Mobile application penetration testing

Test the app on the device. And the trust behind it.

Security testing for iOS and Android apps, from local data to the backend calls in scope.

From A$7,500 ex GST for one mobile platform and its backend API.

Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
What we test

A scope with a purpose.

Data on the device

Local storage, logs, cached content and secrets in the app package.

Platform interactions

Deep links, exported components, permissions and inter-app communication.

Network and session trust

Transport handling, token lifecycle and server-side authorisation.

Before testing

What we need from you

  • Installable iOS or Android test builds.
  • Supported OS versions and test accounts.
  • Whether both platforms and the backend APIs are in scope.
  • Any testing-specific build change, agreed in advance.
Use the scoping checklist
After testing

What you can act on

  • Platform-specific reproduction steps.
  • Evidence showing device or backend impact.
  • Fixes assigned to the app or the server-side control.

Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.

Limits matter

What this test does not cover

  • App-store approval.
  • A full backend assessment by default.
  • Every handset and OS build.
  • Hardware, baseband and third-party SDK internals.
The deliverable

See what you will receive

A 19-page illustrative report built from synthetic findings, not a client report. It shows scope, evidence, severity rationale and the retest record.

See sample report

Questions before you book

Practical answers.

Do iOS and Android count as one scope?

They share business features but have different platform controls and builds. We scope each required platform and the reusable backend work so you are not buying duplicate coverage.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.

How long will it take?

Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.

Ready to price your test?

The sample report is illustrative, built from synthetic findings. It is not a client report.

Get instant quote

Last reviewed: