Mobile Application Security Testing Reviews and Ratings

What is Mobile Application Security Testing (MAST)?

The mobile AST market is composed of buyers and sellers of products and services that analyze and identify vulnerabilities in applications used with mobile platforms (iOS, Android and Windows 10 Mobile) during or post development. Many variations and flavors of techniques exist, but fundamentally mobile AST solutions test applications in three main ways: (1) SAST: These solutions statically analyze the source, binary or bytecode of an application to identify vulnerabilities. (2) Behavioral testing: Mobile AST solutions use behavioral analysis to observe the behavior of the app during runtime and identify actions that could be exploited by an attacker. (3) DAST: These solutions also use dynamic analysis to test the app in its runtime state. DAST simulates attacks against an application and analyzes the application's reactions, determining whether it is vulnerable.

Product Listings

Filter by

Products 1 - 20 of 37

Appknox is a mobile application security firm utilized by different companies globally. It provides a platform for facilitating immediate threat detection within these applications. Appknox has developed a user-friendly system where an app can be uploaded, run through various test procedures, and then receive a comprehensive security diagnostic report. This report highlights any detected threats and provides suggestions for patching them. Appknox is designed to easily integrate with existing security protocols.

Show More Details

Checkmarx helps the world’s largest enterprises get ahead of application risk without slowing down development. We end the guesswork by identifying the most critical issues to fix and give AppSec the tools they need, all while letting developers work the way they want. From DevSecOps to developer experience, security and development teams can now work better together.

Show More Details

Ostorlab is an established Security Testing Automation Platform used globally by developers and security professionals. The primary function of Ostorlab is to appraise applications and identify vulnerabilities effectively and efficiently. It utilizes a substantial vulnerability knowledge database, an advanced detection model that learns from past flaws to identify potential future susceptibilities, and provides constant appraisal with each release and commit. Ostorlab emphasizes precision and aims for zero false positives through a state-of-the-art automated representation of vulnerabilities. Currently, Ostorlab's services are applicable for Mobile Applications on both Android and iOS, with plans to extend to Web Applications, Web APIs, and External Attack Surface Monitoring.

Show More Details

eShard focuses on addressing the increasing threat to the security of data in mobile and IoT devices. The company helps developers and solution providers recognize and comprehend the complexities and risks inherent in these technical areas. eShard advocates for the creation of robust security measures for the developers' products. The company's highly skilled R&D teams are vigilant in identifying and monitoring existing and emerging security threats. By utilizing the appropriate techniques and developing cutting-edge tools, eShard assists in ensuring that the product is secured against possible attacks, contributing to a safer mobile and interconnected world. The main services offered by eShard include providing dedicated security tools, security technical consultancy, and enhancements for mobile application security.

Show More Details

Black Duck builds trust in software by enabling organizations to manage application security, quality, and compliance risks at the speed their business demands. Black Duck solutions help developers to secure code as fast as they write it; development and DevSecOps teams to automate testing within development pipelines without compromising velocity; and security teams to proactively manage risk and focus remediation efforts on what matters most. With Black Duck, organizations can transform the way they build and deliver software, aligning people, processes, and technology to intelligently address software risks across their portfolio and at all stages of the application lifecycle.

Show More Details

NowSecure is a company focused on ensuring security and privacy in the mobile app landscape. The main business problem it addresses is the risk of data breaches within mobile applications. With a basis in standards, NowSecure provides tools for organizations that need to automate security checks, cut testing costs and decrease security risk within their mobile app structures. Their range of continuous security testing solutions cater to DevSecOps, mobile app supply-chain monitoring and penetration testing provided as a service. The company also contributes to open-source communities, standards and certifications such as OWASP MASVS, ADA MASA, NIAP. Their solutions are utilized by organizations and security teams around the world that require robust mobile app security.

