Mobile Application
Penetration Testing

Security testing of your iOS and Android applications against OWASP MASVS — local storage, network communication, binary protections, and reverse-engineering resilience, tested together with the backend APIs.

Overview

The app in their pocket is in scope too.

A mobile app ships your code to a device the attacker fully controls — so insecure local storage, weak certificate pinning, and exposed secrets are common and high-impact.

We test iOS and Android apps against the OWASP Mobile Application Security Verification Standard, combining static and dynamic analysis with runtime instrumentation, and always test the client and its backend APIs together. Free retest within 60 days.


Coverage

What we test.

Client-side and server-side coverage aligned to OWASP MASVS and MSTG.

Methodologies: OWASP MASVS OWASP MSTG Static & dynamic analysis CVSS v3.1

FAQ

Mobile penetration testing FAQ

The questions we're asked most about scope, cost, and timing.

How much does a mobile application penetration test cost?
Typically €3,000–6,000 for a single platform including its backend, with both platforms scoped together for more. Use our estimator for a tailored figure.
How long does a mobile penetration test take?
Most take 5 to 10 working days of active testing plus reporting, depending on platform coverage and backend complexity.
Do you test both iOS and Android?
Yes — including React Native and Flutter apps. We can scope a single platform or both together.
Do you test the backend API as well?
Yes — we always assess the app with its backend APIs, since most serious mobile risk lives in server-side authorisation and data handling.
What do we receive after the test?
A CVSS-scored technical report with reproduction steps, an executive summary, an attestation letter, and a free retest within 60 days.
What do you need to start a mobile test?
The app builds (IPA/APK or TestFlight/Play access), test accounts for each role, and backend/API details. We confirm scope and quote from there.
Do you test on real devices?
Yes — we use a mix of real devices and emulators, including jailbroken/rooted environments for deeper analysis.
Do you cover React Native and Flutter apps?
Yes — alongside native iOS and Android, we test cross-platform frameworks including React Native and Flutter.
Is our source code required?
No — mobile tests are typically grey/black-box, but providing source enables deeper white-box coverage if you want it.
Do you check app-store and platform requirements?
We focus on security, but findings often overlap with platform guidance; we flag anything likely to affect store review.

Related services

Explore more.

Ready to test your mobile app?

A 30-minute scoping call costs nothing. A breach costs considerably more.

Book a meeting Send an email