MOBILE APPLICATION PENETRATION TESTING

Your app is already in the attacker’s hands.

The moment your app reaches the store, anyone can download it, take it apart on their own device and study it offline, the keys inside it, the data it stores, and how it talks to your servers. Our mobile penetration testing covers both halves, the iOS or Android app and the APIs behind it, by hand, and proves what an attacker could extract, bypass or abuse.

How a mobile pentest works
87%
of our clients renew annually
150+
organisations across multiple European countries
7/10
confirm findings their previous provider did not find
Want to know what your app actually exposes? Share your main concern and your email.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by product and security teams in highly regulated environments

Detect what an attacker pulls out of your app.

attacker workbench · live
GOAL · ANOTHER USER’S DATA
ipatool · apkpure public store · no privileged access LIVE
acme
acme.example · v4.12 · 4.2 ★ (12,431)
App Store · Play Store
$ipatool download -b com.acme.app -o ./acme.ipa
$apkpure pull com.acme.app -o ./acme.apk
acme.ipa 42.7 MB
acme.apk 38.1 MB
MOBILE → BACKEND PIVOT 5 HOPS · ~35 MIN
·static_secretsAWS key + JWT secret hard-coded in the APK
·runtime_bypassSSL pin off · biometric prompt skipped via Frida
·ipc_abuseexported Activity launches authenticated WebView
·backend_pivotIDOR on /v1/users/{id} · cross-tenant PII pulled

Unlike a web app, your mobile app runs on a device you do not control. An attacker can install it, tamper with the phone, and study the app for as long as they like. We test from exactly that position.

We take the app apart without running it, reading its code and the secrets left inside, then watch it while it runs on a tampered device to see what it leaks. Then we follow the app to its backend and test the API behind it, which is very often the real prize.

WHAT WE TEST
  • Data the app leaves on the phone
  • Secrets hardcoded in the binary
  • Traffic to your servers and certificate pinning
  • Login, sessions, tokens and biometrics
  • Root, jailbreak and tampering defences
  • Deep links, WebViews and inter-app messaging
  • The backend APIs the app talks to
  • Third-party SDKs and what they collect

Why a CTO, CISO or product lead books a mobile pentest.

A new release, a payments or onboarding flow going live, an app-store or enterprise-customer requirement, a fraud spike, or a compliance audit forces the question.

TAP A SITUATION
Compliance & audit ISO 27001 audit window

An auditor does not accept a marketing PDF, and an app handling card data raises the bar.

With PCI DSS, ISO 27001, ENS or GDPR on the line, the report has to survive scrutiny: traceable scope, a methodology mapped to the recognised mobile standard, signed retest and an execution certificate.

  • Methodology mapped to OWASP MASVS and MASTG, plus PTES and NIST SP 800‑115
  • Cardholder-data handling on the device and in transit assessed
  • Execution certificate ready for the auditor folder
  • Retest evidence with timestamps and signoff
Board & customer Enterprise customer security questionnaire

Someone with authority asked, and ‘we’re fine’ isn’t an answer.

When the ask is for assurance, you need an external, expert-led mobile pentest and a deliverable that maps to business impact in language a non-technical stakeholder can read.

  • Executive summary that lands without translation
  • Findings ranked by business impact and audit exposure
  • Evidence formatted for app-store, partner and procurement review
  • Independence: external and expert-led throughout
Release & change New app or major release

You are shipping a new build. Verify the new behaviour.

The cheapest moment to validate is right at the change. We test the new build on both sides, the app on the device and the API behind it, and retest after the fix to confirm nothing leaked between releases.

  • Scope tuned to what is shipping, measured against the previous build
  • Certificate pinning, root and jailbreak detection and biometric gates pressure-tested
  • Third-party SDKs reviewed for what they collect and where they send it
  • Critical findings reported live, so fixes happen mid-release
Incident-driven Fraud or API abuse from the app

Something looked off. You need to know what is still exposed.

We reproduce the extraction on a tampered device, follow the token to the API that accepts it, and map the adjacent paths an attacker would take next.

  • Targeted scope around the suspected extraction or abuse path
  • Adjacent paths mapped: on-device storage, deep links, inter-app messaging, backend APIs
  • Certificate pinning and root or jailbreak detection tested as built, not as documented
  • Live findings to your responders, not the final report
Business event Newly acquired app or company

A transaction put the app under someone else’s eyes.

Anyone can download the binary, take it apart on their own device and study it offline: that is where we start, and then we follow the app to the backend behind it. What you are taking on ends up measured.

