forumNew topic

How do you secure a mobile app, and what pre-launch checks are absolute musts?

AAycan K***Member
Job title
Store Manager
Sector
Catering
Organization type
20-person company
Joined
Mar 2024
Message
132
#1

We built a mobile app for B2B wholesale ordering and dealer account tracking. Our two-person dev team completed the project in about 4 months using a hybrid mobile framework and a Laravel-based API architecture. We plan to launch it on app stores next month.

Right now, 40 of our wholesale dealers are field-testing the system in a closed beta. Highly sensitive commercial data flows through the app, including dealer-specific discount rates, open account balances, invoice statements, and corporate tax ID numbers. We don't have a cybersecurity specialist on our team.

Our devs say the system is secure because they use standard HTTPS encryption and JWT-based authentication. But does mobile app security really boil down to just those two things? What measures must we take before submitting to app stores to protect against reverse engineering, data leaks, or unauthorized access?

FFeyza K***Expert
Job title
Clinic manager
Sector
Catering
Organization type
regional distributor
Joined
May 2022
Message
302

Doki · Interface design · 2024

Most Helpful#2

Short answer: Mobile app security doesn't live on the client device—it's largely handled at the API and data transport layers. Relying solely on HTTPS and standard tokens is not enough; code obfuscation, SSL pinning, and object-level authorization checks are absolute musts.

You need to build these four fundamental security layers before launch, in this order: 1) API and Authorization (BOLA Checks): The most common vulnerability in mobile is a dealer changing the dealer ID or invoice number in request parameters to fetch another company's statement. You must verify on the server side with every query whether the token owner is actually authorized to view the requested data. 2) SSL Pinning: Standard HTTPS is easy to bypass with a proxy between the device and server. Embed your server certificate's fingerprint directly into the app code to prevent man-in-the-middle attacks. 3) Code Obfuscation and Anti-Reverse Engineering: Hybrid apps are very easy to unpack and decompile. Use code obfuscation tools to make it hard to read API keys, hidden endpoints, and business logic in plain text. 4) Local Data Storage: Never store unencrypted passwords, raw tokens, or customer data in device memory, cache, or local databases. Keep sensitive data inside the OS secure storage (Keychain/Keystore).

Build a checklist covering these points at least two weeks before launch and have an external specialist or security testing tool scan your API endpoints—it will save you from major business liabilities.

TTolga Y***MemberCommunity member
Joined
Dec 2023
Message
2
#3

If you're using JWTs, keep token lifespans very short—like 15 minutes for access tokens and 7 days for refresh tokens. Also, make sure no `.env` file gets bundled into the build artifact. Devs sometimes accidentally leave staging database credentials or third-party API keys right in the client code.

BBora A***MemberCommunity member
Joined
Sep 2025
Message
118
#4

Pre-launch priority items: 1) Add root/jailbreak detection to flag modified devices. 2) Block screenshots and blur the app switcher preview when backgrounded. 3) Suppress server paths and raw database logs from error responses.

İİbrahim T***ExpertCommunity member
Joined
Mar 2025
Message
22
#5

You can test this right now: install a network packet capture tool on your PC, connect your phone to the same Wi-Fi, and route traffic through your computer. If you can read wholesale pricing and invoice details in plain text on your monitor SSL pinning isn't in place.

NNeslihan E***Member
Job title
Board member
Sector
Security services
Organization type
8-person team
Joined
Apr 2025
Message
35

Doki · Corporate website · 2023

#6

People obsess over locking down the mobile client and forget the real front door: the API. Even if you turn your mobile app into an impenetrable fortress, an attacker won't bother using it; they'll just hit your API endpoints directly. Never treat the mobile client as a trusted environment—all validation logic belongs on the server.

OOrhan B***VeteranCommunity member
Joined
Jan 2023
Message
26
#7

We ran into this exact issue last year on a B2B wholesale app. A dealer intercepted the request while placing an order and sent a unit price of 15 TL instead of 150 TL to the API. The price field was locked on our mobile screen, but our backend blindly accepted the incoming price. We only caught it two weeks later during inventory counts. Double-check all server-side price validations.

MMeryem M***Veteran
Job title
Data entry clerk
Sector
Security services
Organization type
8-person team
Joined
Oct 2023
Message
220
#8

dont forget to disable debug logs user data and tokens can leak straight into logcat clear all console logs before pushing to stores.

İİbrahim Y***Expert
Job title
Project manager
Sector
Paper
Organization type
boutique agency
Joined
Jan 2023
Message
120
#9

Since your application stores financial data that qualifies as commercial trade secrets for corporations and sole proprietorships, any potential leak triggers a mandatory data breach notification to the Kişisel Verileri Koruma Kurumu under KVKK regulations. Documenting and maintaining your data security protocols is a strict legal necessity.

NNecati Ş***VeteranCommunity member
Joined
Nov 2024
Message
91
#10

wait so with this reverse engineering thing, dealers or anyone else can just download the app and inspect our entire source code on their computer? doesnt the app store review process block that?

LLale Y***MemberCommunity member
Joined
Jul 2025
Message
378
#11

Correct.

KKemal T***Member
Job title
IT manager
Sector
Accounting & advisory
Organization type
two-branch business
Joined
Nov 2023
Message
121

Doki · Corporate website · 2024

#12

Thanks this was very helpful.

RReyhan Ö***MemberCommunity member
Joined
Sep 2024
Message
280
#13

Don't miss this: When you try to change everything at once, nothing settles.

Just leaving this note, it might be useful.

Doki ekibiDoki team
Job title
Official account
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Mar 2023
Message
310
#14

Let me share what happened to me; it might be useful. Hasty decisions become decisions you have to fix six months later.

GGökhan B***Expert
Job title
Information Security Specialist
Sector
Software
Organization type
8-person team
Joined
Nov 2023
Message
20
#15

i diddnt know that.

OOrhan A***Member
Job title
QA Tester
Sector
Software
Organization type
40-person manufacturing company
Joined
Jan 2024
Message
2
#16

Here's how it went for us. Trying to do this alone is the most expensive way.

Hope this helps.

MMuhammetNew member
Job title
Association manager
Joined
Oct 2024
Message
34

Doki · Corporate website · 2025

#17

there are three things to check when doing this but securitty isn't absolute; it's about making attacks not worth the effort.

don't hesitate to ask; those who don't ask always pay more. i mean if I were you, I'd go this route.

BBora G***Expert
Job title
Product Manager
Sector
Healthcare services
Organization type
20-person company
Joined
Jul 2022
Message
292

Doki · Infrastructure migration · 2026

#18

I've been down this road, let me tell you. Security isn't absolute; it's about making attacks not worth the effort.

Correct me if I'm wrong.

FFerhat E***MemberCommunity member
Joined
Nov 2025
Message
134
#19

Don't miss this: Just because everyone does it doesn't mean it's right.

Forgotten test environments are more often the entry point than live systems.

PPınarExpert
Job title
Analytics Specialist
Joined
Jan 2024
Message
198

Doki · Mobile app · 2025

#20

The answer above hits the nail on the head. Solutions that work at a small scale collapse when you grow; I learned this late.

People defend habits, not processes. Resistance comes from there. That's all, sorry if I went on too long.

Reply