Data stored on the device
Are session tokens, personal data and cached files kept in secure storage or in plain files? We also check what leaks into backups and screenshots.
We examine your Android and iOS app from inside the device and from the network side: which permissions it asks for, how it stores data on the device, how it talks to the server. Findings are reported in an order you can close before store submission.
Are session tokens, personal data and cached files kept in secure storage or in plain files? We also check what leaks into backups and screenshots.
We intercept the traffic and test whether encryption, certificate validation and API authorisation allow access to someone else's account.
Every requested permission needs a reason. We also inspect keys embedded in the package, debug leftovers and protection against reverse engineering.
Between what the screen shows and what the server holds lie four layers, each with its own risks and its own tests.
We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.
Each step ends with something concrete in your hands; we move on with your approval.
Together we put the goal, the boundaries and the acceptance criteria in writing.
We assess the current state against agreed criteria and note gaps with evidence.
We share what was done, the result and the next step in a plain report.
We retest fixed findings and confirm with evidence that they are closed.
Which categories are applied is agreed together, based on your target and scope.
We examine your app both through its code and while it runs: data storage on the device, network traffic, authentication and the app's own protection.
The figures are the number of checks in our automated security engines. Not every category runs in every test; the ones that fit your target and scope are selected.
Every test runs with your written permission and within the scope we agree together. Tests that could disrupt a service, and social engineering, are planned only with separate written approval. No test proves that a system is completely secure; we report clearly what was and was not found.
What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.
Tell us what you need; we will define the scope together.
Tell us about your projectIt is not required. We can work with the built app package and a test account. If you share the source code, the review goes deeper and the fix recommendations become more precise.
Yes. Only systems you are authorised for and have approved in writing are assessed.
Scope, time window and methods are agreed in advance; risky steps require your separate approval.
Tell us what you need; we will define the scope together.