  • Scope agreed against the app as shipped, plus the APIs it consumes
  • Secrets and keys inside the binary found by static analysis, not assumed absent
  • Findings ranked by business impact, in language a non-technical reader follows
  • Retest to closure, so the handover ends with the gaps closed

Ready to see what your app is exposing?

Book a call
Thirty minutes with an experienced pentester.

A seven-phase method, for your mobile security pentesting.

The route we take through an iOS or Android app, from the build in our hands to the retest that closes each finding. The short version is below; the full step-by-step lives on its own page.

What you actually get, and why it is different.

Most mobile tests scan the binary and stop. Here is where we go further.

Both halves, one engagement

We test the app and the backend API it depends on together, because a leaked key on the device only matters when we prove what it unlocks on the server.

By hand, on a real tampered device

A senior specialist runs the app on a rooted or jailbroken phone and validates every finding. No emulator-only scan, no false positives, only what genuinely works.

Mapped to the standard auditors accept

Every finding is mapped to OWASP MASVS and MASTG, the recognised mobile security standard, so your report is one your customers’ procurement teams and your auditors already trust.

Closed, not just reported

Findings arrive live in our platform, and a free retest confirms each fix against the original proof. Your security improves, not just your paperwork.

Want to see what your next mobile pentest with us would look like?

We at Etnia highly value our collaboration with Asperis Security.
Sergi Leno, Systems Manager · ETNIA Barcelona

Loved by engineering and security teams.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
Sergi Leno, Systems Manager
ETNIA Barcelona
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS
READY WHEN YOU ARE

Want a real mobile scope?

Tell us your app, your target platform and where you want us to start. An experienced consultant will reply.

Questions that come up before signing.

Mobile application penetration testing is a manual security assessment of your iOS or Android app and the backend it talks to, performed from the position of an attacker who has downloaded the app onto their own device. It checks what the app stores, what secrets it hides, how it protects its traffic, whether its defences can be bypassed, and whether its APIs can be abused. The deliverable is a short list of proven, exploitable findings, each ranked by business impact with a reproducible proof of concept.

Yes, and it should. The app on the device is where an attacker finds the keys, tokens and endpoints; the backend API is where they use them to reach data or abuse functionality. We test both in one engagement by default. If you only need the API tested, our API pentesting service covers it on its own.

Yes. We test iOS and Android as separate targets, because their storage, permission and platform models differ and a flaw on one is often not present on the other. If you ship both, we scope both; if you ship one, we focus there. The report treats each platform on its own terms and highlights issues shared across them.

No. We test a build you provide on our own devices, not your users’ phones or your production data. Where the backend is in scope, we agree Rules of Engagement, test windows and rate limits in advance, and touch production only for explicitly authorised, non-destructive actions with your team informed.

A single-platform app typically takes one to two weeks of active testing; testing both iOS and Android, or including a complex backend, runs two to three weeks. Scoping happens beforehand and the retest follows your fixes. We confirm the timeline in the proposal, delivered within 48 hours of the first call.

Price follows scope: one platform or both, the app’s complexity, and whether the backend API is included. We quote a fixed price with no hidden fees and no obligation to renew. A single-platform app assessment sits at the bottom of the range; both platforms with backend testing scale from there. The retest that confirms your fixes is always included.

The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSWE and OSEP credentials, works by hand against OWASP MASVS and MASTG, and we are NASA Bug Bounty verified contributors. The same person scopes, executes and retests. They are your point of contact from start to finish.

We follow the OWASP Mobile Application Security project, MASVS for the verification requirements and MASTG for the testing methodology, alongside PTES and NIST SP 800‑115. This is the recognised standard for mobile security, so the report maps cleanly to what auditors and enterprise customers expect, and to the OWASP Mobile Top 10 risks they ask about.

Ready to test your app?

Start with a no-obligation introductory meeting. We will review your platforms, your app’s sensitive flows and your backend, and define the right mobile pentest before the project begins.

Request a mobile pentest proposal.
An experienced mobile pentester replies within one business day. You talk to the person who runs the test.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly.

OUR CLIENTS HAVE ALREADY DONE IT

We at Etnia highly value our collaboration with Asperis Security.

Sergi Leno, Systems Manager
ETNIA Barcelona

ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.

Jordi Bondia, IT Director
SALVI

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.

Sergi Laencina Verdaguer, CISO
NPAW

With Asperis you don’t hire a service. You hire a partner.