Insecure data storage
- World-readable files & prefs
- Secrets in SharedPreferences
- External-storage leaks
Atomic pulls your Android APK apart and runs 420+ OWASP checks across its bytecode — then streams back severity-graded findings with the exact class, line, and fix. No source code. No agent. No setup.
// first scan free · then €39 a scan · or subscribe from €49/mo
420+ checks across all eight OWASP MASVS categories and the full OWASP Mobile Top 10 — from hardcoded secrets to taint-tracked PII leaks. Each finding is graded, evidenced, and mapped to OWASP MASTG so you can fix it and re-verify.
No pipeline changes. No source. Upload a build and read the findings.
Drop your release APK into the dashboard, or push it through the API — no agent, no SDK, no CI wiring, nothing to install.
Atomic decompiles your release and walks its bytecode end to end, running all 420+ checks across the app exactly as it ships — the way an attacker would read it. No source, no instrumentation, nothing to change.
Severity-graded findings stream back live, each with the exact class, method, and smali/Java location, an OWASP MASTG reference, and a concrete fix. Export SARIF or CSV, pull results over the API, suppress false positives in one click.
No vague risk scores. Each result names the precise location in your code, cites the OWASP test it failed, and tells you exactly what to change. One click marks a false positive — and it stays suppressed.
A long-lived credential is embedded in the binary. Anyone who unzips the APK can read it and call your backend as the app.
const-string v3, "AKIA…REDACTED…7Q"
invoke-direct {v0, v3}, …AwsCreds;-><init>Move the secret server-side and rotate it. Issue the client a short-lived, scoped token at runtime instead of shipping a static key.
The finding above is illustrative. Sign up — no card — and explore three complete example reports on deliberately-vulnerable apps (InsecureShop, AndroGoat & InsecureBankv2) to see exactly what Atomic surfaces, before you upload your own.
Your first scan is free — no card. After that, €39 a scan or a subscription, with 30-day money-back on your first purchase.
New here? Your first scan is on us — no card. After that, €39 a scan. Money-back on your first purchase.
For solo devs & small studios.
High-volume scanning for a product team.
For pentest shops scanning client apps.
Every plan includes all 420+ checks, live findings, exports, and the full API — tiers differ by monthly scans and seats.
Self-host / air-gapped, SSO, custom check packages, volume pricing & SLAs.
The only thing you upload is the release APK — the same binary your users already have — so there is no source code or internal repo exposed. Your scans and findings stay in your workspace, visible only to your team and the API keys you issue.
No. Atomic analyses the release APK directly — decompiling it and tracing how data moves through the app. You scan exactly what your users install, with nothing to integrate.
No, and that is by design. Atomic only analyses the APK your users install, so a scan never sends a request to your servers or production APIs — zero risk to live systems. You get deep client-side coverage of your mobile app.
Scan apps you own, or that you are explicitly authorised to test — for example, a client app you are engaged to assess. Atomic is static-only: it analyses the uploaded APK and never touches live systems.
Every finding is severity-rated and ships with evidence: the exact class, method, and smali/decompiled-Java location, plus an OWASP MASVS/MASTG reference and a concrete fix. Anything you confirm as a non-issue is one click to suppress, and stays suppressed.
Most apps finish in minutes. Findings stream into the dashboard live as each check completes — you do not wait for the whole scan to read the first result.
Yes. Sign up, verify your email, and scan your first APK free — no credit card. After that it is €39 a scan or a subscription, with a money-back guarantee on your first purchase.
Your first payment is covered by our money-back guarantee — single scan or subscription. Not satisfied? Email [email protected] within 30 days and we will refund it.
You keep scanning — extra scans are billed per scan at your plan rate (€5 on Indie, €4 on Business, €3 on Consultancy), always cheaper than a one-off. Nothing blocks you mid-release.
Yes — the Enterprise plan covers on-prem / air-gapped deployment, SSO, custom check packages, and volume pricing. Talk to us.
Atomic is Android-first today. iOS (IPA) analysis is on the roadmap — tell us if you need it and we will keep you posted.
First scan free — no card. Then €39 a scan, or subscribe and scan on every build.
Scan your first build — free