VAPT Testing Required for Mobile Application (iOS & Android)
Budget: ₹12,500 – ₹37,500 INR
Let's driEV is seeking a highly skilled and certified cybersecurity professional or team to conduct comprehensive Vulnerability Assessment and Penetration Testing (VAPT) for our flagship mobile application, currently live on both iOS and Android platforms:
* iOS: [Let's driEV on App Store](https://apps.apple.com/in/app/lets-driev/id6651832845)
* Android: [Let's driEV on Play Store](https://play.google.com/store/apps/details?id=com.release.community)
Objective:
The primary goal is to identify, assess, and mitigate potential vulnerabilities that could compromise data integrity, user privacy, or system availability. The outcome should include detailed technical findings and actionable remediation recommendations, adhering to OWASP Mobile Top 10 and industry best practices.
Scope of Work:
* In-depth static and dynamic analysis of both Android and iOS applications.
* Authentication & session management testing.
* API and backend integration security validation.
* Data leakage and storage risk assessment.
* Code-level security issues (reverse engineering, code obfuscation, etc.)
* Business logic vulnerabilities.
* Rooted/Jailbroken device behavior analysis.
Deliverables:
1. VAPT Summary Report (Executive-level)
2. Technical Vulnerability Report (Developer-focused)
3. Risk Rating Matrix (High, Medium, Low)
4. Retesting and verification post-remediation
5. Final Compliance Statement/Certificate (if applicable)
**Timeline:**
Initial testing and report expected within 10–12 business days from project kick-off.
**Budget:
Open to competitive proposals; please include a cost breakdown with your quote.
* iOS: [Let's driEV on App Store](https://apps.apple.com/in/app/lets-driev/id6651832845)
* Android: [Let's driEV on Play Store](https://play.google.com/store/apps/details?id=com.release.community)
Objective:
The primary goal is to identify, assess, and mitigate potential vulnerabilities that could compromise data integrity, user privacy, or system availability. The outcome should include detailed technical findings and actionable remediation recommendations, adhering to OWASP Mobile Top 10 and industry best practices.
Scope of Work:
* In-depth static and dynamic analysis of both Android and iOS applications.
* Authentication & session management testing.
* API and backend integration security validation.
* Data leakage and storage risk assessment.
* Code-level security issues (reverse engineering, code obfuscation, etc.)
* Business logic vulnerabilities.
* Rooted/Jailbroken device behavior analysis.
Deliverables:
1. VAPT Summary Report (Executive-level)
2. Technical Vulnerability Report (Developer-focused)
3. Risk Rating Matrix (High, Medium, Low)
4. Retesting and verification post-remediation
5. Final Compliance Statement/Certificate (if applicable)
**Timeline:**
Initial testing and report expected within 10–12 business days from project kick-off.
**Budget:
Open to competitive proposals; please include a cost breakdown with your quote.
Related categories:
NoSQL Couch & Mongo
Database Administration
Elasticsearch
Google Cloud Storage
MongoDB