On the device
Data & privacy
How well does your app protect information on the device?
- Local storage and logs
- Keychain and permissions
- Unnecessary data exposure
Independent iOS penetration testing
We assess iOS applications within an agreed scope and deliver clear findings with practical recommendations.
The service
A focused assessment of your app, its data, and how it behaves.
On the device
How well does your app protect information on the device?
Inside the app
A closer look at the compiled app and the logic it reveals.
Between app and service
How your app communicates with the services it relies on.
Testing environmentYour standard app and its endpoints, or an authorized testing or staging environment.
We agree on the scope and access before testing.
Scope exclusionsSource-code review, infrastructure testing, and phishing. Reverse engineering examines recoverable logic; it does not guarantee recovery of the original source code.
The approach
Three steps, with one point of contact throughout.
We start with your security questions, then agree on the app, environment, permissions, and areas to assess.
We investigate the compiled app and its behavior. API testing follows the explicitly agreed scope.
You receive a detailed report with evidence, impact, and practical recommendations.
Planning a release or a significant change?
Allow time to assess the app and address the findings before launch.
Your deliverable
Detailed enough for developers. Clear enough to support decisions.
Before we start
A few answers to help you plan an assessment.
We examine the compiled iOS app and use reverse engineering to understand recoverable logic. This is not a source-code review, and it does not guarantee recovery of the original source code.
Yes, when authorized. The starting point is your standard app and its normal endpoints, or an agreed testing or staging environment. Additional API testing requires explicit permission and its own agreed scope.
A short description of your app, what you want assessed, and any timing constraints. We then agree on scope, permissions, app access, and any test accounts needed.
Get in touch
Tell us what your app does, what you want assessed, and whether there is a release date in mind.
info@ivaltrix.nl