Set the scope and test access
List the approved app, build, environment, accounts, roles, workflows, backend services, and prohibited actions. Confirm native and device coverage separately.
Casco uses the approved iOS or Android app and test accounts, records the backend calls made by the workflows in scope, and tests the authorization and business rules behind those calls. Native binary and device-level testing must be confirmed for the specific engagement.
Mobile application pentesting checks the approved app workflows and the services they call. Casco can test logged-in behavior, backend APIs, roles, tenant boundaries, data access, and business rules. Native binaries, local storage, deep links, and device controls are included only when the build, device setup, and scope support them.
How Casco tests
Scroll through the four parts of the test. The diagram shows what Casco has at each point, what it checks next, and what it records.
List the approved app, build, environment, accounts, roles, workflows, backend services, and prohibited actions. Confirm native and device coverage separately.
Casco follows the approved workflows and records the endpoints, accounts, objects, and state changes visible with the access provided.
Casco changes object references, roles, tenants, inputs, and request order to check authorization, session handling, data exposure, and business logic.
Each confirmed issue identifies the affected app or backend resource, impact, fix guidance, and steps to reproduce it.
Pentest deliverables
The report lists the workflows, accounts, services, builds, and device-level checks that were included so there is no ambiguity about coverage.
Learn more
See how Casco tests logged-in workflows, roles, tenant boundaries, and business logic.
Read the sourceSee how Casco tests API endpoints, identities, objects, and request sequences.
Read the sourceCompare fixed scanner checks with tests that use the application and its API.
Read the sourceChecks included when applicable
The findings depend on the accounts, backend services, builds, devices, and native coverage in the scope. Not every check below applies to every mobile test.
Related testing
Frequently asked questions
AI mobile application pentesting uses software agents to operate the approved app, inspect its backend requests, and choose the next security test from the response. Casco reports vulnerabilities it can reproduce.
Yes, when the backend endpoints, test accounts, and mobile workflows are included in the scope.
Yes, if the specific iOS or Android app, build, environment, and test method are agreed during scoping. Backend workflow testing does not automatically include native binary or device-level checks.
Only when it is included in the engagement. Native analysis may require an installable build, test device, source or symbols, and platform-specific tooling.
Only when native and device-level coverage is in scope. Otherwise, Casco tests the app workflows and backend services it can reach with the provided access.
Casco needs the approved app and environment, rules of engagement, and test accounts. Backend testing needs access to the relevant API. Native testing may also need an installable build, devices, source or symbols, and platform-specific setup.
A finding can include severity, the affected app or backend resource, impact, fix guidance, reproduction steps, execution output, and captured requests when request tracking is available.
Yes. Casco records the original result, the retest, and the current finding status.