Package Review
Inspect application packages, manifests, entitlements, dependencies, and bundled resources for exposure or weakness.
Application Security
Android and iOS applications carry risk across code, local storage, runtime protections, API communications, and backend trust. BlockSecBrain tests insecure authentication, data leakage, API exposure, and mobile-specific weakness patterns using manual, automated, and hybrid techniques.
Overview
A mobile application runs on hardware you do not control, in an environment the user can fully inspect. Any secret shipped in the binary is a published secret, and any control enforced only on the client is a control an attacker can remove.
We test the application as a rooted or jailbroken adversary would: unpacking the binary, hooking the runtime, intercepting pinned traffic, and then attacking the backend directly with the credentials and tokens the client hands over.
The result covers both halves of the risk. Client-side weaknesses that expose user data on a lost device, and server-side trust failures that let a modified client bypass the business rules the interface appears to enforce.
Assessment Methodology
A practical approach to client-side, backend, and device trust validation.
Inspect application packages, manifests, entitlements, dependencies, and bundled resources for exposure or weakness.
Test login flows, token handling, session persistence, and MFA pathways under real usage conditions.
Validate mobile-to-backend trust, API authorisation, TLS handling, pinning logic, and error leakage.
Evaluate local storage, runtime protections, tamper resistance, and platform trust assumptions.
Document technical findings with remediation guidance that spans app code, APIs, and deployment posture.
Confirm fixes after remediation to ensure security controls perform as intended on real devices.
Deliverables
Every engagement closes with a documented, defensible evidence set that serves engineering, leadership, and audit at the same time.
Every finding with reproduction steps, evidence, affected components, risk rating, and specific remediation guidance.
PDF reportRisk posture, business impact, and thematic root causes written for leadership and board reporting.
PDF / slidesA structured issue list with severity, owner, and status columns that maps directly into your ticketing system.
XLSX / CSVFormal confirmation of which findings were verified as remediated, suitable for customers and auditors.
PDF attestationChained walkthroughs showing how individual weaknesses combine into a realistic compromise scenario.
Report sectionA live walkthrough with your engineering and security teams covering findings, priorities, and fix strategy.
Live sessionReporting Process
Findings are rated on demonstrated exploitability and business impact, not scanner severity. Critical findings are escalated during testing rather than held for the report.
Client Benefits
Mobile findings translate directly into store compliance, customer assurance, and reduced fraud exposure.
Android and iOS are tested in parallel with a single scope, report, and remediation cycle.
Testing maps to OWASP MASVS control groups so results feed maturity targets, not just a bug list.
Findings are validated on physical hardware, not only emulators, including tamper and biometric flows.
Technology Coverage
Coverage spans native, cross-platform, and hybrid stacks along with the backends and SDKs they depend on.
Standards Alignment
Mobile findings are mapped to the standards that app store reviewers, enterprise customers, and regulators expect to see.
Testing follows the Mobile Application Security Testing Guide and reports against MASVS-STORAGE, CRYPTO, AUTH, NETWORK, PLATFORM, CODE, and RESILIENCE.
The backend behind the app is tested as a first-class target, including object-level authorisation and mass assignment.
Evidence supports secure development lifecycle, cryptographic control, and technical vulnerability management requirements.
Findings map to Protect and Detect outcomes for mobile endpoints and the services they consume.
For companion apps to medical devices, testing evidences secure development and product security requirements.
Where the app forms part of a product with digital elements, findings feed the technical documentation and vulnerability handling evidence set.
| Standard | Where it applies | How this engagement supports it |
|---|---|---|
| OWASP MASVS | Mobile security baseline | Control-group scoring with per-requirement pass, fail, and not-applicable status. |
| OWASP MASTG | Test procedure evidence | Test case references recorded against each finding for auditor traceability. |
| ISO/IEC 27001 | ISMS certification | Annex A evidence for cryptography, secure development, and access control. |
| NIST CSF 2.0 | Enterprise risk reporting | Posture summary aligned to CSF functions for executive reporting. |
| IEC 81001-5-1 | Health software lifecycle | Secure development and verification evidence for companion applications. |
| EU CRA | Products with digital elements | Vulnerability handling and technical documentation input for the conformity file. |
Industry Expertise
We work with regulated and safety-critical manufacturers where a security failure carries operational, contractual, and certification consequences.
Engagement Workflow
A predictable delivery model with defined checkpoints, so your teams know exactly what happens and when.
We agree targets, depth, timing windows, safety constraints, and escalation contacts before any testing begins.
Trust boundaries, attacker goals, and abuse cases are mapped so testing effort follows real business risk.
Manual, tool-assisted, and AI-accelerated testing with every finding reproduced and evidenced.
Technical detail for engineers, prioritised risk narrative for leadership, delivered in one report set.
Direct access to the testing engineers while your teams design and implement fixes.
A free retest of remediated findings confirms the fix holds and closes the engagement.
Questions
Practical answers to what procurement, engineering, and security teams ask before an engagement starts.
No. We test in black-box or grey-box mode by default. Source access shortens analysis and improves coverage of cryptographic and business logic paths, so we recommend it where your policy permits.
Yes. We can test the store build directly, though we usually ask for a debug or pre-release build so testing does not depend on production data.
Yes, where the environment and rules of engagement allow it. We agree timing windows, rate limits, and safety constraints up front, and we maintain a live escalation channel for the duration of the engagement. Where production testing is unacceptable, we test staging and validate configuration parity separately.
Most assessments run between one and three weeks of active testing, depending on scope size and depth. Scoping takes two to three working days, and the report is delivered within five working days of testing completion.
Yes. One verification retest of remediated findings is included in the engagement fee, provided it is requested within 90 days of report delivery.
Senior security engineers only. We do not staff engagements with junior analysts running scanner output, and the engineer who tested your environment is the engineer you speak to during remediation.
Let us validate your Android and iOS security posture across app code, runtime behaviour, and API trust boundaries.