Total Tests:

ImmuniWeb® MobileSuite
Compliance-Ready Mobile Application Penetration Testing

ImmuniWeb® MobileSuite leverages our award-winning Machine Learning technology to accelerate and enhance
mobile penetration testing. Every pentest is easily customizable and provided with a zero false-positives SLA.
Unlimited patch verifications and 24/7 access to our security analysts are included into every project.

Quality. Efficiency. Value.

In-Depth Testing

In-Depth Testing

SANS Top 25 & business logic
beyond OWASP Mobile Top 10

Threat-Led Testing

Threat-Led Testing

Simulation of real attacks relevant
to your business and industry

DevSecOps Native

DevSecOps Native

Unlimited patch validation,
SDLC & CI/CD integration

Zero False-Positives SLA

Zero False-Positives SLA

100% validated findings
money-back guarantee

Rapid Delivery SLA icon

Rapid Delivery SLA

Always on-schedule testing
and report delivery

First-Class Reports

First-Class Reports

Zero noise, full exploitation cycle,
threat-aware risk scoring

How it works

  1. Configure and schedule
    your penetration test
  2. Download your report and
    get our help with patching
  3. Get a letter of compliance
    after validating the fixes

Control the Entire Process via a Multiuser Portal

DevSecOps Native

WAF Integrations

Mobile Penetration Testing for Any Need

Mobile App Security

Mobile App Security

Static, dynamic and interactive
security testing with SCA

Mobile Backend Security

Mobile Backend Security

Comprehensive testing of
mobile app’s endpoints

Privacy and Encryption

Privacy and Encryption

Detailed analysis of privacy
and encryption problems

Threat-Led Penetration Testing

Threat-Led Penetration Testing

Testing resilience of your systems to specific
Tactics, Techniques & Procedures (TTPs)

Red Teaming

Red Teaming

Breach and Attack Simulation (BAS)
using MITRE ATT&CK® Mobile

IAM Testing

IAM Testing

Full spectrum of cyber-attacks testing your
Identity & Access Management (IAM)

Compliance-Ready Mobile Penetration Testing

EU DORA, NIS 2 & GDPR
EU DORA, NIS 2 & GDPR
Helps fulfill pentesting requirements
under the EU laws & regulations
US HIPAA, NYSDFS & NIST SP 800-171
US HIPAA, NYSDFS & NIST SP 800-171
Helps fulfill pentesting requirements
under the US laws & frameworks
PCI DSS, ISO 27001, SOC 2 & CIS Controls®
PCI DSS, ISO 27001, SOC 2 & CIS Controls®
Helps fulfill pentesting requirements
under the industry standards

Proven Methodology and Standards of Testing

  • OWASP Mobile Security Testing Guide (MASTG)
  • NIST SP 800-115 Technical Guide to Information Security Testing and Assessment
  • PCI DSS Information Supplement: Penetration Testing Guidance
  • MITRE ATT&CK® Matrices for Mobile and Enterprise
  • FedRAMP Penetration Test Guidance
  • ISACA’s How to Audit GDPR
  • ECB TIBER-EU
NIST SP 800-115 Technical Guide to Information Security Testing and Assessment
PCI DSS Information Supplement: Penetration Testing Guidance
FedRAMP Penetration Test Guidance
OWASP Web Security Testing Guide (WSTG)
  • OWASP Application Security Verification Standard (ASVS v4.0.2) Mapping
  • OWASP Mobile Application Security Verification Standard (MASVS v2.1.0) Mapping
  • Common Vulnerabilities and Exposures (CVE) Compatible
  • Common Weakness Enumeration (CWE) Compatible
  • Common Vulnerability Scoring System (CVSS v4)
Common Vulnerabilities and Exposures (CVE) Compatible
Common Weakness Enumeration (CWE) Compatible
Common Vulnerability Scoring System (CVSSv4)
OWASP Web Security Testing Guide (WSTG)
  • CWE/SANS Top 25
  • PCI DSS 4.0 (6.2.4)
  • OWASP Mobile Top 10
  • OWASP Top 10 API
NIST SP 800-115 Technical Guide to Information Security Testing and Assessment
PCI DSS 4.0 (6.2.4)
OWASP Top 10
OWASP Top 10 API

ImmuniWeb® MobileSuite Deliverables

Penetration Testing
  • Full Customization of Testing
  • Mobile App Penetration Testing:
    • SANS Top 25 Full Coverage
    • PCI DSS 6.2.4 Full Coverage
    • OWASP Mobile Top 10 Full Coverage
    • Authenticated Testing (MFA / SSO)
    • Business Logic Testing
  • Mobile Backend Penetration Testing:
    • SANS Top 25 Full Coverage
    • PCI DSS 6.2.4 Full Coverage
    • OWASP Top 10 Full Coverage
    • OWASP Top 10 API Full Coverage
    • Authenticated Testing (MFA / SSO)
    • Business Logic Testing
  • Mobile Application Privacy Review
  • Software Composition Analysis
  • Open Source Software Security Ratings
  • Rapid Delivery SLA Money back

    Contractual money-back guarantee for a delayed delivery date.

