Skip to main content
REF-CAT-002-B

Applications Security

Testing and review at the application layer: mobile, web, and source code.

A developer workstation at night with a dark monitor
Method

Seven phases, code to confirmation.

01

Scope Definition

Applications, platforms, and test accounts agreed before any testing starts.

02

Information Gathering

Map the application, its APIs, and the data moving through them.

03

Vulnerability Assessment

Automated and manual review, including source code where it is in scope.

04

Penetration Testing

Confirm which of those weaknesses are exploitable in practice.

05

Reporting

Findings with reproduction steps, severity, and the evidence behind each one.

06

Remediation

Guidance written for the developers who have to fix it, not just a list.

07

Verification

Retest the fixes before close-out. Mobile Application Penetration Testing includes this phase.

FAQ

Common questions.

Do you test both iOS and Android?

Yes, Mobile Application Penetration Testing covers iOS and Android applications and their backend APIs.

Does Source Code Review replace penetration testing?

No, they're complementary. Source Code Review catches issues visible in the code itself; penetration testing (included as part of the review's later phase) confirms which of those issues are actually exploitable.

Do you offer a retest after we fix the issues?

Mobile Application Penetration Testing includes a dedicated verification phase. For other services, ask when scoping the engagement.

Which application assessment do you need?

Request an Assessment
Request an Assessment Email Us