Android & iOS

OWASP MASVS-aligned

Starting at $1,499

Find Exploitable Vulnerabilities in Your Android and iOS Applications Before Attackers Do

Expert-led mobile application penetration testing covering application security, authentication, authorization, local data storage, network communications, business logic, platform interactions, and the APIs used by your mobile app.

Delivered byValueMentor security testers.
DeliveryExpert-Led Testing
TestingManual + Automated
AssuranceRetesting Included

The definition

What is mobile application penetration testing?

Mobile application penetration testing is a security assessment in which security professionals attempt to identify and exploit vulnerabilities in a mobile application and its associated attack surface. Testing can include the mobile application itself, authentication and authorization, local storage, network communication, platform interactions, business logic, and the APIs used by the application.

Mobile applications introduce security risks that go beyond traditional web application testing. Sensitive information may be stored on the device, authentication tokens can be exposed, application traffic can be intercepted, platform features can be misused, and business logic and authorization weaknesses can allow users to access functions or data they should not have. Secusy combines structured testing with expert-led manual penetration testing to identify vulnerabilities that automated scanners alone may miss.

  • Android & iOS

    Expert-led testing for production or production-equivalent mobile builds.

  • OWASP MASVS-aligned

    Assessment aligned with OWASP Mobile Application Security Verification Standard.

  • Manual + tool-assisted

    Combines manual testing with static and dynamic analysis techniques.

  • Report & retest

    Executive summary, detailed findings, and retest included on fixed tiers.

Choose Your Mobile Application Penetration Test

Select Standard or Advanced based on your application's user roles and API endpoints. Larger or more complex applications can request custom pricing.

Standard

For small to medium mobile applications with straightforward user journeys and API integrations.

$1,499

Includes
  • 1 Android or iOS application
  • Up to 2 user roles
  • Up to 20 API endpoints
  • Standard authentication and authorization flows
  • Standard business workflows
  • One production or production-equivalent build
  • Remote testing
  • Manual mobile application penetration testing
  • Static and dynamic application analysis
  • Local data storage & network communication testing
  • Cryptographic implementation review
  • OWASP MASVS-aligned assessment
  • Executive summary & detailed technical report
  • 1 retest

Typical testing effort: approximately 3 tester-days

Custom

For complex applications and mobile ecosystems that exceed the fixed-price packages.

Get Pricing

Choose Custom if your assessment includes
  • More than 4 user roles
  • More than 40 API endpoints
  • Multiple mobile applications
  • Complex financial or transaction workflows
  • Extensive third-party integrations
  • Complex identity or authentication architecture
  • Large or highly distributed backend environments
  • Additional testing requirements

Timeline and testing effort are agreed after scoping.

Compare Plans

FeatureStandardAdvancedCustom
Price$1,499$2,499Custom
Mobile applications11Custom
PlatformAndroid or iOSAndroid or iOSAndroid / iOS
User rolesUp to 2Up to 45+
API endpointsUp to 20Up to 4041+
Retest11Defined by scope
Approx. testing effort3 tester-days5 tester-daysScoped
Additional equivalent platform+50%+50%Scoped
Manual penetration testing
Static & dynamic analysis
Business logic testing
OWASP MASVS aligned
Technical report
Executive summary

Need Both Android and iOS Tested?

If your Android and iOS applications provide substantially the same functionality, use the same backend APIs, and have the same user roles, you don't necessarily need two completely separate assessments. Add the equivalent second platform for 50% of the base package price.

PackageFirst PlatformAndroid + iOS
Standard$1,499$2,248.50
Advanced$2,499$3,748.50

If the Android and iOS applications differ materially in functionality or architecture, they are scoped as separate applications.

Coverage

What We Test

Testing is risk-based and tailored to the functionality exposed by your mobile application.

Mobile Application Security

We assess the application itself for weaknesses that could expose sensitive information or allow an attacker to manipulate application behavior.

  • Application package analysis
  • Sensitive information exposure
  • Insecure local storage
  • Application logs and cached data
  • Hardcoded secrets
  • Application configuration
  • Backup-related exposure
  • Clipboard and screenshot exposure where relevant
  • Application permissions
  • Platform-specific security controls

Authentication & Session Security

We test how the application establishes and maintains user identity.

  • Login mechanisms
  • Authentication bypass
  • Session handling
  • Token security
  • Credential storage
  • Logout behavior
  • Password-reset flows
  • OTP and MFA implementation
  • Biometric authentication implementation
  • Account recovery mechanisms

Authorization & Access Control

Authentication tells the application who the user is. Authorization determines what that user is allowed to do.

  • Horizontal privilege escalation
  • Vertical privilege escalation
  • Insecure direct object access
  • Role manipulation
  • Unauthorized function access
  • Unauthorized data access
  • Client-side authorization weaknesses

Data Storage & Privacy

We examine how sensitive information is handled on the mobile device.

  • Application storage & databases
  • Preferences & cached information
  • Application logs & temporary files
  • Authentication tokens & credentials
  • Personally identifiable information
  • Other sensitive application data

Network Communications

We assess communications between the application and remote services.

  • TLS implementation
  • Certificate validation
  • Network traffic exposure
  • Man-in-the-middle attack resistance
  • Sensitive information transmitted over the network
  • Certificate pinning implementation where applicable

Cryptography

Where cryptography is implemented by the application, we examine relevant areas.

  • Weak cryptographic algorithms
  • Improper key management
  • Hardcoded cryptographic material
  • Predictable values
  • Incorrect cryptographic implementation
  • Sensitive-data protection

Platform Interaction

Android and iOS applications interact extensively with their underlying operating systems.

