Let's talk about your project
DOKI / Cybersecurity

Cybersecurity · Mobile apps

We examine your Android and iOS app from inside the device and from the network side: which permissions it asks for, how it stores data on the device, how it talks to the server. Findings are reported in an order you can close before store submission.

  • App permissions
  • Data flow
  • Storage review
  • Risk table
01 / What this service includes

Three layers the app does not show.

01

Data stored on the device

Are session tokens, personal data and cached files kept in secure storage or in plain files? We also check what leaks into backups and screenshots.

02

Talking to the server

We intercept the traffic and test whether encryption, certificate validation and API authorisation allow access to someone else's account.

03

Permissions and the app package

Every requested permission needs a reason. We also inspect keys embedded in the package, debug leftovers and protection against reverse engineering.

02 / How it works

The four layers of the review

Between what the screen shows and what the server holds lie four layers, each with its own risks and its own tests.

App and permissions
Network traffic
Server API
On-device storage
03 / Scope

Let's define the scope together.

We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.

Only explicitly authorized assets and agreed scope are assessed.

Deliverables

  • 01App permissions
  • 02Data flow
  • 03Storage review
  • 04Risk table
04 / Process

How we move forward, step by step.

Each step ends with something concrete in your hands; we move on with your approval.

  1. 01

    Scope

    Together we put the goal, the boundaries and the acceptance criteria in writing.

  2. 02

    Assessment

    We assess the current state against agreed criteria and note gaps with evidence.

  3. 03

    Reporting

    We share what was done, the result and the next step in a plain report.

  4. 04

    Retest

    We retest fixed findings and confirm with evidence that they are closed.

05 / Scope

Test categories applied in this service

Which categories are applied is agreed together, based on your target and scope.

Mobile layer

We examine your Android and iOS app both through its code and while it runs.
Number of categories: 1
  • Android and iOS app security analysis (static and dynamic)

    We examine your app both through its code and while it runs: data storage on the device, network traffic, authentication and the app's own protection.

The figures are the number of checks in our automated security engines. Not every category runs in every test; the ones that fit your target and scope are selected.

Every test runs with your written permission and within the scope we agree together. Tests that could disrupt a service, and social engineering, are planned only with separate written approval. No test proves that a system is completely secure; we report clearly what was and was not found.

06 / Decision details

What to know before you ask for a quote.

What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.

Included

  • Permissions, data flows and data stored on the device.
  • Evidence, a risk level (critical, high, medium, low) and a fix recommendation for every finding.
  • One retest within 30 days of the report is included in the price.

Not included

  • Fixing the findings (offered separately as Remediation).

What we need from you

  • A signed written authorisation.
  • The app file (APK or IPA) or its store link.
  • Test accounts for a grey-box test.

Timing and delivery

  • Tests run on weekdays between 09:00 and 18:00 (Türkiye time).

What sets the price

  • One platform (Android or iOS), or both.

Payment and aftercare

  • For work agreed in person, the full fee is paid at the start.
  • For remote work, half is paid at the start and half on delivery.
  • We respond to every request within 12 hours.
  • Meetings are held in Turkish; correspondence and deliverables are handled in the language of your choice with translation support.
  • We work in person in Istanbul and remotely across Türkiye and worldwide.
07 / FAQ

The questions on your mind.

Tell us what you need; we will define the scope together.

Tell us about your project
Do you need the app's source code for the test?

It is not required. We can work with the built app package and a test account. If you share the source code, the review goes deeper and the fix recommendations become more precise.

Is permission needed before testing?

Yes. Only systems you are authorised for and have approved in writing are assessed.

Will testing affect my live system?

Scope, time window and methods are agreed in advance; risky steps require your separate approval.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.