Android & iOS
Expert-led testing for production or production-equivalent mobile builds.
Android & iOS
OWASP MASVS-aligned
Starting at $1,499
Expert-led mobile application penetration testing covering application security, authentication, authorization, local data storage, network communications, business logic, platform interactions, and the APIs used by your mobile app.
The definition
Mobile applications introduce security risks that go beyond traditional web application testing. Sensitive information may be stored on the device, authentication tokens can be exposed, application traffic can be intercepted, platform features can be misused, and business logic and authorization weaknesses can allow users to access functions or data they should not have. Secusy combines structured testing with expert-led manual penetration testing to identify vulnerabilities that automated scanners alone may miss.
Expert-led testing for production or production-equivalent mobile builds.
Assessment aligned with OWASP Mobile Application Security Verification Standard.
Combines manual testing with static and dynamic analysis techniques.
Executive summary, detailed findings, and retest included on fixed tiers.
Select Standard or Advanced based on your application's user roles and API endpoints. Larger or more complex applications can request custom pricing.
For small to medium mobile applications with straightforward user journeys and API integrations.
$1,499
Typical testing effort: approximately 3 tester-days
For larger applications with more user roles, API endpoints, and complex business workflows.
$2,499
Typical testing effort: approximately 5 tester-days
For complex applications and mobile ecosystems that exceed the fixed-price packages.
Get Pricing
Timeline and testing effort are agreed after scoping.
| Feature | Standard | Advanced | Custom |
|---|---|---|---|
| Price | $1,499 | $2,499 | Custom |
| Mobile applications | 1 | 1 | Custom |
| Platform | Android or iOS | Android or iOS | Android / iOS |
| User roles | Up to 2 | Up to 4 | 5+ |
| API endpoints | Up to 20 | Up to 40 | 41+ |
| Retest | 1 | 1 | Defined by scope |
| Approx. testing effort | 3 tester-days | 5 tester-days | Scoped |
| Additional equivalent platform | +50% | +50% | Scoped |
| Manual penetration testing | |||
| Static & dynamic analysis | |||
| Business logic testing | |||
| OWASP MASVS aligned | |||
| Technical report | |||
| Executive summary |
If your Android and iOS applications provide substantially the same functionality, use the same backend APIs, and have the same user roles, you don't necessarily need two completely separate assessments. Add the equivalent second platform for 50% of the base package price.
| Package | First Platform | Android + iOS |
|---|---|---|
| Standard | $1,499 | $2,248.50 |
| Advanced | $2,499 | $3,748.50 |
If the Android and iOS applications differ materially in functionality or architecture, they are scoped as separate applications.
Coverage
Testing is risk-based and tailored to the functionality exposed by your mobile application.
We assess the application itself for weaknesses that could expose sensitive information or allow an attacker to manipulate application behavior.
We test how the application establishes and maintains user identity.
Authentication tells the application who the user is. Authorization determines what that user is allowed to do.
We examine how sensitive information is handled on the mobile device.
We assess communications between the application and remote services.
Where cryptography is implemented by the application, we examine relevant areas.
Android and iOS applications interact extensively with their underlying operating systems.
Where applicable to the assessment, we examine reverse-engineering and tampering risks.
Our testers manually examine important application workflows for ways an attacker could manipulate intended business processes.
Most modern mobile applications depend heavily on backend APIs. Your mobile penetration test therefore includes security testing of the APIs directly used by the in-scope mobile application, up to the endpoint limit of your selected package. For scoping purposes, an API endpoint is counted by the combination of the HTTP method and route — for example, GET /users/{id}, PUT /users/{id}, and POST /payments each count as one endpoint.
The included API testing is intended to assess attack paths associated with the mobile application. It is not a substitute for a comprehensive penetration test of your entire API estate.
Standards
Our mobile application penetration testing methodology is aligned with the OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP Mobile Application Security Testing Guide (MASTG). Testing considers relevant areas including:
Secure storage of sensitive information on the device.
Cryptographic mechanisms used to protect sensitive information.
Authentication and authorization mechanisms.
Secure communications between the mobile application and remote endpoints.
Secure interaction with Android or iOS and other applications.
Security controls relating to application code and processing.
Resistance to reverse engineering and tampering.
Controls protecting user privacy.
How it works
Select Standard or Advanced based on the number of user roles and API endpoints in your application. Applications exceeding the fixed package boundaries can request custom pricing.
Complete checkout directly through Secusy with transparent scope and pricing. No sales call is required for applications that fit within the Standard or Advanced scope.
After purchase, access the Secusy portal and provide the information required to begin testing: build or download instructions, environment details, test accounts, roles, API information, authentication instructions, and testing authorization.
ValueMentor security testers perform the assessment using manual penetration testing, security tools, static analysis, dynamic analysis, and mobile-specific testing techniques.
Once testing is complete, your report — executive summary, scope, methodology, risk-rated vulnerabilities, evidence, impact analysis and remediation recommendations — is made available through the Secusy platform.
Your development team remediates the identified vulnerabilities and requests the included retest. We verify remediation within the agreed retest scope and provide an updated report.
Intake
To begin testing, you should be able to provide the following. We recommend using a production-equivalent test environment whenever possible.
You will normally provide
Included
At the end of the assessment, you receive a professional mobile application penetration testing report suitable for security, development, management, customer assurance, and remediation purposes.
Standard and Advanced include
Scope boundaries
To keep Standard and Advanced pricing predictable, the following are not automatically included unless explicitly stated in the purchased scope:
Not simply an automated mobile vulnerability scan — testers manually investigate vulnerabilities, attack paths, authorization weaknesses, and business-logic issues.
Know the cost and scope before purchasing. Standard mobile applications can start immediately without a lengthy sales and quotation process.
Testing is aligned with OWASP MASVS and MASTG to provide structured coverage of important mobile application security risks.
Secusy is the digital purchasing and service-delivery platform for ValueMentor cybersecurity services.
Use Secusy to purchase, onboard, track, and consume cybersecurity services — and extend your security program as your requirements grow.
Questions