Mobile App Security Testing
Android and iOS applications tested the way a real attacker works โ storage, transport, auth flows, and the APIs behind the app.
What we cover
- Local storage: tokens, PII, and keys in preferences and databases
- Insecure IPC, deep links, and exported components (Android)
- Transport security and certificate pinning bypass
- Authentication and session handling in the app and its backend
- Hardcoded secrets, debug flags, and logging of sensitive data
- Backend API authorization flaws the app exposes
How we test
Decompilation and inspection of the app binary: secrets, logic, and configuration.
Instrumented runtime testing on real devices: storage, traffic, and IPC behavior.
The APIs the app calls are tested for authorization and abuse โ the app is often just the door.
Findings with reproduction steps, severity, and developer-ready fixes; retest included.
What you get
- Mobile-specific findings with device-level reproduction steps
- Backend API issues the app exposes
- Hardening guidance for the next release
- Free retest of fixed findings
The engagement at a glance
A short conversation about your environment. You receive a written scope, timeline, and fixed quote โ no obligation.
Testing begins only with your written permission and agreed rules of engagement. Always.
A calendar agreed before we start, with an agreed communication plan while testing runs.
A verification pass over everything you fix โ included in the price, not an add-on.
See the full engagement process โ and how pricing is scoped in our public pricing guide.
Related research from Hmmnm
Common questions
Do you need source code or the app binary?
The binary is enough for black-box testing; source access deepens coverage. Both work โ we recommend the approach in the scoping call.
Which platforms do you cover?
Android and iOS, on real devices, covering the app and the backend APIs it depends on.
Do you test on our production backend?
Preferably a staging backend mirroring production. If production is the only option, we test with safe techniques under agreed rules.
Want this assessed for your environment?
A short scoping conversation is enough to get a fixed quote. No obligation โ a researcher replies.
Start the conversation โ