Mobile app pentest

Mobile app penetration testing

Focused security testing for your iOS or Android application.

Lite01
$5,499

For startups preparing for a first audit or vendor review.

Assessment surface
One mobile application
Maximum user roles
2
Fix validation
Add-on available
  • Manual pentest with OWASP Top 10 coverage
  • Report with severity, impact, reproduction steps and fixes
  • 30-day findings Q&A by email/Slack
  • Attestation letter
Essentials02
$7,999

For growing teams handling sensitive data and recurring customer reviews.

Assessment surface
One mobile application
Maximum user roles
3
Fix validation
One round within 90 days
  • Everything in Lite
  • One fix-validation round within 90 days
  • Jira / CSV issue export
  • Business logic abuse testing
Assurance03
$9,499

For regulated teams and complex applications that need deeper coverage.

Suitable for applications with AI/LLM features.

Assessment surface
One mobile application
Maximum user roles
5
Fix validation
One round within 90 days
  • Everything in Essentials
  • One fix-validation round within 90 days
  • Jira / CSV issue export
  • Advanced attacks and business logic abuse
Need a different scope?

Multiple applications, a larger environment, or a fixed deadline.

Talk to an expert

The details, side by side.

Compare scope limits and the delivery foundation in every package.

Mobile app · Scope and inclusions
Scope & deliverablesLiteEssentialsAssurance
Price $5,499 $7,999 $9,499
Choose a packageChoose LiteChoose EssentialsChoose Assurance
Assessment surfaceMobile appMobile appMobile app
Maximum user roles235
OWASP Top 10 coverageIncludedIncludedIncluded
Report with evidence and remediationIncludedIncludedIncluded
30-day findings Q&A · email/SlackIncludedIncludedIncluded
Attestation letterIncludedIncludedIncluded
Executive summaryNot listedIncludedIncluded
Fix validation within 90 daysAdd-onOne roundOne round
Jira / CSV issue exportNot listedIncludedIncluded
Business logic coverageLimited depthBusiness logic abuseAdvanced attacks and business logic abuse
Fast-track startAdd-on · subject to availabilityAdd-on · subject to availabilityEligible · subject to availability; add-on 50% off
Live debrief callAdd-onAdd-onOptional · arrange with Blaze
AI/LLM applicationsChoose AssuranceChoose AssuranceSuitable for applications with AI/LLM features.
Choose a packageChoose LiteChoose EssentialsChoose Assurance

Before you decide.

What happens after I purchase?

Your project manager coordinates setup, scope confirmation, access requirements and delivery dates before testing starts. You will receive findings and reports through VulnKeep.

How soon can testing start?

Testing typically starts in 2–3 weeks, subject to availability and scope readiness. Fast-track scheduling targets approximately one week. Your project manager confirms the dates before testing begins.

What if my scope is larger?

Talk to an expert before purchase for larger or unusual scopes. Blaze will help determine the appropriate package or a custom assessment.

Is fix validation included?

Lite offers fix validation as an add-on. Essentials and Assurance include one round within 90 days. Additional rounds are available separately.

Does one package cover both iOS and Android?

Each package covers one mobile application. Talk to an expert before purchase if you need coverage across both iOS and Android.

Compliance support

Pentests for compliance and beyond.

Support audit, customer and procurement requirements with independent testing and clear reporting.

Testing is scoped around the requirements relevant to your organization.

GDPR, ISO 27001, HIPAA, PCI DSS and SOC 2 — compliance frameworks supported by Blaze pentests