Testing · Application
Mobile Application Testing.
iOS and Android applications pulled apart on real devices — binary, storage, transport and the backend behind them.
At a glance
- Surface
- Application
- Execution
- Manual, senior-led
- Retest
- Included, no charge
- Proposal
- Within one business day
Scope
The app is only half the attack surface.
We test the client, the channel and the API together, because that is where mobile compromises actually happen.
iOS application testing
Binary analysis, keychain and storage review, jailbreak-detection bypass and runtime manipulation.
1–2 weeks
Android application testing
Decompilation, exported component abuse, root-detection bypass and insecure IPC.
1–2 weeks
Mobile backend & API testing
The APIs behind the app tested for authorisation, tampering and replay abuse.
1 week
Transport & certificate pinning
TLS configuration, pinning strength and interception resistance validated in practice.
2–4 days
OWASP MASVS verification
Structured verification against MASVS levels for regulated and app-store requirements.
1–2 weeks
Remediation retest
Free retest of the rebuilt binary and an attestation letter.
Within 90 days
Method
Client, channel, backend.
Nothing starts before the authorisation letter is signed and the blast radius is agreed.
- 01
Scoping
Builds, test accounts, platforms and device requirements agreed.
- 02
Static analysis
Decompilation, secret discovery, hardening and dependency review.
- 03
Dynamic analysis
Runtime instrumentation, storage inspection and control bypass on device.
- 04
Backend testing
API authorisation, tampering, replay and business-logic abuse.
- 05
Reporting & retest
Findings with evidence, then verification of the fixed build.
Deliverables
What lands on your desk.
- Static and dynamic findings with device-captured evidence
- OWASP MASVS coverage matrix
- Extracted secrets and hardcoded credential inventory
- Backend API findings with reproduction steps
- Platform-specific hardening recommendations
- Prioritised remediation roadmap with effort estimates
- Free retest report and attestation letter
Indicative timeline
Kickoff to closure.
- Week 0
- Scoping, builds and test accounts provisioned
- Days 1–4
- Static analysis and reverse engineering
- Days 4–10
- On-device dynamic testing and backend abuse
- Days 11–13
- Reporting, walkthrough and executive readout
- Within 90 days
- Free retest of the remediated build
Enquire
Start a Mobile Application Testing conversation.
Tell us what you need tested. A senior consultant replies within one business day with scoping questions and indicative timelines — no sales funnel.
PRACTICE 04 OF 07
Start here
Ship the app with confidence.
Send the build and the scope. Fixed-price proposal and a named lead tester within one business day.
