How it works?

Internet access over mobile phones is increasing at a rapid pace. In May 2012, Indian users accessing internet over mobile devices surpassed those accessing the internet over desktops and laptops (Source: Glabal StatsCounter). As a result, most companies are developing mobile based application as an avenue of interaction with its new age consumers.

Mobile App Security Testing service provides a detailed security analysis of your phone or tablet based app. A key feature of this service is manual testing by experienced security professionals, which typically uncovers many more issues than automated tests alone. This include Static Application Security Testing (SAST) & Dynamic Application Security Testing (DAST).

What is SAST?

Static analysis checks the source code of the mobile app to make sure security protections are implemented properly. A combination automatic/manual technique is typically utilised. Automatic scans identify the easy targets, allowing the human tester to explore the code base while keeping in mind certain use circumstances.


What is DAST?

DAST is focused on testing and assessing apps while they are being used in real-time. Finding vulnerabilities or weak points in a program while it is operating is the major goal of dynamic analysis. The request and response patterns of the mobile app may be examined via dynamic analysis, which is done against the backend services and APIs as well as the mobile platform layer.
In order to determine if security measures offer enough defence against the most common forms of attack, including data leakage while in transit, authentication and authorization problems, and server configuration faults, dynamic analysis is typically performed.
Android Application Testing Guide
  • Data Storage on Android
  • Android Cryptographic APIs
  • Client Code Quality and Build Settings for Android Apps
  • Tampering and Reverse Engineering on Android
  • Android Anti-Reversing Defenses


iOS Application Testing Guide
  • Data Storage on iOS
  • iOS Cryptographic APIs
  • Local Authentication on iOS
  • iOS Network APIs
  • iOS Network APIs
  • Code Quality and Build Settings for iOS Apps
  • Tampering and Reverse Engineering on iOS
  • iOS Anti-Reversing Defenses

A final written report provides an analysis of any security or service problems discovered together with proposed solutions, links to detailed advisories and recommendations for improving the security of both the app and the web services it uses.