Review

Security and threat-surface review

We inspect authentication flows, local storage, certificate pinning, deep links, and backup behaviour on the builds you actually ship.

Typical duration: 5–10 working days

A reviewer holding a smartphone during a quiet desk session

Most of the mobile apps we see in Johor Bahru are already in customers’ hands. The question is not whether the product works on a demo device. It is whether a lost phone, a modified APK, or a chatty log file would expose something you would rather keep inside the company.

We start from the binaries and the accounts you give us, not from a slide deck. That means walking the login, session refresh, biometric fallback, and logout paths on current iOS and Android builds. We look at how tokens land in Keychain, EncryptedSharedPreferences, or less careful places. We watch traffic from a controlled network, then we try the same flows on a device with a user-installed CA and on a jailbroken or rooted handset if you want that depth.

Deep links, app links, and custom URL schemes get their own pass. So do backup flags, clipboard use, screenshot handling on sensitive screens, and any in-app browser. Findings are written as observations with a severity, a reproduction note, and a suggested fix — not as a generic checklist score.

You leave with a findings memo, a short workshop to walk the product team through the highest-risk items, and a retest window once patches land.

Ask for this review