Skip to content
Halberd Security
Authorised testing only. We test only with the owner's written authorisation, so scope is agreed before testing begins. Unauthorised testing is also illegal under the Computer Fraud and Abuse Act.

Service

Mobile app penetration testing for iOS and Android

Mobile app penetration testing looks at two things: what your app leaves on the device, and how it talks to your backend when nobody is watching. Both matter, because a phone is a device you do not control.

  • Named tester before day one
  • One retest within 30 days
  • OWASP WSTG and NIST SP 800-115
Mobile app penetration testing: unpack the app, test device and api and report and retest

What mobile app penetration testing covers

The app itself is only half the story. Therefore we test the build and the backend it depends on.

  • Data stored on the device, including tokens and cached records
  • Communication with the backend, including certificate checks
  • Authentication, session handling and biometric shortcuts
  • Tampering, debugging and reverse engineering resistance
  • The API calls the app makes, and the ones it could make

A recognised method

Our checks follow the OWASP Mobile Application Security project, which covers both iOS and Android. As a result, your auditor or customer can match each finding to a published requirement.

Mobile app penetration testing checklist

Tick what you can supply. It decides how fast testing can start.

Your result appears here as you tick, so you can see what is still open.

iOS and Android differences

The platforms store data and enforce permissions differently, so each build is tested on its own.

AreaiOSAndroid
Local storageKeychain and app sandbox.Keystore, shared preferences and external storage.
Inter-app linksURL schemes and universal links.Intents, deep links and exported components.
Typical issueSensitive data in backups or logs.Exported components other apps can call.

How mobile app penetration testing is scoped

We need the builds, a test account for each role, and the API environment the app calls. The number of platforms and roles drives the effort. In addition, an app with payments or health data needs deeper backend testing.

Price range and report

Our published range is $5,000 to $40,000. One platform with a simple backend sits low; both platforms with several roles and a large API sit higher. The report includes proof and fixes for each finding, an executive summary, an attestation letter and one retest inside 30 days.

Mobile app penetration testing questions

Do you need the source code for mobile app penetration testing?

No. We test the compiled builds, as an attacker would. Source access can make some checks faster.

Can you test both platforms at once?

Yes. Each is tested separately, but the backend is shared, so combined scopes are efficient.

Is the backend API included in mobile app penetration testing?

The calls the app makes are included. A full API test of every endpoint can be added.

Do you test on jailbroken devices?

Yes, because attackers do. It shows what your app exposes when the device itself is not trustworthy.

Related guides

Get a fixed fee for mobile app penetration testing

Tell us the platforms, the roles and what the app does. We reply with a written scope and a fee.

Get my estimate