Skip to product information
Android Application Pentest
€6.999,00
Fixed price. Fixed scope. No sales call. A manual penetration test of one Android application and the backend API it communicates with.
Scope included
- 1 Android application (APK or Play Store build)
- Up to 3 user roles
- Backend API calls made by the app
What we test
- Based on OWASP MASVS / MASTG
- Local data storage, secrets and cryptography
- Network communication, certificate pinning and TLS
- Authentication, session handling and access control on the API
- Exported components, intents, deep links and WebViews
Deliverables
- PDF report with executive summary and technical findings (CVSS-scored, with reproduction steps and remediation advice)
- Letter of attestation you can share with auditors and customers
- Critical findings reported to you immediately, not at the end of the test
Not included
- Retest of findings: add a Separate Retest ($1,499) if you need your fixes verified
- iOS applications, full web application testing of the API beyond calls made by the app
- Social engineering / phishing, denial-of-service, source-code review
If we discover during kick-off that your app is larger than this scope, you can upgrade or get a full refund, your choice.