# Mobile Application Security Assessment

> From $10K · Offensive Security · https://cisomarketplace.services/services/mobile-application-security-assessment

Comprehensive security testing of iOS and Android applications

## In scope

- iOS and Android application testing against OWASP MASVS
- Local data storage, keychain / keystore and cryptography review
- Authentication, session and authorization testing
- Backend API testing for the application
- Reverse-engineering resistance and tamper checks
- Third-party SDK and permission review

## Deliverables

- Mobile application security report mapped to OWASP MASVS
- Reproducible findings with risk ratings
- Developer remediation guidance
- Executive summary
- Retest of fixed findings

## Tiers

### Basic Assessment: $10K

Security test of 1 mobile app on 1 platform (a single iOS build or a single Android build): static and dynamic analysis of the app binary, local storage, authentication, and app-to-server traffic. One retest.

Limits: mobile apps 1

Includes:
- 1 app, 1 platform build
- Static and dynamic analysis of the binary
- Local data storage, auth and session checks
- Traffic interception of app-to-server calls
- One retest of fixed findings

Excludes:
- Second platform build
- Dedicated backend API penetration test
- Source code review
- CI/CD integration of SAST/DAST

### Advanced Assessment: $15K

Security test of 1 mobile app on both platforms (iOS and Android builds) plus its 1 backend API (up to 50 endpoints), with dependency analysis and source-assisted review where code is provided. One retest.

Limits: mobile apps 2, apis 1

Includes:
- iOS and Android builds of 1 app (2 builds)
- 1 backend API, up to 50 endpoints
- Third-party dependency/SDK analysis
- Source-assisted review where code is supplied
- One retest of fixed findings

Excludes:
- Additional apps
- Internal network testing
- Social engineering
- Ongoing testing of new releases

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=mobile-application-security-assessment