Show More Details

Data Theorem focuses on preventing application security (AppSec) data breaches. The main areas of specialty include API Security, Web Security, Mobile Security, and Cloud Security. This is accomplished through the provision of static application security testing (SAST), dynamic application security testing (DAST), and runtime application self-protection (RASP). These services extend to various types of APIs, mobile applications, web applications, and cloud applications. The inventory, security testing, and active protection offered by Data Theorem across its range of products ensure robust defenses against data breaches. The headquarters of Data Theorem is located in Palo Alto, CA, with other offices spread across multiple cities internationally.

Show More Details

OpenText powers and protects information to elevate every person and every organization to gain the information advantage. As a global Information Management company, OpenText offers a portfolio of solutions across content, business network, digital experience, security, application modernization, operations management and developer APIs. OpenText solutions help customers simplify their systems, connect their data, build frictionless automation and thrive in a multi-cloud world. The company fosters inclusive environments that leverage the diverse backgrounds and perspectives of all employees, customers, suppliers and partners.

Show More Details

HCLSoftware is an integral arm of HCLTech and is primarily engaged in the development, marketing, sale, and support of software solutions. The company's main sector focus includes AI and Automation, Data, Analytics and Insights, Digital Transformation, and Enterprise Security. As a provider of cloud-native solutions for enterprise software, HCLSoftware is responsible for powering an extensive number of applications at numerous organizations globally. The fundamental mission of HCLSoftware revolves around ensuring customer success through continuous product innovation.

Show More Details

Pradeo is a company that focuses on mobile security. With global operations, it delivers services aimed at safeguarding smartphones, tablets, and mobile applications. The firm's primary solution, Pradeo Security, employs advanced AI-based technology to offer robust defense against mobile threats. This technology helps to prevent data leakage and enhances compliance with data privacy regulations. The business caters to a diverse range of sectors including the public sector and private companies. Pradeo maintains a cooperative approach, developing integrations and joint solutions with enterprise mobility companies around the world.

Show More Details

Testhouse, founded in 2000 and headquartered in London, UK, operates on a global scale with a focus on providing software testing, quality assurance, and DevOps services. It has a broad presence with offices in the USA, Middle East, Australia and offshore development centres in India. Testhouse delivers a variety of third-party software testing services. These include manual and automation functional testing, performance, and security/penetration non-functional testing as well as Microsoft Dynamics 365 testing. In addition, it provides consulting and training on various tools. Further services encompass source code security code review, feasibility studies, assurance audits, and additional IT and quality assurance consultancy services. The company holds ISO 9001:2015 and ISO 27001:2013 certifications.

Show More Details

Founded in 2015, Mobisec has focused on application cybersecurity from the beginning.

We were created to meet the security needs of an increasingly connected world, developing unique skills and knowledge in ethical hacking and innovation. We offer tailor-made solutions to provide security and peace of mind for those managing application cybersecurity, mobile devices, and IoT in their companies.

Our mission is to reduce clients' risks and concerns with an innovative approach to mobile security.

Show More Details

Quixxi focuses on app security, providing an automated vulnerability assessment that presents a thorough analysis of apps. It generates detailed reports mentioning every detected vulnerability, explaining the risks involved, and suggesting solutions. Quixxi Shield offers protection against unauthorized use and malicious tampering of apps without the need for coding. It further contributes to app security by enforcing the licensing model through Quixxi Supervise. This function can identify and restrict access to unlicensed users. Quixxi extends its services towards app performance analytics, providing insights on user interactions after the app's publication. It also offers diagnostics support, practical for troubleshooting by collecting detailed information and debug files directly from the affected user.

Show More Details

ImmuniWeb® AI Platform is a service offered to enterprises all around the globe. It focuses on safeguarding applications and infrastructure to mitigate supply chain attacks and prevent data breaches. Additionally, the platform helps maintain compliance requirements. ImmuniWeb® AI Platform uses advanced AI and Machine Learning technology to speed up and intelligently automate the process of attack surface management, dark web monitoring and risk-based application penetration testing for web, mobile, and API security testing. A key feature of the company is its assurance to buyers of zero false positives. The ImmuniWeb® Community Edition is known to perform over 100,000 daily tests, establishing one of the vast application security communities. The business is registered as ImmuniWeb SA.

