For mobile product owners and development teams preparing a release, introducing sensitive data flows or arranging an independent customer assessment.
Before a mobile release or a change to sensitive data handling.
What we examine
- Confirm the platform, application build, access and backend services in scope.
- Examine relevant data handling, trust boundaries and client-server interactions.
- Validate findings and distinguish client-side issues from backend risks.
A clear start. A useful finish.
Tell me the problem
Share the product, stack, goal and deadline. A short overview is enough to start the conversation.
Agree the engagement
Receive a written scope, deliverables, acceptance criteria, price and schedule before we begin.
Review the work as it develops
For assessments, examine the evidence and priorities. For engineering, review agreed implementation milestones.
Put the result to work
Get a technical walkthrough and useful handoff. Agree any further implementation or verification your team needs.
I can build the system behind the solution.
My work spans software architecture, implementation and security research. I designed and developed Hendra’s context-aware scanning architecture. That experience is useful when your challenge needs engineering as well as investigation.
See how I built HendraQuestions before we begin
Which mobile platforms can you assess?
Share the platform, framework and build requirements. We confirm suitability and the testing approach before agreeing the engagement; the proposal names the supported targets.
Is backend and API testing included?
Only when it is explicitly in scope. A mobile application assessment and a backend assessment have connected but different boundaries, which the proposal makes clear.
What access do you need?
This depends on the agreed approach. Relevant builds, test accounts, environment details and, for code-assisted work, selected source code may be needed.
Useful lessons from security research
- After React2Shell: three security boundaries every server component review needs
- The 2026 Axios attack: why a clean dependency tree cannot clear a build runner
- CVE-2024-26855: when a missing attribute becomes a NULL dereference