This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money
Mobile application penetration testing services: prices, scope and retest terms compared
By The PenTest Index · Offers checked October 9, 2026
Mobile application penetration testing services test your iOS or Android app and, only if the scope says so, the API behind it. Four of eight providers we checked on October 9, 2026 publish a starting price; the selected pricing cards and listings run from $2,200 per app (Astra, shared codebase) to $6,000 (Blaze). Astra and NowSecure count iOS and Android as two units, so name both builds.
The short version. If a customer or auditor asked for a pentest report, buy a human-led test that names the app builds and API in the requested scope. If your fixes will take more than a month, look first at Blaze and Software Secured, because Astra Pentest Expert's included re-check must be requested within 30 days. If all you want is the Google Play security badge, you need a different review, covered below.
Mobile application penetration testing services compared
Compare the exact offer, not the company. The same provider can sell a yearly plan, a one-off test and a quote-only service, and each has its own price unit and re-check rules.
Companies are listed A to Z within each group. This is not a ranking. Prices are in US dollars. Everything below is provider-published: we read it on the provider's own pages on October 9, 2026. We have not bought these tests.
Offers with a published starting price
| Provider and offer | Published price and unit | iOS and Android | Backend API | Retest terms | Stated timing |
|---|---|---|---|---|---|
| Astra, Pentest Expert | $5,999 per year per target. For apps that share a codebase, its FAQ says "tailored pricing starting from $2200/app depending on the scope". The billing period for that figure is not stated. Pricing | Two targets. "Mobile is per platform, so an Android app and an iOS app are two targets." | Not stated for a mobile target. Standalone APIs count as one target each. | 2 manual rescans, within 30 days of the date the vulnerabilities were reported. Fix at least 50% of Critical and High findings first. Extensions case by case. Rescan rules | Manual pentest: 10 to 15 working days (pricing FAQ) |
| Blaze, mobile app pentest | "From $5,299" in its cost guide. "Prices starting at $6,000" on its AWS Marketplace listing, followed by a private offer. | Tests "each iOS and Android build". Its cost guide associates $5,299–$9,999 with a single platform. Platform coverage at the $6,000 Marketplace starting price is not stated. | "Can be included." A large or shared API estate "may need a dedicated API pentest". Mobile page | AWS listing: free fix validation within 90 days of the final report. Its own site says retesting is available "when included". | Average start about two weeks. Effort 5 to 25 person-days (AWS listing). |
| Halo Security, mobile app pentest | "Starts at $3,950", then a fixed-price quote after a scoping call. Service page | Number of platforms is a listed price factor. No multiplier published. | Backend API complexity is a listed price factor. Backend API testing is listed in its coverage; the full API scope at the starting price is not stated. | One round of retesting included. Window not stated. | 1 to 2 weeks for one platform, 2 to 3 for both, 3 to 4 for complex apps |
| Software Secured, Mobile App Pentesting | "Starts at $5,400 USD." Pricing Its mobile service page also displays $10,800 USD. The pages do not explain the difference; confirm the applicable starting scope. | Scoping is "based on platforms, APIs, SDKs". Whether the starting price covers one platform or two is not stated. | APIs are named in its coverage line. | "3 rounds over 12 months." Requests within 12 months of report delivery. | Scheduling within 3 to 6 weeks, sometimes sooner; report within 48 to 72 hours of test completion |
Quote-only offers
| Provider and offer | What it publishes about mobile | Price basis | Retest terms |
|---|---|---|---|
| Cobalt, pentest under an annual credit package | Method based on OWASP MASVS and MASTG. Testers "do not need access to the source code", unless you require it. You share the IPA and/or APK files. Backend work follows its API method. Mobile method | Annual credits. No mobile figure. Credits needed for your scope require a quote. Pricing | The help policy states free retesting for 6 months (Standard) or 12 months (Premium, Enterprise), only while the contract is active, and no later than 10 days before it ends. The pricing FAQ instead describes retesting throughout the contract; confirm the applicable end date. Retest policy |
| DeepStrike, mobile app pentest | Manual testing with API security testing listed. Service page | Quote. No unit stated. | "Free Unlimited Re-testing" on the mobile page. Its Basic pricing plan lists 12 months of remediation retesting; confirm that plan applies to the mobile quote and when the period starts. |
| NetSPI, Mobile App Pentesting | "Human-led" testing for iOS and Android, covering "both client-side and backend server functionality". Service page | Quote. No figure on the page. | Not stated on the mobile page. |
| NowSecure, mobile app pen test | Testing on real iOS and Android devices, signed in as a user. Sells full-scope and focused tests. Service page | Quote. Its terms (effective August 6, 2026) count the same app on iOS and Android as two Apps. | "A retest to confirm the fix" is listed. Count and window not stated. |
Two things follow from these tables. A provider that can test both platforms has not told you one price covers both. And two platforms does not mean you pay for two full API tests. Ask every provider to split the quote into three lines: iOS work, Android work and shared backend work.
