forumNew topic

Mobile app security audit: how do we ensure the dev actually protects data before sign-off?

TTolga K***ExpertCommunity member
Joined
Apr 2025
Message
24
#1

We're having an appointment and health-tracking mobile app developed in Hamburg for private clinics and patients. We agreed on a 22,000 EUR budget and a 5-month turnaround with a local agency for this hybrid iOS and Android project. We're now in the final month, and the agency wants to hand over and publish the app next week.

Whenever I ask how they protect the data, I just get generic answers like "Don't worry, all traffic is SSL encrypted and the database is kept on a secure cloud server." But the app will store patients' personal info, appointment history, and doctor notes. I know that in Germany, legal and criminal liability for a health data breach falls straight on us. I'm not a technical founder, so I can't just dive into the source code to spot SQL injection flaws or check if authorization is handled properly.

What tangible security deliverables should I demand from the dev before making the final milestone payment and submitting the app to the stores? What's the most sensible way to independently audit an agency's work?

BBurcu A***VeteranCommunity member
Joined
Apr 2024
Message
360
Most Helpful#2

Short answer: you can't accept an app that handles health data based on the developer's verbal promises; you must require standard security scan reports as an acceptance criterion and commission an independent API pen test. Using SSL isn't a premium security perk, it's the baseline internet standard and does nothing to prevent database-level authorization flaws.

Demand three concrete technical deliverables at handover. First, static and dynamic code analysis (SAST/DAST) scan reports proving known mobile vulnerabilities were scanned and all critical findings were resolved. Second, a technical architecture document detailing database encryption methods and server-side authorization mapping. Third, a Software Bill of Materials (SBOM) listing known vulnerabilities in any open-source libraries used.

Even after getting those deliverables, set aside a fraction of your budget to hire an independent expert solely for back-end (API) testing. The most critical mobile vulnerabilities don't live in the client-side code; they hide in the server endpoints the app talks to. For example, testing whether tampering with a patient ID parameter in a request exposes someone else's clinical notes (an IDOR flaw) must be verified independently.

Run this independent test on the staging environment provided by the agency. Do not release the final milestone payment or sign off on project acceptance until all high or critical findings from the audit are fully resolved.

ZZeynep K***Expert
Job title
Marketing manager
Sector
Textile
Organization type
two-branch business
Joined
Nov 2023
Message
330
#3

Health data is classified as special category data under DSGVO Article 9 in Germany. Claiming you're secure because of SSL is like having a sturdy lock on the building's front door while leaving every room inside wide open. Definitely do not release that final milestone payment without seeing an independent test report.

RRıdvan B***MemberCommunity member
Joined
May 2023
Message
180
#4

Our developer on a similar health app insisted everything was rock-solid. We brought in a 3rd party for a 2-day API test costing 2,500 EUR. The report revealed that simply tweaking the patient ID parameter allowed anyone to pull the entire appointment history. That single test saved us from potential six-figure fines.

RRabia Ç***Member
Job title
IT manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jun 2025
Message
354
#5

Does your contract include a formal sign-off (Abnahme) clause? German contracts usually grant a 14 to 30-day review period following delivery. If that's in place, you can conduct your independent testing within that statutory window and formally submit remediation demands.

RRıdvan Ç***Member
Job title
Graphic Designer
Sector
Machinery manufacturing
Organization type
early-stage startup
Joined
Mar 2026
Message
38
#6

Be sure to ask whether they implemented certificate pinning on the mobile client. Also have them specifically test session key (JWT) expiry on the back end and verify whether tokens are properly invalidated upon logout. That's where things slip through the cracks most often.

MMert B***ExpertCommunity member
Joined
Sep 2024
Message
129
#7

Even without a technical background you can upload the app build file to an open-source mobile security scanner. You'll get a clear 15-minute report highlighting basic blunders like hardcoded database credentials or exposed API keys.

CCaner B***Member
Job title
Data Analyst
Sector
Real estate
Organization type
20-person company
Joined
Nov 2025
Message
39
#8

Don't fall for 40-page boilerplate PDF reports spat out by automated tools that agencies love to wave around. Automated scanners can't catch business logic and broken authorization flaws. The report must be signed off by a specialist who conducted manual testing.

RRecep S***Member
Job title
Production planning
Sector
Retail
Organization type
sole proprietorship
Joined
Sep 2023
Message
103
#9

if security wasnt explicitly defined in the contract it migt be hard to push now, but bring up compliance and legal mandates in healthcare. tbh tell them you cant go live without an independent audit they will have to cooperate.

BBurak B***Veteran
Job title
Software developer
Sector
Printing
Organization type
40-person manufacturing company
Joined
Mar 2023
Message
252
#10

completely valid concern and developers usually just check if buttons work and screens load leaving back-end data isolation as an afterthought. protect yourself: delay launch by two weeks if needed, but make sure you sign off with total peace of mind.

ŞŞerife K***Expert
Job title
System administrator
Sector
Machinery manufacturing
Organization type
workshop
Joined
May 2023
Message
154
#11

I'm in the same situation, that's why I'm asking. An untested backup is not a backup.

BBekirNew member
Job title
Site Manager
Organization type
a company within a holding
Joined
Oct 2024
Message
28
#12

I have an objection here. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

If you have questions, write them; I'll answer as best I can.

SSelin Ö***MemberCommunity member
Joined
Nov 2025
Message
336
#13

The opposite happened to me, that's why I'm writing. Everything goes well for the first three months; problems arise in the fourth.

This is my opinion, I'm not claiming it's absolute truth.

İİbrahim Y***MemberCommunity member
Joined
Dec 2024
Message
182
#14

Good call starting this thread.

FFurkan K***MemberCommunity member
Joined
Nov 2023
Message
141
#15

I felt relieved reading this answer, so it's not just me. tbh any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

That's all sorry if I went on too long.

KKeremMember
Job title
Agency sales
Joined
Jul 2024
Message
94
#16

I agree, and I'd like to emphasize that. The biggest time-waster for us was not knowing who had the final say.

Just leaving this note, it might be useful.

FFurkan K***Expert
Job title
Data entry clerk
Sector
Furniture manufacturing
Organization type
40-person manufacturing company
Joined
Feb 2025
Message
64
#17

You're right.

AAhmet B***New memberCommunity member
Joined
May 2026
Message
62
#18

Thanks, that was the answer I was looking for.

EEsra A***Member
Job title
Accounting Manager
Sector
Leather
Organization type
medium-sized business
Joined
Dec 2024
Message
41
#19

you're right, I've been down that road too. i mean your time to detect an issue directly determines its cost.

processes without records never improve, beacuse you dont know what to fix.

AAslı O***Veteran
Job title
Project manager
Sector
Software
Organization type
boutique agency
Joined
May 2023
Message
23

Doki · KVKK compliance consulting · 2023

#20

I was thinking the same thing. If it's your first time, start small; scaling comes later.

If you have questions, write them; I'll answer as best I can.

Reply