Reporting
  • Threat-Aware Risk Scoring
  • MITRE ATT&CK® Matrix Mapping
  • Step-by-Step Instructions to Reproduce
  • Web, PDF, JSON, XML and CSV Formats
  • Tailored Remediation Guidelines
  • PCI DSS and GDPR Compliances
  • CVE and CWE Mapping
  • CVSSv4 Scoring
  • OWASP MASVS Mapping
  • Zero False-Positives SLA Money back

    Contractual money-back guarantee for one single false positive.

Remediation
  • Unlimited Patch Verifications
  • One-Click Virtual Patching (Backend)
  • 24/7 Access to Our Security Analysts
  • DevSecOps & CI/CD Tools Integration
  • Multirole RBAC Dashboard with 2FA
  • Penetration Test Certificate



ImmuniWeb® MobileSuite Packages

Mobile Application Penetration Testing

ImmuniWeb® MobileSuite
Ultimate
Corporate Pro
Corporate

Designed for mobile application of small size and complexity, with one or two endpoints (e.g. APIs or web services) and one user role.

Express Pro
Threat-Led Penetration Testing

Our penetration testers will carefully review the unique risk profile of your organization and industry to simulate TTPs (Tactics, Techniques and Procedures) of the most relevant and sophisticated cyber-attacks that may target your organization specifically.

Yes
AI-Powered Security Testing

Since 2019, our award-winning Machine Learning technology accelerates and intelligently automates thousands of tests and checks of your web and mobile application security, which usually require human labor and cannot be performed by automated vulnerability scanners due to complexity.

Yes Yes Yes Yes
OWASP MASVS Testing Level

MASVS (v1) Level 1 is a foundational level of testing for simple apps with little or no confidential data

MASVS (v1) Level 2 is a minimum level of testing for apps that handle any personal, health or financial data

MASVS (v1) Level R is the required level of testing for business-critical apps that handle highly sensitive data

L1, L2, R L1, L2, R L1, L2 L1
OWASP ASVS Testing Level

ASVS Level 1 is a foundational level of testing for simple applications with little or no confidential data

ASVS Level 2 is a minimum level of testing for applications that handle any personal, health or financial data

ASVS Level 3 is the required level of testing for business-critical applications that handle highly sensitive data

Level 3 Level 3 Level 2 Level 1
Manual Penetration Testing

Our CREST-accredited security experts conduct advanced security testing of your mobile application’s business logic, perform reverse engineering and exploitation of your mobile application backend (e.g. APIs or web services), and run other security and privacy checks that require human intelligence due to high complexity.

10 days 5 days 5 days 3 days
Report Writing

The assessment report can be viewed or downloaded during the next 100 days following the Security Assessment completion.

2 days 8 hours 8 hours 4 hours
Unlimited Retesting

During 100 days after delivery of your penetration testing report, you can schedule patch verification assessment to ensure and validate that all findings are properly fixed.

Yes Yes Yes Yes
Penetration Test Certificate

Once the detected vulnerabilities are fixed, you receive a penetration test certificate.

Yes Yes Yes
Network Security Assessment

If your mobile backend APIs are hosted on your own network infrastructure, the network server(s) hosting your backend infrastructure will be tested for exposed, outdated or otherwise misconfigured network services.

Yes Yes
Testing on Physical Device

If your mobile app requires to be tested on a physical device, Corporate Pro or Ultimate package is required due to additional time and resources required for such testing.

Yes Yes
Resilience Mechanism Bypass

If your mobile app has any resilience mechanisms (e.g. root, jailbreak or emulator detection, SSL pinning, code obfuscation, etc.), Corporate Pro or Ultimate package is required due to additional time and resources required for such testing.

Yes Yes
Price per Application

One application may include APIs and subdomains without which the application cannot work.

