We're a 16-person medical device consumables distributor based in Stuttgart. We hired two freelance developers with a budget of 22.000 EUR to build an Android app so clinics and private practices can place quick reorders. The project is finished, the UI works fine, and orders are coming through to our database.
That said, with Germany's strict data protection regulations and client confidentiality, I can't shake this uneasy feeling. The developers keep saying 'everything was built securely to standard,' but since I don't have a technical background, I have no idea what was actually addressed under the hood.
As a business owner, how do I verify that proper security is actually in place on Android? What exact questions should I be asking the developers, or what concrete tests should I request before officially signing off on it?