Mobile application penetration testing

Test the app on the device. And the trust behind it.

Security testing for iOS and Android apps, from local data to the backend calls in scope.

Human-led testing.
Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
What we investigate

A scope with a purpose.

Data on the device

Local storage, logs, cached content and secrets in the app package.

Platform interactions

Deep links, exported components, permissions and inter-app communication.

Network and session trust

Transport handling, token lifecycle and server-side authorisation.

Before testing

What we need from you

  • Installable iOS or Android test builds.
  • Supported OS versions and test accounts.
  • Whether both platforms and the backend APIs are in scope.
  • Any testing-specific build change, agreed in advance.
Use the scoping checklist
After testing

What you can act on

  • Platform-specific reproduction steps.
  • Evidence showing device or backend impact.
  • Fixes assigned to the app or the server-side control.

Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.

Limits matter

What this test does not cover

  • App-store approval.
  • A full backend assessment by default.
  • Every handset and OS build.
  • Hardware, baseband and third-party SDK internals.
Questions before you book

Practical answers.

Do iOS and Android count as one scope?

They share business features but have different platform controls and builds. We scope each required platform and the reusable backend work so you are not buying duplicate coverage.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.

How long will it take?

Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.

A mobile application is a client. The interesting findings are usually behind it, which makes API penetration testing the other half of the scope, and the admin surface is web application penetration testing. Sizing the engagement is covered in how to scope a penetration test, and the deliverable standard is in what a penetration test report should contain.

Let’s scope it

Let’s define your mobile applications test.

Share the assets and your reason for testing. We will confirm the approach, fee and schedule.

Request a quote

Last reviewed: