Already have an app? Our security team tests it the way an attacker would — against OWASP MASVS and the Mobile Top 10 — and hands you a CVSS-scored report with fixes. If you want, our developers implement them.
Mobile apps get reverse-engineered within hours of hitting the store. Hard-coded secrets, insecure local storage, missing certificate pinning and authorisation flaws in the API behind the app are what we find most often — in apps built by well-known agencies. Evosec's mobile app penetration testing covers the client, the API and the way they trust each other.
We test for fintechs, health-tech and marketplaces in France, the United States and Tunisia, in English or French, with a report your developers can act on the same day and your auditors can file.
Static and dynamic analysis mapped to MASVS levels L1/L2 and resilience (R) requirements.
Insecure storage, weak crypto, hard-coded secrets, exported components, deep-link abuse, jailbreak/root bypass, runtime hooking.
Auth and session handling, BOLA/IDOR, mass assignment, rate limiting — the OWASP API Top 10.
Obfuscation review, anti-tamper, Play Integrity / App Attest validation, binary protections.
CVSS-scored findings, proof-of-concept, prioritised remediation, executive summary, free retest of fixes.
Optionally, our React Native, Flutter, Swift and Kotlin developers fix the findings — one vendor, one contract.
Typically $4,000–$12,000 per platform (iOS or Android), including the backing API, and takes 1–3 weeks with the report. Both platforms sharing one codebase are usually discounted. Fixed price, free retest.
Not necessarily — we test black-box, grey-box or white-box. Providing source and a test build makes coverage deeper for the same budget.
Our reports follow OWASP MASVS/MASTG and include the attestation letter and remediation evidence those reviews require.
Yes — that's the difference between us and a pure security vendor. Our mobile developers can implement the fixes and we re-test for free.