SVC—05 · ASSESSMENT
Mobile application penetration testing
Each MASVS control is linked to a concrete mobile test, and the scope states clearly whether the backend is included.
Start scopingTEST BOUNDARY
What sits inside the boundary
Platforms, builds, roles, screens and backend inclusion
Storage, cryptography, transport, platform interaction and code quality
Resilience, tamper controls and sensitive workflows
ACCESS MODES
Knowledge level is scoped
Binary-only
Instrumented
Source-assisted
DELIVERY—LEDGER
Deliverables you can inspect.
OUTPUT
MASVS, MASWE, and MASTG coverage trace
Device and backend evidence
Fix guidance and verification
EFFORT—DRIVER
Platforms and builds
Roles, screens, and backend/API inclusion
Anti-tamper and device constraints
EXPLICIT—LIMIT
Store-review acceptance and platform security are not guaranteed
Backend testing is excluded unless named in scope
POINT—IN—TIME
Precision includes what we do not claim.
A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.
Method and limitations