  • Android intents, activities, services & broadcast receivers
  • Content providers
  • Deep links, URL schemes, app links & universal links
  • Inter-process communication
  • Application permissions
  • Keychain/Keystore usage
  • Other exposed application components

Code & Resilience

Where applicable to the assessment, we examine reverse-engineering and tampering risks.

  • Application reverse engineering
  • Code obfuscation
  • Debugging
  • Runtime manipulation & application tampering
  • Rooted or jailbroken environments
  • Application integrity controls
  • Embedded secrets

Business Logic

Our testers manually examine important application workflows for ways an attacker could manipulate intended business processes.

  • Bypassing required steps
  • Manipulating transactions
  • Abusing account workflows
  • Circumventing application restrictions
  • Replaying transactions
  • Changing parameters
  • Exploiting differences between user roles

API Testing Included — Within Your Mobile App Scope

Most modern mobile applications depend heavily on backend APIs. Your mobile penetration test therefore includes security testing of the APIs directly used by the in-scope mobile application, up to the endpoint limit of your selected package. For scoping purposes, an API endpoint is counted by the combination of the HTTP method and route — for example, GET /users/{id}, PUT /users/{id}, and POST /payments each count as one endpoint.

StandardUp to 20API endpoints
AdvancedUp to 40API endpoints

The included API testing is intended to assess attack paths associated with the mobile application. It is not a substitute for a comprehensive penetration test of your entire API estate.

Standards

Aligned With OWASP Mobile Security Standards

Our mobile application penetration testing methodology is aligned with the OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP Mobile Application Security Testing Guide (MASTG). Testing considers relevant areas including:

  • MASVS-STORAGE

    Secure storage of sensitive information on the device.

  • MASVS-CRYPTO

    Cryptographic mechanisms used to protect sensitive information.

  • MASVS-AUTH

    Authentication and authorization mechanisms.

  • MASVS-NETWORK

    Secure communications between the mobile application and remote endpoints.

  • MASVS-PLATFORM

    Secure interaction with Android or iOS and other applications.

  • MASVS-CODE

    Security controls relating to application code and processing.

  • MASVS-RESILIENCE

    Resistance to reverse engineering and tampering.

  • MASVS-PRIVACY

    Controls protecting user privacy.

How it works

How Mobile Application Penetration Testing Works

  1. Step 1

    Choose Your Package

    Select Standard or Advanced based on the number of user roles and API endpoints in your application. Applications exceeding the fixed package boundaries can request custom pricing.

  2. Step 2

    Purchase Online

    Complete checkout directly through Secusy with transparent scope and pricing. No sales call is required for applications that fit within the Standard or Advanced scope.

  3. Step 3

    Complete Your Secure Intake

    After purchase, access the Secusy portal and provide the information required to begin testing: build or download instructions, environment details, test accounts, roles, API information, authentication instructions, and testing authorization.

  4. Step 4

    Expert-Led Testing Begins

    ValueMentor security testers perform the assessment using manual penetration testing, security tools, static analysis, dynamic analysis, and mobile-specific testing techniques.

  5. Step 5

    Receive Your Penetration Test Report

    Once testing is complete, your report — executive summary, scope, methodology, risk-rated vulnerabilities, evidence, impact analysis and remediation recommendations — is made available through the Secusy platform.

  6. Step 6

    Fix and Request Your Retest

    Your development team remediates the identified vulnerabilities and requests the included retest. We verify remediation within the agreed retest scope and provide an updated report.

Intake

What You Need to Provide

To begin testing, you should be able to provide the following. We recommend using a production-equivalent test environment whenever possible.

You will normally provide

  1. A testable Android or iOS application
  2. Authorization to perform penetration testing
  3. Test accounts for each included role
  4. Access to the relevant test environment
  5. Any required MFA or OTP access
  6. API documentation where available
  7. Application workflow information where needed
  8. Technical contact for testing-related questions

Included

What you get

At the end of the assessment, you receive a professional mobile application penetration testing report suitable for security, development, management, customer assurance, and remediation purposes.

Standard and Advanced include

  • Executive Summary — A management-level overview of the application's security posture and significant findings.
  • Detailed Technical Findings — Evidence and technical information needed to understand identified vulnerabilities.
  • Risk Ratings — Findings prioritized according to their security impact and relevant risk factors.
  • Remediation Guidance — Practical recommendations your development team can use to address identified vulnerabilities.
  • Retest Results — Verification of remediated findings covered by the included retest.
  • Updated Final Report — An updated report reflecting the status of findings following retesting.

Scope boundaries

What's Not Included in the Fixed-Price Packages?

To keep Standard and Advanced pricing predictable, the following are not automatically included unless explicitly stated in the purchased scope:

  • Source code review
  • Full API estate penetration testing
  • Cloud infrastructure penetration testing
  • Web application penetration testing
  • Network penetration testing
  • Thick-client applications
  • Multiple materially different mobile applications
  • More roles or API endpoints than the selected package allows
  • Social engineering
  • Denial-of-service testing
  • Physical security testing
  • Remediation implementation

Why Secusy?

Expert-Led Testing

Not simply an automated mobile vulnerability scan — testers manually investigate vulnerabilities, attack paths, authorization weaknesses, and business-logic issues.

Clear Fixed Pricing

Know the cost and scope before purchasing. Standard mobile applications can start immediately without a lengthy sales and quotation process.

Built Around OWASP MASVS & MASTG

Testing is aligned with OWASP MASVS and MASTG to provide structured coverage of important mobile application security risks.

Security Expertise Powered by ValueMentor

Secusy is the digital purchasing and service-delivery platform for ValueMentor cybersecurity services.

One Platform for Your Security Journey

Use Secusy to purchase, onboard, track, and consume cybersecurity services — and extend your security program as your requirements grow.

Questions

Frequently asked questions