Skip to content
Noroxi

Mobile application testingWhat stays on the device is still on you.

We test your mobile app beyond its screens: on-device storage, network traffic and the API behind it, all together.

Duration
5–8 business days
Standard
OWASP MASVS
Deliverables
Report, readout and retest within 30 days

What we test

  1. 01

    Local storage

    Tokens, personal data and cache stored on the device.

  2. 02

    Network communication

    TLS, certificate validation and traffic integrity.

  3. 03

    Identity and sessions

    Biometric login, session lifetime, device binding.

  4. 04

    Backend API

    Every endpoint the app talks to.

  5. 05

    App integrity

    Resilience against tampered builds and reverse engineering.

  6. 06

    Payment flows

    In-app purchases and server-side validation.

Vulnerabilities we often find

The ones we’ve run into most in recent engagements. You can’t know whether you have them until you test.

  • In-app purchases not validated on the serverCritical
  • Unencrypted session data on the deviceHigh
  • Incomplete certificate validationHigh
  • API key embedded in the app packageMedium
  • Personal data in error logsLow

This is how a finding is delivered.

Clear enough for a developer to fix on their own. Plain enough for an executive to grasp at a glance.

NRX-2026-0141page 14 / 38
CriticalCVSS 4.0 · 9.1

Broken object-level authorization in the Orders API

Affected asset
api.ornek-sirket.com.tr
Category
OWASP API1:2023 · CWE-639
Discovered
September 12, 2026
Reported
Same day, by phone

Impact

A signed-in customer can view invoices that belong to other customers. Because the invoices include names and addresses, this may require notification under KVKK (Turkey’s personal data protection law).

Remediation

In the invoice lookup, verify that the record belongs to the signed-in user. Centralize authorization checks in a single middleware layer and apply it to every endpoint.

Retest · October 3, 2026 Resolved

How it works

  1. 011–2 days

    Scoping

    Test builds, test accounts and target platforms.

  2. 024–6 business days

    Static and dynamic analysis

    We examine the app package and the running app side by side.

  3. 032–3 business days

    Report and readout

    Findings by platform, with remediation guidance.

  4. 04Within 30 days

    Retest

    Fixed findings are retested in the new build.

Frequently asked questions

Are iOS and Android priced separately?
If both platforms share the same backend, we test them under a shared scope at a lower cost.
Do you test the version in the app stores?
We ask for a separate test build. We use the store version for comparison only.
Do you recommend root and jailbreak detection?
It depends on your threat model. For banking and payment apps, we do.

Often paired with

Let’s take a free look first

Leave us your domain. Within 2 business days, we’ll review your external surface and send the priority risks and a recommended scope on a single page.

  1. 01Leave your email and domain.
  2. 02We review your external surface within two business days.
  3. 03You get a one-page summary and a recommended first step.

We use your details only for this request. Privacy notice

mini assessment1 page
14
Subdomains
6
Exposed services
B
TLS grade
3 / 7
Security headers

Top three risks

  1. 1Admin panel exposed to the internetHigh
  2. 2Outdated TLS version still supportedMedium
  3. 3Content Security Policy missingLow
Delivery: 2 business daysRecommended first step: web and API testing