Note

What a mobile security review actually opens

Not a scanner score. A week with the builds you ship, the accounts you use in production-like conditions, and a written trail of what we could do.

Two colleagues reviewing information on a laptop

People ask for a “pen test of the app” and mean three different jobs. One is a look at the API from a laptop. One is a store-listing hygiene pass. One is time on devices with the same privileges a customer, a lost-phone finder, or a modified client would have.

At System Fabric Path the last of those is the centre of a security review. We install the builds you give us. We create or receive test accounts that match real roles. Then we try to read data we should not see, keep a session alive after logout, pull tokens off the device, and trick the app into opening a link it should ignore.

We still glance at the API, because a mobile client that trusts the phone to enforce prices is a finding. We do not pretend that a week on two handsets replaces a full web-service assessment. The memo will say so.

If you are preparing a brief, send the current iOS and Android artefacts, a privacy notice, a list of roles, and the journeys that move money or personal data. That package does more for the quality of the week than a long questionnaire.

More notes