Mobile App Security Testing

Android and iOS applications tested the way a real attacker works โ€” storage, transport, auth flows, and the APIs behind the app.

Why this matters: A mobile app is a thick client with your API keys inside it. Attackers decompile, inspect local storage, bypass pinning, and abuse the backend APIs the app trusts. The same manual methodology we publish for web applications applies โ€” plus the mobile-specific attack surface most teams never review.

What we cover

  • Local storage: tokens, PII, and keys in preferences and databases
  • Insecure IPC, deep links, and exported components (Android)
  • Transport security and certificate pinning bypass
  • Authentication and session handling in the app and its backend
  • Hardcoded secrets, debug flags, and logging of sensitive data
  • Backend API authorization flaws the app exposes

How we test

1Static analysis

Decompilation and inspection of the app binary: secrets, logic, and configuration.

2Dynamic testing

Instrumented runtime testing on real devices: storage, traffic, and IPC behavior.

3Backend review

The APIs the app calls are tested for authorization and abuse โ€” the app is often just the door.

4Report & retest

Findings with reproduction steps, severity, and developer-ready fixes; retest included.

What you get

  • Mobile-specific findings with device-level reproduction steps
  • Backend API issues the app exposes
  • Hardening guidance for the next release
  • Free retest of fixed findings

The engagement at a glance

๐Ÿ“ž Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote โ€” no obligation.

โœ๏ธ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

โฑ๏ธ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

๐Ÿ” Retest included

A verification pass over everything you fix โ€” included in the price, not an add-on.

See the full engagement process โ†’ and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

Do you need source code or the app binary?

The binary is enough for black-box testing; source access deepens coverage. Both work โ€” we recommend the approach in the scoping call.

Which platforms do you cover?

Android and iOS, on real devices, covering the app and the backend APIs it depends on.

Do you test on our production backend?

Preferably a staging backend mirroring production. If production is the only option, we test with safe techniques under agreed rules.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement โ€” the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation โ€” a researcher replies.

Start the conversation โ†’