Skip to content
Vaptiq logo mark — V orientationVAPTIQ
All services

[ Applications ]

Mobile Application Penetration Testing

iOS and Android, tested on real devices, binary, traffic and backend.
Typical duration
6-10 days
Starting price
Scoped
You provide
Builds for both platforms, test accounts

[ 01 / The engagement ]

A mobile app is three targets in one: the binary on the device, the transport between it and you, and the backend it talks to. We test all three on real hardware, including jailbroken and rooted devices, against the OWASP MASVS, because the protections that hold on a stock handset often disappear the moment somebody roots one.

[ 02 / Coverage ]

What we test, in practice.

This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.

Methodology

OWASP MASVSOWASP MASTG
  1. 01Static analysis of the binary, hardcoded secrets and API keys
  2. 02Insecure local storage, keychain and keystore misuse
  3. 03Certificate pinning strength and bypass under instrumentation
  4. 04Runtime manipulation with Frida and Objection
  5. 05Deep link, intent and inter-process communication abuse
  6. 06Backend API testing with a mobile client's privileges
  7. 07Root and jailbreak detection resilience

[ 03 / What you get ]

Four things land at the end of every engagement.

Technical report

Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.

Executive summary

Two pages your board can read. Risk in business terms, with the three things that matter most called out.

Letter of attestation

A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.

Free retest

Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.

[ 04 / Questions ]

Before you commit.

No, a TestFlight build or a signed APK is ideal, since it lets us test before your users can reach the flaw.

Yes, and it is cheaper than two separate ones because the backend work is shared. The report separates platform-specific findings clearly.

Scope a mobile application penetration testing.

Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.