Which mobile pentest offers deserve a closer look?
Start with the condition that would rule an offer out for you. For most teams that is the retest date, then source code access, then how the app is counted.
| Your situation | Look first | What to confirm |
|---|---|---|
| One test this year, and fixes will take longer than 30 days | Blaze, Software Secured | That the retest is written into your offer, and what starts the clock |
| You can share app files but not source code | Blaze, Cobalt, Software Secured | "Can you finish this scope with builds and test accounts only? What would be left out?" |
| Several tests a year across apps and APIs | Cobalt | Credits needed per test, and your contract end date |
| You want a yearly plan and can fix inside 30 days | Astra Pentest Expert | Target count, whether the API is a third target, and which plan the "$2,200/app" figure belongs to |
| One platform and a low published starting figure | Halo Security | What the starting price leaves out, and the retest window |
| Complex signed-in flows, or you need proof on real devices | NowSecure, NetSPI | Full-scope or focused, NowSecure's two-app count, and retest terms |
| You already have a pentest provider or a recent API report | Your current provider | "Which mobile app and app-to-API work does our last report leave open?" |
That last row matters. If your API was tested recently and has not changed much, you may only need the two app builds tested. Ask before you buy a whole new assessment.
A worked Purchase Check
A Purchase Check is how we turn published terms into a decision: take one buyer's requirements, apply them to one exact offer and record what the evidence shows. "Supported" means that one condition is backed by what the provider published. It is not a verdict on testing quality, and it does not mean your customer will accept the report.
Here is an example. It is made up, and no provider has quoted for it.
The brief: Say you ship one app on iOS and Android from a shared React Native codebase. It talks to one API and has two user roles. You can hand over app files, test accounts and API docs, but not source code. Your customer wants a report that names both builds and the API. Findings and the final report arrive on the same day, and your fixes will be ready for a manual re-check 45 days later.