Show More Details

Pradeo is a company that focuses on mobile security. With global operations, it delivers services aimed at safeguarding smartphones, tablets, and mobile applications. The firm's primary solution, Pradeo Security, employs advanced AI-based technology to offer robust defense against mobile threats. This technology helps to prevent data leakage and enhances compliance with data privacy regulations. The business caters to a diverse range of sectors including the public sector and private companies. Pradeo maintains a cooperative approach, developing integrations and joint solutions with enterprise mobility companies around the world.

Show More Details

Quokka is a mobile security company, trusted by the Fortune 500 and governments worldwide to reduce their mobile attack surface. Formerly known as Kryptowire, the company is the first and longest-standing mobile app security solution for the US Federal Government. Quokka’s Contextual Mobile Security Intelligence is app risk intelligence that uncovers what lurks in mobile apps—malicious behaviors, zero day threats, privacy risks, and compliance gaps. Powered by multiple detection engines and machine learning, it cuts through the noise to deliver precise, actionable insights that plug key gaps in enterprise mobile detection capabilities. Designed for device security, Q-scout uses behavior-driven detection to uncover malicious intent and privacy risks within apps. Built for app development, Q-mast performs comprehensive testing at every stage, pinpointing risks in your code to resolve vulnerabilities early and ensure secure app releases from the start.

Show More Details

Syhunt specializes in developing advanced, patented web application security assessment technology. The technology is designed to provide organizations with the ability to simulate web-based attacks and identify vulnerabilities, offering both remote and in-house solutions. The aim is to support organizations in actively protecting their web infrastructure from potential security threats.

Show More Details

Aikido is a developer-centric security platform that gives developers and security teams an instant overview of all code-to-cloud security issues and guides teams to fix vulnerabilities fast.

Aikido supports security teams execute by aggressively reducing false-positives, automatic triage and risk bundling, and translating Common Vulnerabilities and Exposures (CVEs) into easy step-by-step explanations to resolve.

Described as an "all-in-one" application security platform, Aikido's covers the entire Software Development Lifecycle (SDLC), including: static application security testing (SAST), dynamic application security testing (DAST), infrastructure-as-code (IaC), container scanning, secrets detection, open source lisence scanning, cloud posture management (CSPM), runtime protection, and more.

Be the first to .

RAY Labs is a PropTech firm committed to resolving challenges associated with the management of community and space. The primary product that RAY Labs offers is a mobile-centric Software as a Service (SaaS) platform. This platform is aimed at equipping property, facility, and community managers with the necessary tools to efficiently supervise communities and spaces. By using these tools, operational efficiency might significantly improve, the process of making payments could potentially become more convenient, community interaction could be heightened, and administrative work may be lessened.

Be the first to .

AppCheck is a Dynamic Application Security Testing (DAST) solution, developed and supported by experienced penetration testers. We approach security testing as a hacker would, leveraging multiple proprietary crawling engines to analyse target behaviour across both modern and traditional technologies, including Single Page Applications (SPAs), APIs, and complex authentication flows such as SSO, 2FA, and TOTP. Organisations can conduct unlimited security assessments across web applications, APIs, cloud services, networks, and internal or external assets.

Supporting production and UAT testing, AppCheck also enables ‘shift left’ security by integrating with CI/CD pipelines and build servers, including ADO, GitHub, Jenkins, TeamCity, CircleCI, TravisCI, Bamboo, and GitLab CI/CD. Allowing automated security testing throughout development, identifying risks as soon as changes are introduced.

AppCheck is also a CVE Numbering Authority (CNA), contributing to global security research

Be the first to .