Mobile Application Security Assessment
Static and dynamic analysis of your Android and iOS applications and the backend APIs they consume, aligned with the OWASP Mobile Application Security Verification Standard.
The app ships to thousands of devices you do not control. Tokens sit in local storage, deep links open screens they should not, and the backend trusts checks that only ever ran on the client. A store review is not a security review, and the API behind the app has usually never been tested under a valid session.
What the assessment covers
AZRE Consulting assesses the in-scope Android and iOS applications through combined static and dynamic analysis, covering both the mobile client itself and the backend APIs it consumes. Testing is aligned with the OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP Mobile Top 10.
- Applications: native and cross-platform Android and iOS applications, in every supported language and layout direction
- Builds: internal-distribution builds for both platforms, so traffic can be intercepted under a controlled proxy where release builds would refuse a user-installed certificate
- User roles: unauthenticated flows such as registration, account recovery, and identity verification, and authenticated users with and without a completed onboarding journey
- Backend APIs: the mobile backend-for-frontend, including bearer-secured, unauthenticated, multi-step ceremony, and file-upload endpoints, together with the identity provider flow the app authenticates through
- Access model: grey box, with test accounts for each role and the build variants needed for interception
Key testing areas
- Static analysis: binary and source review for hardcoded secrets, API keys, cryptographic material, debug artifacts, and insecure third-party libraries
- Insecure data storage: credentials, tokens, and sensitive data held in local databases, shared preferences, keychain and keystore, caches, logs, and backups
- Platform interaction: exported components, deep-link and intent handling, inter-process communication, clipboard exposure, screenshot and background caching, and file-provider abuse
- Transport security: TLS configuration, certificate validation and pinning, and resilience against interception under a controlled proxy
- Runtime and client-side trust: root and jailbreak detection, debugger and emulator checks, code obfuscation, and authorization or feature gating enforced on the client rather than the server
- Authentication and session handling: token storage and lifecycle, biometric authentication flows, device binding, and session invalidation on logout or credential change
- Backend API testing: full authenticated testing of the mobile API surface, including authorization, object-level access control, and business logic abuse under valid sessions
Methodology
All activities follow recognised application security and risk management frameworks, including OWASP MASVS, the OWASP Mobile Top 10, the OWASP API Security Top 10, NIST SP 800-53 and SP 800-115, and the security control expectations defined under ISO/IEC 27001 and SOC 2. Testing combines deep manual exploration with targeted automated analysis, and every finding is manually validated to eliminate false positives.
How the engagement runs
The engagement follows a four-step process designed to fit existing engineering workflows without operational friction or downtime.
- Alignment and onboarding: a dedicated engagement lead and a testing team matched to your technology stack; a kick-off to align on scope, business logic, and no-go zones; and the secure handover of builds, test accounts, and access allowances
- Active testing and live collaboration: deep manual testing alongside automated analysis, in constant contact with your technical leads; any critical or high-risk finding is reported immediately so remediation can begin in parallel
- Analysis and technical debrief: a comprehensive preliminary report with proof-of-concept evidence and actionable hardening recommendations, followed by a findings walkthrough with the engineering and product teams
- Verification and closure: targeted re-testing once fixes are implemented, confirming that vulnerabilities are resolved and no regressions were introduced, then the final certified report and archival of all project data
- Immediate notification of every critical or high-risk finding, during testing
- Preliminary report with proof-of-concept evidence for each finding, across client and backend
- Risk-rated findings mapped to MASVS controls, with actionable hardening recommendations
- Findings walkthrough with your engineering and product teams
- Targeted re-test of every remediated finding
- Final certified report
The outcome
The app, and the API behind it, hold up on a device the attacker controls, and the controls that matter are enforced on the server rather than trusted to the client.
Start with a conversation, not a proposal.
Tell us what is happening in the business. If we are the wrong firm for it, we will say so and point you somewhere better. If we are the right firm, you will leave the conversation with a clearer read on the problem than you came in with.
Start a conversation