OWASP Mobile Top 10 · MASVS · MASTG — 420+ checks

Disassemble the risk in every release.

Atomic pulls your Android APK apart and runs 420+ OWASP checks across its bytecode — then streams back severity-graded findings with the exact class, line, and fix. No source code. No agent. No setup.

// first scan free · then €39 a scan · or subscribe from €49/mo

com.acme.banking
sample 66/66 · 12s
Severity spectrum 41 findings
2 critical 6 high 11 medium 14 low 8 info
critical Hardcoded AWS secret key
high WebView allows file:// access
medium Vulnerable OkHttp · CVE-2021-0341
low Cleartext traffic permitted
info Debuggable build flag set
420+
automated checks
76
security analyzers
Minutes
to first finding
Live
streaming results
§ 01 — Detection

The periodic table of mobile risk.

420+ checks across all eight OWASP MASVS categories and the full OWASP Mobile Top 10 — from hardcoded secrets to taint-tracked PII leaks. Each finding is graded, evidenced, and mapped to OWASP MASTG so you can fix it and re-verify.

criticalhighmediumlowinfo
01 STORAGE
St

Insecure data storage

  • World-readable files & prefs
  • Secrets in SharedPreferences
  • External-storage leaks
02 CRYPTO
Cr

Broken cryptography

  • Weak ciphers & modes
  • Hardcoded keys / IVs
  • Cipher + signature key reuse
03 AUTH
Au

Auth & secrets

  • Hardcoded credentials
  • Gitleaks secret rules
  • Exposed API tokens
04 NETWORK
Nt

Network security

  • Cleartext traffic allowed
  • Permissive network config
  • Disabled cert pinning
05 PLATFORM
Pf

Platform & IPC

  • Exported components
  • Insecure WebViews
  • Implicit-intent PII leaks
06 CODE
Cd

Vulnerable code

  • CVE libraries via OSV
  • Outdated dependencies
  • Dangerous API usage
07 PRIVACY
Pv

Privacy & PII

  • PII written to logs
  • Tracking in notifications
  • Over-broad permissions
08 RESILIENCE
Rs

Tamper resilience

  • Missing root/debug checks
  • No anti-tamper
  • Unprotected signing
§ 02 — Method

From upload to verdict, in three moves.

No pipeline changes. No source. Upload a build and read the findings.

01 INTAKE

Upload an APK

Drop your release APK into the dashboard, or push it through the API — no agent, no SDK, no CI wiring, nothing to install.

02 ANALYSIS

Take it apart

Atomic decompiles your release and walks its bytecode end to end, running all 420+ checks across the app exactly as it ships — the way an attacker would read it. No source, no instrumentation, nothing to change.

03 READOUT

Read the findings

Severity-graded findings stream back live, each with the exact class, method, and smali/Java location, an OWASP MASTG reference, and a concrete fix. Export SARIF or CSV, pull results over the API, suppress false positives in one click.

§ 03 — Evidence

Every finding, dissected.

No vague risk scores. Each result names the precise location in your code, cites the OWASP test it failed, and tells you exactly what to change. One click marks a false positive — and it stays suppressed.

Finding · specimen SAMPLE
critical CRYPTO MASTG-TEST-0014

Hardcoded AWS secret key in API client

A long-lived credential is embedded in the binary. Anyone who unzips the APK can read it and call your backend as the app.

Lcom/acme/net/ApiClient;->init ApiClient.java:42
const-string v3, "AKIA…REDACTED…7Q"
invoke-direct {v0, v3}, …AwsCreds;-><init>
FIX

Move the secret server-side and rotate it. Issue the client a short-lived, scoped token at runtime instead of shipping a static key.

See the real thing — free.

The finding above is illustrative. Sign up — no card — and explore three complete example reports on deliberately-vulnerable apps (InsecureShop, AndroGoat & InsecureBankv2) to see exactly what Atomic surfaces, before you upload your own.

Explore example reports — free
§ Pricing

Start with one scan. Scale to hundreds.

Your first scan is free — no card. After that, €39 a scan or a subscription, with 30-day money-back on your first purchase.

Free · your first scan, full report

New here? Your first scan is on us — no card. After that, €39 a scan. Money-back on your first purchase.

Start free
Most popular

Indie

€49 / mo

For solo devs & small studios.

  • 10 scans every month
  • Extra scans €5 each
Start with Indie

Business

€599 / mo

High-volume scanning for a product team.

  • 180 scans every month
  • 5 team seats
  • Extra scans €3 each
Start with Business

Consultancy

€999 / mo

For pentest shops scanning client apps.

  • 400 scans every month
  • 20 team seats
  • Extra scans €2 each
Start with Consultancy

Every plan includes all 420+ checks, live findings, exports, and the full API — tiers differ by monthly scans and seats.

Enterprise

Self-host / air-gapped, SSO, custom check packages, volume pricing & SLAs.

Contact us
§ FAQ

Before you upload.

01 Is it safe to upload my app? +

The only thing you upload is the release APK — the same binary your users already have — so there is no source code or internal repo exposed. Your scans and findings stay in your workspace, visible only to your team and the API keys you issue.

02 Do you need my source code? +

No. Atomic analyses the release APK directly — decompiling it and tracing how data moves through the app. You scan exactly what your users install, with nothing to integrate.

03 Does it test my backend or live APIs too? +

No, and that is by design. Atomic only analyses the APK your users install, so a scan never sends a request to your servers or production APIs — zero risk to live systems. You get deep client-side coverage of your mobile app.

04 What am I allowed to scan? +

Scan apps you own, or that you are explicitly authorised to test — for example, a client app you are engaged to assess. Atomic is static-only: it analyses the uploaded APK and never touches live systems.

05 How accurate is it — will I drown in false positives? +

Every finding is severity-rated and ships with evidence: the exact class, method, and smali/decompiled-Java location, plus an OWASP MASVS/MASTG reference and a concrete fix. Anything you confirm as a non-issue is one click to suppress, and stays suppressed.

06 How long does a scan take? +

Most apps finish in minutes. Findings stream into the dashboard live as each check completes — you do not wait for the whole scan to read the first result.

07 Is the first scan really free? +

Yes. Sign up, verify your email, and scan your first APK free — no credit card. After that it is €39 a scan or a subscription, with a money-back guarantee on your first purchase.

08 What if a scan is not useful to me? +

Your first payment is covered by our money-back guarantee — single scan or subscription. Not satisfied? Email [email protected] within 30 days and we will refund it.

09 What happens when I use up my monthly scans? +

You keep scanning — extra scans are billed per scan at your plan rate (€5 on Indie, €4 on Business, €3 on Consultancy), always cheaper than a one-off. Nothing blocks you mid-release.

10 Can I self-host or run on-prem? +

Yes — the Enterprise plan covers on-prem / air-gapped deployment, SSO, custom check packages, and volume pricing. Talk to us.

11 iOS? +

Atomic is Android-first today. iOS (IPA) analysis is on the roadmap — tell us if you need it and we will keep you posted.

Find what your last pentest missed.

First scan free — no card. Then €39 a scan, or subscribe and scan on every build.

Scan your first build — free