forumNew topic

Android app for clients: How do we know if the developer actually wrote secure code?

DDeniz B***ExpertCommunity member
Joined
Jan 2026
Message
79
#1

We're a 16-person medical device consumables distributor based in Stuttgart. We hired two freelance developers with a budget of 22.000 EUR to build an Android app so clinics and private practices can place quick reorders. The project is finished, the UI works fine, and orders are coming through to our database.

That said, with Germany's strict data protection regulations and client confidentiality, I can't shake this uneasy feeling. The developers keep saying 'everything was built securely to standard,' but since I don't have a technical background, I have no idea what was actually addressed under the hood.

As a business owner, how do I verify that proper security is actually in place on Android? What exact questions should I be asking the developers, or what concrete tests should I request before officially signing off on it?

OOkyanusMember
Job title
Embedded software
Organization type
regional distributor
Joined
Apr 2024
Message
96
Most Helpful#2

Short answer: Determining whether a developer built a secure Android app isn't about looking at the UI; it comes down to how data is stored on the device, how server communications are encrypted, and how well the source code is protected against reverse engineering. Instead of relying on the developer's word, you should demand an independent static analysis report and a standard penetration test.

As a business owner, demand these four concrete deliverables from the developers right away: 1) Local data storage method: Are user passwords, order histories, or session tokens stored as plain text on the device, or are they encrypted using the Android KeyStore? 2) Network security configuration: Is traffic between the server and app just standard HTTPS, or has SSL pinning been implemented to prevent man-in-the-middle attacks? 3) Code obfuscation: Is protection enabled during compilation so open-source analysis tools can't easily decompile and read the functions? 4) Permissions list: Does the app manifest request unnecessary access like camera, location, or contacts that have nothing to do with its core function?

To verify all this before publishing the app to the Google Play Store, hire an independent third-party security specialist to run a baseline mobile penetration test specifically for Android. It usually costs between 2.000 and 4.000 EUR, but given that medical data is involved, that's negligible compared to potential breach fines.

GGizem Ö***Member
Job title
QA Tester
Sector
Consulting
Organization type
regional distributor
Joined
Jul 2024
Message
257
#3

Ask the developer this simple question: 'If a user opens this app on a rooted phone or if I inspect the network traffic through a proxy can I see client session tokens?' If they dodge the question the security layer is weak. You can also install the app on a test device and run the APK file through free open-source vulnerability scanners yourself to check the basics.

RRıdvan A***Veteran
Job title
Software developer
Sector
Leather
Organization type
two-branch business
Joined
Jan 2024
Message
12
#4

Where is the backend server (API) hosted and who audited its security? With mobile apps data leaks rarely happen from the phone itself; they usually come from broken authorization flaws on the backend server the app pulls data from. Has the API security been tested?

İİlker G***Member
Job title
Board member
Sector
Livestock
Organization type
regional distributor
Joined
Apr 2026
Message
341
#5

If you are storing clinic data and commercial orders in Germany, you are required by DSGVO to document the 'privacy by design' principle. Ask the developer to fill out an OWASP Mobile Application Security Verification Standard (MASVS) compliance checklist. Have them write down what measure they took for each item and sign off on it. You'll quickly see whether they are willing to take official responsibility.

VVildan Ş***MemberCommunity member
Joined
Nov 2023
Message
17
#6

Developers saying 'everything is secure' means absolutely nothing. Most freelancers just copy-paste ready-made code snippets from the internet and hardcode API keys right into them as plaintext. Never believe an app is secure unless an independent pair of eyes has reviewed it from the outside.

SSelin T***Member
Job title
Intern
Sector
Logistics
Organization type
300-person organization
Joined
Sep 2022
Message
2

Doki · Corporate website · 2023

#7

first thing check app permissions in phone settings. if an app that just takes orders wants access to files, location or contacts it means the dev just copy-pasted a template and moved on. unnecessary permissions are the biggest risk.

DDilara Y***Veteran
Job title
Human Resources Manager
Sector
Real estate
Organization type
8-person team
Joined
Oct 2024
Message
98
#8

Doesnt the Google Play Store already run security checks when apps are uploaded anyway? If the store approved it, do we still have to get extra security testing done?

FFiliz P***Member
Job title
Production Manager
Sector
E-commerce
Organization type
300-person organization
Joined
Jun 2025
Message
166
#9

We took delivery of a similar B2B app last year. The developers sounded super confident, but we paid 2.500 EUR to have an independent mobile pentest done. The report revealed that backend server passwords were left completely exposed inside the APK and session tokens never expired. If we hadn't paid that money, we would've faced a massive scandal.

JJale P***MemberCommunity member
Joined
Mar 2024
Message
207
#10

The cheap-looking path usually ends up costing more later. An untested backup is not a backup.

HHakan K***MemberCommunity member
Joined
Oct 2022
Message
84
#11

i think differently. if it's your first time, start small; scaling comes later.

provn by experience.

BBeyza K***Expert
Job title
Social media manager
Sector
Software
Organization type
early-stage startup
Joined
Jul 2025
Message
2
#12

The opposite happened to me, that's why I'm writing. If you get three different answers on a topic, the question was asked wrong.

If you post the result here, it will help others too.

ZZübeyde G***MemberCommunity member
Joined
Feb 2024
Message
9
#13

just a heads-up. like don't rely on a single measure; go layer by layer.

if you post the result here, it will help others too.

MMetin C***MemberCommunity member
Joined
Feb 2024
Message
170
#14

I agree.

UUğur Y***MemberCommunity member
Joined
Jun 2023
Message
38
#15

youre right Ive been down that road too. dont hesitate to ask; those who dont ask always pay more.

EEsra U***MemberCommunity member
Joined
Feb 2026
Message
160
#16

My questions are cleared up, thanks. If 2FA is on, a stolen password alone is useless.

The real issue isn't the number, but what it's based on.

ÜÜmit K***Member
Job title
Operations manager
Sector
Jewelry
Organization type
a company within a holding
Joined
May 2022
Message
406
#17

You're right. Your time to detect an issue directly determines its cost.

BBerenMember
Job title
Product designer
Joined
Mar 2024
Message
112
#18

There's one point I'm curious about. When making decisions, write down the worst-case scenario too, not just the best.

That's all, sorry if I went on too long.

FFeyza K***Member
Job title
Intern
Sector
Catering
Organization type
workshop
Joined
Nov 2024
Message
2
#19

I didn't know that. If 2FA is on, a stolen password alone is useless.

FFeyza A***MemberCommunity member
Joined
Mar 2026
Message
55
#20

Let me summarize what's been said so far. If it's your first time start small; scaling comes later.

Good luck with that.

Reply