| Requirement | Offer | What the published terms show | Finding | Question to send |
|---|---|---|---|---|
| Manual retest requested on day 45 | Astra Pentest Expert | Rescans must be requested within 30 days of findings being reported | Mismatch | "Will you include a manual rescan requested on day 45, and at what price?" |
| Manual retest requested on day 45 | Blaze, AWS Marketplace listing | Fix validation within 90 days of the final report | Unresolved on the request deadline; day 45 falls within the published validation period | "Confirm the day-45 retest is in our offer, and whether 90 days is the date to request or to finish." |
| Manual retest requested on day 45 | Software Secured | 3 rounds; requests within 12 months of report delivery | Supported for the timing condition | "Confirm our report-delivery date and available retest rounds." |
| Manual retest requested on day 45 | Cobalt | 6 or 12 months by tier, capped at 10 days before the contract ends | Unresolved until Cobalt confirms the applicable retest end date | "What is our last retest submission date?" |
| Manual retest requested on day 45 | Halo, NetSPI, NowSecure | A retest is listed, but no window | Unresolved | "Until what date can we request the included retest?" |
| Manual retest requested on day 45 | DeepStrike | Basic lists 12 months; mobile-plan applicability and the clock start are not established | Unresolved | "Does Basic apply to our mobile quote, and what is our last retest request date?" |
| No source code | Blaze, Cobalt, Software Secured | All three say they can test app files without source | Supported | "List anything you could not test without source." |
| Both platforms priced | Astra Pentest Expert | Two targets at $5,999 each | Supported: $11,998 per year at list. The API may be a further target. | "Is our API a third target? Does shared-codebase pricing apply instead?" |
| Both platforms priced | NowSecure | Two Apps under its terms | Supported as a count. Price is unresolved. | "Itemize both apps and the shared API work." |
| Complete price for both builds plus the API | Every offer | No provider publishes this total | Unresolved | "What is the complete price for iOS, Android and the API with two roles, including the day-45 retest?" |
What this means for that buyer. Astra Pentest Expert is out on its included terms, because day 45 is past the 30-day window. It comes back in only if Astra extends the window in writing. Blaze and Cobalt pass the no-source-code condition; Blaze's day-45 request deadline and Cobalt's applicable retest end date still need confirmation. Software Secured passes the published retest and no-source conditions. Between them, the choice is about how you buy. Blaze and Software Secured publish a starting dollar figure for a single test. Cobalt sells a year of credits, which makes more sense if you will run several tests.
One answer that still decides it is the complete price. Nobody publishes it for two builds plus an API, so send the same brief to each and compare the itemized replies.
Compare the offers that may fit:
If your fixes will land inside 30 days, or you want scanning included in a yearly plan:
For a single platform, or for testing on real devices:
These links open the provider's own page. They do not send your details to anyone.
How much does a mobile app penetration test cost?
The selected pricing cards and listings show starting figures from $2,200 to $6,000, but none of them is a full price for two app builds plus an API. Here is what each number actually is, as checked on October 9, 2026:
- $2,200 per app. Astra's starting point for "tailored pricing" when iOS and Android share a codebase. The billing period is not stated.
- $3,950. Halo Security's starting price before a scoping call.
- $5,299 and $6,000. Blaze's starting prices in its own cost guide and on AWS Marketplace. They differ by channel, and the Marketplace price leads to a private offer.
- $5,400. Software Secured's mobile pricing-card figure. Its mobile service page also displays $10,800 USD; confirm the applicable starting scope.
- $5,999 per year per target. Astra's Pentest Expert plan. An iOS app and an Android app are two targets, so the list arithmetic for both is 2 × $5,999 = $11,998 a year. That is our sum from Astra's published rule, not a quote.
A starting price is the floor for the smallest job the provider will take. These are the things that move it:
- Platforms. One build or two.
- The API. In, out or already tested.
- User roles. Each extra role is more permission checking.
- Source code. Testing with it can go deeper and may be scoped differently.
- Retest terms. A second re-check, or a later one, can cost extra.
- Commitment. One test, or a yearly plan or credit package.
You will also see wide ranges quoted around the web. Blaze's cost guide, for example, lists $5,000 to $30,000 as the "average 2026 cost" of a mobile app pentest. That is Blaze's estimate. We do not have a measured market average, and we will not invent one.
For prices across every kind of test, see penetration testing cost.
Do iOS and Android need separate penetration tests?
If you ship both, both need to be in the scope, and most pricing treats them as two units. Astra counts two targets. NowSecure's terms count two Apps. Blaze says it tests "each iOS and Android build" with platform-specific techniques, "even when both apps share a backend". Halo lists the number of platforms as a price factor.
Why can't one test cover both? Think of the same recipe cooked in two different kitchens. The logic is shared. But where the app keeps data on the phone, how it talks to other apps and how it resists tampering are built differently on each system. A flaw on Android may not exist on iOS, and the reverse.
A shared codebase, such as React Native or Flutter, is still worth mentioning to providers. Astra says in writing that it changes the price. Ask the others to show which work is shared and which is per platform.
If you only ship on one platform, say so and skip the second. Don't pay for an Android test of an app that doesn't exist.
