Local data
Application storage, caches, logs, backups, screenshots and other device-resident information relevant to the agreed scope.
Singapore / iOS & Android
Assess the application on the device, the way it handles data and the backend services it relies on.
Discuss your scope01 / Service fit
A mobile application does not operate in isolation. Its security depends on how the client stores information, uses platform controls, communicates over the network and enforces sensitive actions through backend APIs.
The engagement can focus on an iOS build, an Android build or both, together with agreed supporting services. It is useful before release, after a significant change, when handling higher-risk data or transactions, or when independent assurance is required.
Coverage is adapted to the application architecture, distribution model, available test accounts and authorised environments rather than applying a generic mobile checklist.
02 / Scope
The final scope reflects the app’s platform, functions, data and backend dependencies.
Application storage, caches, logs, backups, screenshots and other device-resident information relevant to the agreed scope.
Use of device permissions, key storage, biometric prompts, deep links and platform security features where applicable.
Protection of data in transit, endpoint validation and handling of relevant network trust conditions.
Login, token handling, account recovery, session lifecycle and controls around sensitive operations.
Client-side trust assumptions, exposed components, sensitive workflows and misuse of supported application functions.
Authorisation, data exposure and server-side enforcement for the endpoints used by the mobile client.
03 / Method
Testing combines application analysis with validation of real client-to-service behaviour.
Agree platforms, versions, distribution method, environments, accounts, backend endpoints and any required test devices or access.
Map sensitive functions, stored information, permissions, network calls and trust boundaries between the client and backend.
Review relevant client behaviour and exercise authorised workflows while validating server-side enforcement through supporting APIs.
Provide reproducible evidence, impact, severity rationale and remediation guidance for mobile and backend teams.
Use updated builds or backend changes to verify findings included in the agreed retest scope.
04 / Deliverables
Findings distinguish client-side weaknesses, backend control gaps and issues spanning both sides of the application.
Scope, build and environment context, overall observations and prioritised remediation themes.
Reproduction steps, evidence, affected platform or service, impact and severity rationale.
Practical recommendations, clarification with delivery teams and status of agreed retests.
05 / Boundaries
Mobile testing needs explicit agreement on builds, devices, accounts and backend scope.
Only supplied or approved builds, accounts, endpoints and environments are tested. Third-party services require appropriate permission.
Platform versions, device state, network conditions, test data and any production restrictions are agreed before testing.
Malware persistence, destructive actions, denial-of-service, social engineering and unrelated platform or third-party targets are excluded unless separately authorised.
A mobile assessment reflects the supplied builds, authorised services and test period. It is not a guarantee that every weakness has been found and does not certify platform-store or regulatory compliance.
06 / Related services
Start a conversation
Share the platforms, builds, key functions, backend endpoints and target timing so the relevant client and server-side coverage can be agreed.