I will perform professional mobile application vapt
Cyber Security Consulting
About this Gig
We will perform an authorized Mobile Application VAPT using manual testing supported by industry-standard tools.
Why Choose Us?
- 3500+ Mobile Application VAPT Test Cases
- 10+ Years of Experienced Security Professionals
- Manual Testing with Business-Impact-Focused Assessment
- Evidence-Based Reporting & Standards-Aligned Methodology
- Secure and Confidential Engagement with Transparent Communication
Our Security Testing is aligned with OWASP MASVS, MASTG and the OWASP Mobile Top 10 and can cover:
- Static APK/iPAA analysis and manifest.xml/info.plist review
- Insecure storage, logging, backups and screenshots
- Authentication, session and authorization weaknesses
- SSL Certificate pinning and API communication
- Exported components, deep links, WebViews, IPC, Containerization etc.
- Hardcoded secrets, weak cryptography and vulnerable libraries
- Root detection/jailbreak Detection, tampering, reverse engineering and business logic
You'll Receive:
- Executive and technical PDF report
- Validated findings with severity and CVSS
- Evidence, PoC and reproducible steps
- Business impact and actionable remediation
- OWASP, CWE and affected-component mapping
- Optional remediation retest
My Portfolio
FAQ
Do you need the source code?
No. Black-box and grey-box testing can be performed using an APK and test accounts. Source-code-assisted testing can be purchased separately.
Is the testing manual or automated?
Both. Automated tools improve coverage, but findings are manually investigated and validated. You will not receive an unverified scanner dump.
Which security standards do you follow?
Testing is aligned with OWASP MASVS, MASTG and relevant OWASP Mobile Top 10 risks. Findings may also include CVSS and CWE mapping.
Is API security testing included?
Basic includes up to 10 observed endpoints, Standard up to 30 and Premium up to 60. Additional endpoints require a Gig Extra or custom offer.
Can you test Flutter or React Native applications?
Yes, many native Java, Kotlin, Flutter, React Native and hybrid applications can be assessed. Please confirm the technology before ordering.
Can you test certificate pinning and root detection?
Yes, these controls can be evaluated when authorized. A debuggable UAT build may be requested when commercial protection prevents reasonable assessment.
Is a remediation retest included?
Standard and Premium include one retest of the originally reported findings within the stated retest period. Basic buyers can purchase it as an extra.
What counts as a revision?
A revision covers factual, presentation or agreed report corrections. It does not include a new build, additional role, expanded API scope or a fresh assessment.
Does the report certify that my app is completely secure?
No security assessment can guarantee absolute security. The report represents a point-in-time evaluation of the agreed scope and is not a formal certification.
Is the Cert-In STH Certificate included in the Premium Package?
No. It's totally up to the client whether he requires it. We will provide an STH (Safe to Host Certificate) for the application, but it will cost an additional $300, as mentioned in the gig description.