Does a mobile app pentest include the backend API?
Not automatically. An API is the server-side interface your app sends data to and gets data from. OWASP, the nonprofit behind the main mobile security standard, is blunt about the gap: its Mobile Application Security Verification Standard (MASVS) "only covers the security of the mobile app (client-side)", and the remote endpoints "should be verified against appropriate standards" of their own. OWASP source
This matters because the app is the remote control and the API is the TV. Most of what an attacker wants, such as other customers' data, lives behind the API.
What the providers publish:
- Blaze: APIs "can be included". A large or shared API estate "may need a dedicated API pentest".
- Cobalt: backend testing follows its separate API method.
- NetSPI: tests "both client-side and backend server functionality".
- Software Secured: names APIs in its mobile coverage line.
- Astra: mobile API testing is listed, but the included scope is not defined. Standalone APIs count as one target each.
- Halo Security: API complexity changes the price.
So write the API into your request by name: which services, which environment, which roles. Then ask whether it is included, excluded or priced separately.
What if the API was already tested?
Then you may not need to pay for it twice. Give the provider the earlier report's scope and date, and tell them what has changed since. Ask them to price only what is still open: the two app builds and the way they talk to the API. Check with whoever asked for the report that the earlier API test still counts for them.
If you also have a web app on the same API, see web application penetration testing services.
Will the retest window last until your fixes are ready?
"Retest included" tells you almost nothing until you know the count, the deadline and what starts the clock. A retest is the provider checking that your fixes worked. If you miss the window, you either pay again or hand your customer a report with open findings.
The clocks we could read on October 9, 2026 start from different events:
| Offer | Included re-checks | Deadline | Clock starts |
|---|---|---|---|
| Astra Pentest Expert | 2 manual rescans | 30 days | The date the vulnerabilities were reported |
| Astra Enterprise (from $9,999 per year) | 4 rescans | 90 days | The date the vulnerabilities were reported |
| Blaze, AWS Marketplace listing | Fix validation, count not stated | 90 days | The final report |
| Cobalt | Free retesting | 6 months (Standard) or 12 months (Premium, Enterprise) | Not stated in the policy we read. Capped at 10 days before your contract does. |
| Software Secured | 3 rounds | 12 months for requests | Report delivery |
| Halo Security | 1 round | Not stated | Not stated |
| DeepStrike | "Unlimited" on the mobile page | Basic plan: 12 months; applicability to mobile quote requires confirmation | Not stated |
Two details are easy to miss. Astra asks you to fix at least 50% of Critical and High findings before you request a manual rescan. And Cobalt's deadline is tied to your contract, not only your tier. Say your Cobalt contract ends December 20. Under the documented ten-day rule, the contract-based submission cutoff is December 10, even if your tier's 12 months would run longer.
Check your own date:
Retest date check
This assumes your findings and final report arrive on the same day. If your report arrives later, the Blaze and Software Secured clocks start later.
Worked example, without entering anything: D = 45, C = Not sure; Astra Pentest Expert: Mismatch; Astra Enterprise: Supported for timing; Blaze: Unresolved on request deadline; Software Secured: Supported for timing; Cobalt: Unresolved; Halo Security, DeepStrike, NetSPI and NowSecure: Unresolved.
Your results
Astra Pentest Expert
Finding: Unresolved
Ask your team when fixes will be ready, then check again. 2 manual rescans. Fix at least 50% of Critical and High findings first. Extensions case by case.
Source checked October 9, 2026: Astra Pentest Expert source
Astra Enterprise
Finding: Unresolved
Ask your team when fixes will be ready, then check again. 4 manual rescans, subject to remaining quota. Fix at least 50% of Critical and High findings first. Extensions case by case. Plan is $9,999 per year onwards.
Source checked October 9, 2026: Astra Enterprise source; Astra pricing
Blaze (AWS Marketplace listing)
Finding: Unresolved
Ask your team when fixes will be ready, then check again. Fix validation is published within 90 days of the final report; the last request date and completion schedule need confirmation.
