Platform
Android applications
App Defense Alliance MASA AL1
Android apps
Get automated security testing, MASA requirement validation, evidence review, clear remediation findings, and one retest — starting at $499 per Android application.
The definition
Android applications
App Defense Alliance (ADA)
OWASP mobile application security standards
1 included per application
Simple pricing based on the number of Android applications you need assessed.
$499per app
$449per app
Custom
| Feature | 1–2 Apps | 3–4 Apps | 5+ Apps |
|---|---|---|---|
| Best for | Developers and organizations with one or two Android apps | Organizations managing multiple Android applications | Organizations, developers, and publishers with larger Android portfolios |
| Retest | 1 included per app | 1 included per app | Based on scope |
| Remediation window | Up to 60 days | Up to 60 days | Based on scope |
| MASA AL1 assessment | |||
| Automated security testing | |||
| MASA requirement validation | |||
| Self-attestation & evidence review | |||
| Findings report & remediation guidance |
Every standard assessment includes one remediation retest per application. Additional retests are $199 per application.
Each distinct Android application is treated as one MASA AL1 assessment. Pricing applies per Android application, not per organization or developer account. iOS applications are outside the scope of this service.
Your Android application is evaluated against the applicable MASA AL1 requirements.
How the application handles sensitive information, credentials, cryptographic keys, and other protected data — including secure storage, application logs, sensitive information displayed through the UI, and privacy-related controls.
The application's use of cryptography, including hardcoded cryptographic keys, deprecated algorithms, and insecure cryptographic implementations.
Authentication mechanisms, credentials, and session-management controls, evaluated against the applicable requirements where relevant.
Security of communications between the application and remote services, including TLS implementation and certificate validation.
How the application interacts with the Android platform, including permissions, exported functionality, external inputs, and inter-process communication.
Applicable security-related application configuration and build characteristics, including release configuration, debugging functionality, and third-party components.
A simple digital process from purchase to completed assessment.
Select the number of Android applications you want assessed. 1–4 apps can be purchased directly online; 5+ apps route to volume pricing.
Access Secusy and provide what the assessment needs — Google Play details, the app package or build, test credentials, app information, a completed self-attestation, supporting evidence, and assessment authorization.
Your application is evaluated against the applicable MASA AL1 requirements, combining automated security testing with review and validation of requirements, declarations, and supporting evidence.
If requirements aren't satisfied, you receive clear findings showing what needs to be addressed, so your development team understands the issue and the requirement it maps to.
Fix the identified issues and submit the updated build or evidence through Secusy. One remediation retest per application is included, focused on validating the requirements that weren't satisfied.
Once the applicable requirements are satisfied, we complete the MASA AL1 assessment and validation process, and issue applicable validation documentation.
Included
Standard assessment includes
Scope boundaries
If your application requires a higher assurance level, see MASA AL2 Assessment. If deeper security testing is required, a Mobile Application Penetration Test can be purchased separately.
Intake
To avoid delays, be ready to provide the information and access required to assess your application. Incomplete information, inaccessible functionality, or invalid test credentials may delay the assessment.
You will normally provide
All three validate Android app security, but at different depths. Choose MASA AL1 for the streamlined, fixed-price requirement. Choose MASA AL2 when your OAuth scope or platform requires higher-assurance, lab-led validation. Choose a mobile application penetration test when you need broader security assurance beyond the defined MASA scope.
| Feature | MASA AL1 | MASA AL2 | Mobile App Pentest |
|---|---|---|---|
| Best for | MASA AL1 requirement | Higher-assurance MASA requirement | Deeper application security assurance |
| Primary purpose | Validate applicable MASA AL1 requirements | Higher-assurance, lab-led MASA validation | Identify exploitable security vulnerabilities |
| Scope | Defined MASA requirements | Defined MASA requirements, lab-led | Broader application attack surface |
| Testing approach | Standardized AL1 assessment | Higher-assurance lab assessment | Expert-led security testing |
| Automated testing | Yes | Yes | Yes |
| Lab-led / manual testing | Limited | Yes | Extensive |
| Business logic testing | Not the primary purpose | Where required by scope | Included where applicable |
| MASA validation | Yes | Yes | No |
| Starting price | $499/app | $2,999/app | $1,499/platform |
Questions