Please Log In to See Prices

How to Buy

Instant Online Purchase

  • All Product Benefits
  • Instant Online Payment
  • Instant Start 24/7/365
  • Zero Paperwork
  • 100% Online
Buy Now

Guided Purchase

  • All Product Benefits
  • Volume Discounts
  • Custom Packaging
  • Custom Contract
  • Personal Manager
Talk to Sales
VISA MasterCard American Express PayPal Maestro JCB UnionPay Bank Transfer
All payments can be made via a bank wire or secure online payment

Frequently Asked Questions

  • Q
    Do I need two packages for iOS and Android versions of the same app?
    A
    Normally yes, however, the second package will be offered with a 50% discount. Recurrent penetration testing of the same mobile app also has special discounts. Please get in touch with us to learn more and get a custom quote for your mobile security testing needs.
  • Q
    How can customize my mobile pentesting requirements?
    A
    At the first step of project creation, you can easily configure special requirements for mobile penetration testing. For example, you can select authenticated (White Box) testing with 2FA/SSO if you mobile app supports authentication, try some specific attack vectors, such as extracting protected content or activate features that are only available to premium users.
  • Q
    What is the difference between the packages?
    A
    Packages (from right to left) include gradually more human time and other resources that will be allocated for the penetration test. Generally, the bigger your scope is, the bigger package you need to comprehensively test your mobile application and its backend for all known vulnerabilities and attack vectors. Please reach out to us for a quote tailored for your specific needs and scope.
  • Q
    Can you test mobile applications built with Xamarin or Flutter?
    A
    Yes, we can test applications built with any mobile frameworks or technologies. However, complicated cross-platform frameworks, such as Xamarin and Flutter, impose additional challenges that usually require supplementary resources and human time for comprehensive testing of the application. Therefore, the minimum required package for those frameworks is MobileSuite Corporate.
  • Q
    How can I get a letter of compliance after completing penetration test?
    A
    For cybersecurity compliance services, ImmuniWeb collaborates with external law firms that can provide you with a letter of compliance signed by lawyers. Learn more.
  • Q
    Where will my data reside?
    A
    By default, your data resides on ImmuniWeb’s servers in Switzerland and Canada: both countries have an adequacy decision by the European Commission (EC) for the EU GDPR compliance purposes. Upon request, your data can be stored in another jurisdiction of your preference for an extra cost. Your data can be securely deleted at any time upon your request. No public cloud providers are used to store your data.
  • Q
    Do you offer special pricing for government, academia and non-profit organizations?
    A
    Yes, we do offer advantageous pricing for government, academia and non-profit organizations. Please reach out to our sales team to see whether your organization qualifies.
Because prevention is better

Why Choosing ImmuniWeb® AI Platform

Because You Deserve the Very Best

Reduce Complexity
All-in-one platform for 20
synergized use cases
Optimize Costs
All-in-one model & AI automation
reduce costs by up to 90%
Validate Compliance
Letter of conformity from law firm
confirming your compliance

Trusted by 1,000+ Global Customers

Gartner Peer Insights

Mobile Application Penetration Testing

Best Value for Money

Many of our mobile security experts started mobile penetration testing with the first version of iPhone over a decade ago. Today, ImmuniWeb pioneers mobile application penetration testing market with ImmuniWeb® MobileSuite that combines all-inclusive security, privacy and compliance testing of a mobile app and its backend.

Being well familiar with all the hurdles of a traditional mobile application penetration testing, we have been designing and continuously improving our offering to make it both cost-efficient and easily consumable.

Our award-winning Deep Learning AI technology accelerates and intelligently automates a wide spectrum of laborious security checks and tests that usually require many hours of expensive and unscalable human work. On top of our unique technology, our mobile security experts and CREST-accredited penetration testers conduct the most sophisticated security tests spanning from reverse engineering of mobile app defense solutions to sophisticated exploitation of business logic flaws or chained vulnerabilities in iOS or Android apps.

This hybrid approach consolidates the best of AI technology and human genius, delivering the most inclusive but rapid and price-wise service to our customers and partners. Prominent industry analysts from IDC, Forrester and Gartner mentioned the advantages of ImmuniWeb technology compared to fully automated mobile application security testing or human-driven mobile penetration testing assisted with fairly primitive mobile vulnerability scanners.

Importantly, our mobile application penetration testing is fully equipped with all possible DevSecOps integrations to facilitate vulnerability remediation by software developers.

Our packages include holistic and in-depth security and privacy testing both of the mobile application and its endpoints such as APIs and Web Services, effectively combining web and mobile security.

Our pricing outshines traditional penetration testing, heavily based on unscalable and thus expensive manual labor. While our unbeatable quality of testing overshadows automated mobile security testing tools by the number of detected security vulnerabilities and privacy risks.

Gartner IDC Forrester

Our award-winning hybrid approach consolidates the very best of Artificial Intelligence and human genius, eventually making human ingenuity both scalable and cost-efficient.

Get your free
ImmuniWeb®
MobileSuite

presentation
Book a Call Ask a Question
Close
Talk to ImmuniWeb Experts
ImmuniWeb AI Platform
Have a Technical Question?

Our security experts will answer within
one business day. No obligations.

Have a Sales Question?
Email:
Tel: +41 22 560 6800 (Switzerland)
Tel: +1 720 605 9147 (USA)
*
*
*
*
Your data will stay private and confidential