Source checked October 9, 2026: Blaze (AWS Marketplace listing) source
Software Secured
Finding: Unresolved
Ask your team when fixes will be ready, then check again. 3 rounds; requests are within 12 months of report delivery.
Source checked October 9, 2026: Software Secured source; Software Secured mobile service
Cobalt
Finding: Unresolved
Ask your team when fixes will be ready, then check again. The contract cutoff is a cap, and the tier period can expire earlier; confirm the applicable tier end date.
Source checked October 9, 2026: Cobalt source; Cobalt pricing
DeepStrike
Finding: Unresolved
Ask your team when fixes will be ready, then check again. Basic lists 12 months; confirm the mobile quote's plan, clock start and last request date.
Source checked October 9, 2026: DeepStrike source
Halo Security
Finding: Unresolved
Ask your team when fixes will be ready, then check again. A retest is listed but no window is published. Ask for the last request date in writing.
Source checked October 9, 2026: Halo Security source
NetSPI
Finding: Unresolved
Ask your team when fixes will be ready, then check again. A retest is listed but no window is published. Ask for the last request date in writing.
Source checked October 9, 2026: NetSPI source
NowSecure
Finding: Unresolved
Ask your team when fixes will be ready, then check again. A retest is listed but no window is published. Ask for the last request date in writing.
Source checked October 9, 2026: NowSecure source
What does a mobile app penetration test cover?
A penetration test, or pentest, is people trying to break into your app the way an attacker would, with your written permission. For a mobile app that means the app file itself, what it stores on the phone, what it sends over the network, how it deals with other apps and how hard it is to tamper with.
OWASP sorts this into eight groups in its MASVS standard: storage, cryptography, authentication and authorization, network communication, platform interaction, code quality, resilience against reverse engineering and tampering, and privacy. OWASP source Most providers on this page say their method follows it. That is a useful shared checklist, but OWASP "does not certify any vendors, verifiers or software", so "MASVS certified" on a sales page is the provider's own claim.
Two things to settle before you compare offers:
Is it a pentest or a scan? A scan is software checking for known problems. It is quick and cheap, and it misses flaws in how your app's own features can be misused. If the request says "penetration test", an automated scan alone may not meet it. See penetration testing vs vulnerability scanning.
Which build gets tested? Some providers ask for a build with protections switched off so they can see inside it. Astra, for example, asks for an app file "with SSL pinning and Root/Jailbreak Detection disabled". Astra setup guide That is a normal way to test what is underneath. But if those protections matter to your customer, ask: "Will you also test the protections in the build we actually ship, and will the report say which build each finding came from?"
If you are still deciding what kind of test you need at all, start with penetration testing services.
What will testers need from you, and how long does it take?
Plan on one to four weeks of testing once access is ready, plus the wait for a start date. The providers that publish timing say:
- Halo Security: 1 to 2 weeks for one platform, 2 to 3 for both, 3 to 4 for complex apps.
- Blaze: an average start time of "about two weeks" after scoping, and 5 to 25 person-days of effort. A person-day is one tester for one day, so it measures effort, not calendar time.
- Astra: 10 to 15 working days for the manual pentest, per its pricing FAQ. Its help documentation gives a wider 10 to 20, so ask for your schedule in writing.
- Cobalt: once you submit a fix, the tester rechecks it "within seven days".
None of these is a promised report date. If you have a deadline, ask for four dates in the proposal: when access must be ready, when testing starts, when the report arrives and the last day to request a retest.
What to have ready, based on the intake lists Halo, Cobalt and Astra publish:
- The app files: an IPA for iOS and an APK for Android
- One test account for each user role
- A staging or test backend the provider is allowed to test
- API documentation, if you have it
- Source code only if you want that deeper review
Missing test accounts and late builds are things you control, so sort them out before the start date.
What should a mobile pentest report show?
It should let your customer and your engineers see exactly what was tested, what was left out and how each finding was proven. OWASP's guidance for organizations certifying against MASVS says a report must include "the scope of the verification (particularly if a key component is out of scope)" and a summary of findings with clear indications of how to resolve them.
