SERVICE / 02 · IOS / ANDROID

Mobile penetration testing

What stays on the device and what travels to your backend. We analyse the app and its connections to find where trust between the two breaks.

The app in the store is only half of it. The other half is what it keeps on the phone, how it talks to your backend, and what happens when the device is in the hands of someone it should not be.

We combine static analysis of the binary with dynamic testing on the device, and reach the APIs the app consumes.

What we look at

  • Static and dynamic analysis of the binary
  • Local storage and secrets on the device
  • Communications, certificates and pinning
  • The backend APIs the app consumes

What you get

  • Static and dynamic analysis
  • Storage
  • Communications
  • APIs

Related services

Shall we put this to the test?

We define the scope with you and start with written authorisation.

Request an assessment
KNULL / DATA
DATA / CONTACT

Only what
we need.

This page collects nothing. The request form on the home page stores only what you send it, on the server that hosts this site, with no analytics and no AI model.