CLOUDPANICCLOUDPANIC

Mobile application penetration testing

The binary ships to the attacker's device. Assume it gets unpacked, instrumented and run against a proxy you don't control.

We test Android and iOS apps on rooted and jailbroken devices with live instrumentation: what an adversary extracts from the binary, what the app trusts on the wire, and what the backend exposes once its client-side controls are removed.

Test scope

The full attack surface — not just what's visible from the outside.

Local data & secrets

Secrets stored on the device

Keychain/Keystore use, plaintext in shared preferences and SQLite, cached credentials, logs and backups, and keys recoverable from the binary.

Transport security

A network you don't control

TLS configuration, certificate pinning and its bypass under instrumentation (Frida/objection), and MITM resilience on hostile networks.

Runtime & anti-tampering

Threats in the runtime environment

Root and jailbreak detection, anti-debug and anti-hooking defenses, code integrity, and how fast they fall to instrumentation.

Platform IPC & deep links

Ways to bypass the interface

Exported components, intent and URL-scheme handling, and WebView and JS-bridge exposure.

Authentication & session

Does the server enforce when the client lies

Token storage and lifetime, biometric gating, and whether server-side controls survive a tampered client.

Built on recognised standards

Established industry frameworks — not proprietary checklists.

methodology.sh
OWASP MASVS / MASTG

Verification standard and test methodology, executed manually on instrumented devices.

Runtime instrumentation

Frida/objection-driven analysis: pinning bypass, hooking and live tampering.

OWASP API Top 10

Applied to the backend, where client-side controls stop protecting you.

We bypass pinning and root detection as a matter of course. If your architecture treats them as a security boundary, the engagement tests exactly that — and the result is rarely a surprise to the tester, but often is to the client.
From scope to retest

A structured process from scope to retest — no surprises at delivery.

Diagram of the penetration testing cycle: scope and reconnaissance, testing, reporting
Common questions

The questions we hear most often before a contract is signed.

A signed build is enough for black-box. Source, test accounts and architecture context move us to grey-box and raise coverage per day. Either way we instrument on our own rooted/jailbroken devices.

They deter casual analysis but don't survive a determined tester. We bypass them as a matter of course; the engagement measures what your backend enforces afterward.

Yes, tested separately. Storage, IPC and platform controls differ enough that findings rarely carry over.

Contact us

For any matter, you can reach us using the contact details below or via the contact form.

Calendar icon for scheduling meetings

If you would like to speak with us in person, we invite you to book a meeting using the Microsoft Bookings platform.

Book a meeting in Microsoft Bookings
E-mail:
Send us an email and our team will get back to you within 1–2 business days.
Phone:
We also offer phone contact from Monday to Friday, 9:00 AM – 5:00 PM.
0 / 5000
The personal data provided will be used solely for the purpose of handling your inquiry or contact request. The data controller is CLOUDPANIC Sp. z o.o. You can find detailed information in our privacy policy.