We read one public example, labeled here as a sample we inspected, not a test we bought. NetSPI publishes a five-page preview of a mobile report with a 2024 cover date. In its scope section it shows:
| What the preview shows | Why it helps you | What it does not prove |
|---|---|---|
| Separate tables for the Android and iOS builds, each with version and a file fingerprint (SHA256) | You can match the report to the exact build you shipped | That your quote covers both builds |
| The test accounts and their roles | You can see whose permissions were tested | That every role you have was included |
| A line that everything else was out of scope | No arguing later about what was covered | Anything about the full findings, which are not in the preview |
Ask any provider for a recent redacted mobile report and check it against these three things. Then check with the person who asked for the report. See the penetration testing report checklist. They decide whether it is acceptable. The provider doesn't, and neither do we.
Is Google Play's independent security review the same as a pentest?
No. If the request is for the "Independent Security Review" badge on Google Play, a general pentest will not get you there.
Google describes the review as "optional" and "undertaken and paid for by developers". It runs through a program called Mobile Application Security Assessment (MASA), where a Google Authorized Lab checks your Android app against OWASP's MASVS. Once the lab has verified the app, you can show the badge in your Data safety section. Google Play guidance
It is also a narrower check. The App Defense Alliance, which runs MASA, directs apps to its current MASA specification, built on MASVS, and says that "the limited nature of testing does not guarantee complete safety of the application". MASA overview NowSecure, which says its accredited scope covers MASA, states on its own page that this scope is narrower than its pen test.
So match the purchase to the request:
- A customer wants a pentest report: buy the pentest.
- You want the Play badge: contact a lab from the official list on the MASA site.
- You want both: the scopes can be quoted together, and they need not come from the same company.
Mobile scope brief to send every provider
Send every provider the same brief so their answers line up. If each one prices a different job, the cheapest quote is often just the smallest job.
Copy this, fill it in privately and send it to the providers you picked.
Mobile pentest scope brief
Why we need it and who reads the report: [customer request, audit, launch] / [who receives it and what they asked for, in their words]
Platforms: [iOS / Android / both] Framework: [native / React Native / Flutter / other / not sure]
Builds: [app name and version for each platform, shared privately]
Backend API: [which services, which environment]. Please state whether API testing is included, excluded or priced separately.
Earlier testing: [date and scope of any earlier API or mobile test, and what has changed since]. Please price only the work that is still open.
User roles: [list each role]. Sensitive flows: [payments, account recovery, exports, health data and so on]
What we can give you: [app files, test accounts, API docs, staging backend, source code yes or no]. Tell us which build you need and whether any protections must be switched off.
Report: Please confirm the report will name each build tested, the API scope, exclusions and how each finding was proven. Please send a recent redacted mobile sample.
Dates: access ready on [date]; report needed by [date]; fixes ready for retest around [date].
Retest: How many manual retests are included? What starts the clock? What is the last day we can request one? What does an extra round cost?
Price: Please itemize iOS work, Android work and shared backend work. Include any platform or subscription fee, the full commitment, the billing schedule and renewal terms.
A filled-in example (fictional): Lumen Ledger is a made-up expense app. Why: a customer's security questionnaire asks for a pentest report within 90 days. Platforms: both, React Native. API: one REST API on staging, in scope. Earlier testing: none. Roles: employee and finance admin. What we can give: IPA, APK, two accounts per role, API docs, no source code. Dates: access ready November 3, report by December 5, fixes ready about 45 days after findings. Retest: one manual round needed around day 45.
This brief is a buying aid. It does not give anyone permission to test. Before work starts, you and the provider need written authorization that names the real targets and activities. Keep passwords, keys and details of known weaknesses out of the brief, and agree with your chosen provider how to share access safely.
