Android Application Pentest

Android Application Pentest

€6.999,00
Skip to product information
Android Application Pentest

Android Application Pentest

€6.999,00

Fixed price. Fixed scope. No sales call. A manual penetration test of one Android application and the backend API it communicates with.

Scope included

  • 1 Android application (APK or Play Store build)
  • Up to 3 user roles
  • Backend API calls made by the app

What we test

  • Based on OWASP MASVS / MASTG
  • Local data storage, secrets and cryptography
  • Network communication, certificate pinning and TLS
  • Authentication, session handling and access control on the API
  • Exported components, intents, deep links and WebViews

Deliverables

  • PDF report with executive summary and technical findings (CVSS-scored, with reproduction steps and remediation advice)
  • Letter of attestation you can share with auditors and customers
  • Critical findings reported to you immediately, not at the end of the test

Not included

  • Retest of findings: add a Separate Retest ($1,499) if you need your fixes verified
  • iOS applications, full web application testing of the API beyond calls made by the app
  • Social engineering / phishing, denial-of-service, source-code review

If we discover during kick-off that your app is larger than this scope, you can upgrade or get a full refund, your choice.

You may also like