On-device data and permissions
Assess protection of application files, logs, tokens and secrets. Review Android component and permission boundaries. Explain evidenced situations where another application or a lost device could expose information.
Mobile application security
We assess how a mobile app stores data, verifies users and communicates with its server, explaining findings in terms of customer-data and access risks.
01 / ASSESSMENT
Review application files and runtime behaviour: local data, sessions, server APIs, permissions and connection security. OWASP mobile testing practices guide reproducible findings and practical developer remediation.
PRACTICAL SCENARIOS / TTP
TTPs are an adversary’s tactics, techniques and procedures. We analyse these approaches and select scenarios for your environment and the scope agreed in writing, connecting each assessment result to practical defensive guidance.
Assess protection of application files, logs, tokens and secrets. Review Android component and permission boundaries. Explain evidenced situations where another application or a lost device could expose information.
Hiding a mobile button does not enforce server-side access. Test session lifetime, reauthentication and API object permissions across user roles. Explicitly assess isolation between different customers’ data.
Use OWASP MASVS/MASTG to compare application structure and runtime behaviour. Burp Suite and agreed lab tools support network and execution observation. Findings include reproduction conditions, impact and developer remediation criteria.
02 / OUTCOMES
Work proceeds under the system owner’s written authorisation, a contract and a confidentiality agreement. Assets, methods, timing, stop conditions and data handling are defined before work begins.
Send your requirements through CyberTrust. We will clarify asset count, assessment depth and expected outcomes with you, then set out timing and pricing in the proposal.