Mobile pentest scope brief Why we need it and who reads the report: [customer request, audit, launch] / [who receives it and what they asked for, in their words] Platforms: [iOS / Android / both] Framework: [native / React Native / Flutter / other / not sure] Builds: [app name and version for each platform, shared privately] Backend API: [which services, which environment]. Please state whether API testing is included, excluded or priced separately. Earlier testing: [date and scope of any earlier API or mobile test, and what has changed since]. Please price only the work that is still open. User roles: [list each role]. Sensitive flows: [payments, account recovery, exports, health data and so on] What we can give you: [app files, test accounts, API docs, staging backend, source code yes or no]. Tell us which build you need and whether any protections must be switched off. Report: Please confirm the report will name each build tested, the API scope, exclusions and how each finding was proven. Please send a recent redacted mobile sample. Dates: access ready on [date]; report needed by [date]; fixes ready for retest around [date]. Retest: How many manual retests are included? What starts the clock? What is the last day we can request one? What does an extra round cost? Price: Please itemize iOS work, Android work and shared backend work. Include any platform or subscription fee, the full commitment, the billing schedule and renewal terms. This brief is a buying aid. It does not give anyone permission to test. Before work starts, you and the provider need written authorization that names the real targets and activities. Keep passwords, keys and details of known weaknesses out of the brief, and agree with your chosen provider how to share access safely.
Buying more than a mobile test? Find My PenTest Match gives you a general scope checklist for web apps, APIs and other systems, plus the questions to ask whoever will read the report. It is free to copy or print and asks for no contact details. It does not list mobile providers yet, so use the tables on this page for those.
How we checked these offers
We read each provider's public pricing, mobile service, retest and setup pages on October 9, 2026, plus one public sample report preview. We quote their words where the exact wording matters, and we mark anything they do not state as "not stated" instead of guessing.
We did not buy these tests, we have not judged anyone's testing quality, and no provider has quoted for the example brief. The Purchase Check findings apply to the single condition named in each row. Our methodology explains the labels, and how we make money explains our links. Providers appear here because they rank for this search, publish terms we could compare or both. None paid to be included.
Sources and check dates
All checked October 9, 2026 unless noted.
| Source | What we used it for |
|---|---|
| Astra pricing | Plan prices, target rule, shared-codebase FAQ, rescan counts, timing |
| Astra rescan rules | Rescan window, start of the clock, 50% rule, extensions |
| Astra iOS or Android target setup | Build and account requirements |
| Astra mobile application security services | Published mobile API testing capability |
| Blaze mobile service page | Platforms, source code, API, start time, retesting "when included" |
| Blaze on AWS Marketplace | Starting price, person-days, 90-day fix validation |
| Blaze cost guide | "From $5,299", duration, Blaze's stated average range |
| Cobalt mobile methodologies | Source code, app files, backend method |
| Cobalt retest policy | Retest periods, contract cutoff, seven-day recheck |
| Cobalt pricing | Annual credit packages (checked October 7 and 8, 2026) |
| DeepStrike mobile service page | Scope, retesting statement |
| DeepStrike pricing | Basic-plan retest period; mobile applicability and clock remain unresolved |
| Halo Security mobile service page | Starting price, retest round, timing, intake list |
| NetSPI mobile service page | Scope description |
| NetSPI mobile sample report preview | Sample inspected: build tables, roles, out-of-scope line |
| NowSecure mobile service page | Real-device testing, test types, retest, MASA scope comparison |
| NowSecure terms and conditions | Definition of an App, effective August 6, 2026 |
| Software Secured pricing | Starting price, scoping basis, retest rounds |
| Software Secured mobile service | Different displayed starting figure, report-delivery retest clock, source-free testing and stated timing |
| OWASP MASVS: Assessment and Certification | Client-side boundary, no OWASP certification, report contents |
| OWASP: Using the MASVS | The eight control groups |
| Google Play: Data safety guidance | Independent security review |
| App Defense Alliance: MASA | Transition notice and stated limits |
| App Defense Alliance: current MASA specification | Current requirements replacing the legacy Level 1 description |
| NowSecure PTaaS | Optional standards validation alongside expert testing |
Offer terms change. Each figure on this page is what the provider published on the date shown, not a quote for your project.