PEN / PEN-05
Mobile application security testing
Assessment of an Android or iOS application and its communications to identify exposed data and inadequate security controls.

WHEN IT HELPS
A focused response
to a defined need.
Mobile software vendor or CTO; store release, field application or personal-data processing.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Local storage and secrets
- authentication and communications
- permissions, release settings and interaction with in-scope APIs
Deliverables
- Platform-specific report
- minimised evidence
- separate application-side and server-side remediation
Acceptance evidence
Findings reference a specific version and test scenario; server-side dependencies are identified.
DELIVERY
How the work is structured.
Approach
Obtain authorisation and rules of engagement; prepare accounts and backups; perform controlled tests; debrief, clean up and arrange retesting.
Prerequisites & responsibilities
Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.
Scope factors
Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.
Questions to clarify
Which platforms and versions? Is a test build available? Is the API included in the engagement?
IMPORTANT BOUNDARIES
Device protections do not replace API controls; specify devices, versions and permitted testing techniques.
No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A field-service app stores customer documents on phones. Project: examine storage and logout behaviour. Target outcome: stronger local protection and cleanup rules, verified on test devices.
Scenario 02
A loyalty app embeds a shared secret in its binary. Project: assess its use and server controls. Target outcome: remove the distributed secret and implement appropriate access controls; obfuscation alone is not presented as a sufficient fix.
Technology and reference context
OWASP MASVS/MASTG; dedicated devices and synthetic data.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
