Mobile application pentesting
Assess iOS and Android clients for insecure storage, weak local controls, and unsafe trust in APIs—then validate the services they call.
Scope
Agreed builds (TestFlight/Play internal or equivalent): local data storage, IPC/export surfaces, certificate pinning behavior, runtime tamper basics, and the mobile↔API trust boundary. Device farm or your devices per SOW.
Method
Client-side review plus authenticated API checks tied to the app. CREST-aligned methodology. Our testers hold OSCP and CREST certifications.
Deliverables
Mobile-specific findings plus related API issues in scope, remediation guidance, optional retest. Often paired with /pentesting/api.
Common questions
Either or both per SOW.
Used when agreed for deeper client tests.
In scope as shipped binaries/workflows.
Prefer non-production builds with debug symbols when possible.