client.
→ Findings with reproduction steps
- 05
Report & walkthrough
A written report plus a live session with your mobile and backend engineers together, since the fix usually spans both.
→ Full report + attestation letter
- 06
Retest
We re-run every finding against your fixed build and reissue the report with each one marked closed.
→ Retest addendum
Deliverables.
- Written report covering the app, the device and the backend
- Reproduction steps and evidence for every finding
- The list of secrets, endpoints and SDKs recoverable from the binary
- Severity, business impact and a recommended fix per finding
- Letterheaded attestation letter for customers and auditors
- One free retest within 90 days against your fixed build
Before we can quote.
- 01Installable builds — IPA and APK, or TestFlight and internal-track access
- 02Which platforms and OS versions you support
- 03Test accounts in every role, and the backend environment to point at
- 04Whether pinning is in place, and whether we may bypass it
- 05Any third-party SDK you are contractually barred from having tested
Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.
Mobile App Pentest, answered.
Do you need our source code?
No. We test the compiled artefact, because that is what an attacker has. Source access speeds up root-cause analysis and we will use it if you offer it, but it is never a prerequisite.
Is the backend really included?
Yes, and it is usually where the serious findings are. An app is a client; if the server trusts it, that is the finding.
We use certificate pinning — does that block you?
It stops casual interception, which is what it is for. We bypass it on a test device with your consent, because an attacker will. Pinning is worth keeping; it is not a control you can rely on alone.
Scope a Mobile App Pentest.
Mobile App Pentest is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.