SVC—05 · ASSESSMENT

Mobile application penetration testing

Each MASVS control is linked to a concrete mobile test, and the scope states clearly whether the backend is included.

Start scoping
OWASP MASVS 2.1OWASP MASTG 2.0NIST SP 800-115

TEST BOUNDARY

What sits inside the boundary

Platforms, builds, roles, screens and backend inclusion
Storage, cryptography, transport, platform interaction and code quality
Resilience, tamper controls and sensitive workflows

ACCESS MODES

Knowledge level is scoped

Binary-only
Instrumented
Source-assisted

DELIVERY—LEDGER

Deliverables you can inspect.

OUTPUT

MASVS, MASWE, and MASTG coverage trace

Device and backend evidence

Fix guidance and verification

EFFORT—DRIVER

Platforms and builds

Roles, screens, and backend/API inclusion

Anti-tamper and device constraints

EXPLICIT—LIMIT

Store-review acceptance and platform security are not guaranteed

Backend testing is excluded unless named in scope

POINT—IN—TIME

Precision includes what we do not claim.

A penetration test provides evidence about named assets, versions, access, and time. It does not guarantee the absence of vulnerabilities, replace internal vulnerability management, or constitute compliance certification.

Method and limitations

SCOPE—NEXT

Define the boundary before the fee.

Build a scope draft