Skip to content

Security signals. Human decisions.

Most scanners guess. Vybebat checks the Android or iOS release build, confirms what matters and shows its work, assessed against OWASP MASVS v2.1, MAS-L1 testing profile.

Beta is free while it is open, in exchange for honest feedback. The quick scan needs no signup.

Works with
Release builds
.apk.aab.ipaAndroid and iOS
Standard
OWASP MASVS v2.1
Profile
MAS-L1 testing profile
Standard tier
24 controls
01 · The handoff

One release.
A clear record.

Bring the build, not your source code. We connect the release artifact to a review your team can act on.

How the handoff works

Your release build

Android release
APK / AABapp-release.apk

Build intended for release

Dependency lockfileIncluded with the build
Scope authorised

Start with the app you intend to ship.

Assessment

  • Inspect the build
  • Run on a device
  • Confirm with a human
  • Record the evidence

Agreed scope. Written permission.

Your assessment record

Assessment record

Evidence you
can act on.

Evidence
What was observed
Impact
Why it matters
Practical fix
What to change
Human confirmed

Finish with a clear next step.

Illustrative workflow. No analysis is running on this page.

02 · What you get

Less noise.
More context.

Scanner output is a candidate. A person checks the release build before anything becomes a finding, and every control leaves a record.

AndroidManifest.xmlConfirmed finding
android:debuggable=true

Debuggable release build

Evidence
The flag is present in the release artifact manifest.
Impact
Runtime inspection becomes easier on a production device.
Practical fix
Disable debug flags in the release variant and block them in CI.
Human review changes the record
Try both decisions. This is a sample, not a customer report.
A · Evidence and decision

A lead is not a verdict.

A debug flag is a lead. A person checks the release build before that lead becomes a finding, and writes down why.

  • Exact manifest line quoted
  • Impact in plain language
  • A fix you can apply
Control groupOne MASVS controlScope, not a result.
B · Every control named

Every control, named.

Standard gives all 24 OWASP MASVS v2.1 controls a verdict or a written reason, with the MAS-L1 testing profile as the baseline. A control that could not be tested gets a written reason, never a quiet pass.

  • 8 control groups, 24 controls
  • A verdict or a written reason for each
  • Other tiers agree their scope in writing
Explore coverage
assessment-record.txtillustrative
  1. MASVS-RESILIENCE-4CONFIRMEDevidence attached
  2. MASVS-STORAGE-1REJECTEDnot reproduced in release build
  3. MASVS-NETWORK-2NOT TESTEDoutside agreed scope, reason recorded
  4. MASVS-CRYPTO-1PASSreviewed on device

Rejected candidates and their reasons ship in the report.

C · The report record

A record, not a dump.

Every control in scope ends with a verdict or a written reason. Nothing is left silent, and nothing is padded to look like a pass.

  • Rejected candidates keep their reason
  • Untested controls say why
  • One retest within 60 days on Standard
03 · The process

A careful handoff.
By design.

Security review should not create a new security problem. Each stage has a purpose and a boundary.

  1. 01

    Agree the scope

    We confirm what will be reviewed, prove ownership and put permission in writing.

    You provide
    Store link, tier, ownership proof, NDA and authorisation
    You get
    A written scope and a signed boundary
  2. 02

    Review your release

    Static analysis and a device run examine the build you actually intend to ship.

    You provide
    .apk, .aab or .ipa plus a lockfile
    You get
    Isolated analysis. No source code requested
  3. 03

    Make the call

    A reviewer confirms or rejects each candidate. Scanner output alone is not a finding.

    You provide
    Nothing more
    You get
    A recorded reason for every decision
  4. 04

    Leave a useful record

    Get the evidence, the impact and a practical fix for every confirmed finding.

    You provide
    A fixed build, if a retest applies
    You get
    Report, readout and one retest on Standard

Isolated analysis. No source code requested. Artifacts deleted within 30 days of report delivery.

Understand the boundaries
04 · What this is

An assessment.
Not a penetration test.

Vybebat assesses a named Android or iOS release build. It is not a penetration test or certification.

How a Vybebat assessment compares with an automated scan and a penetration test
ScopeVybebatAutomated scanPenetration test
A person confirms every findingYesNoYes
Rejected candidates keep their reasonYesNoVaries
All 24 MASVS controls, untested ones named with a reasonYes, on StandardNoVaries
The release build is the core artifactYesTool dependentScope dependent
Backend and server testingNoTool dependentScope dependent
Tiers · per assessment, no VATStandard covers all 24 controls

Beta, Indie and Enterprise scope and retest terms are agreed in writing before work begins.

Compare tiers
05 · Before you send a build

Good questions.
Straight answers.

Know what you are requesting before you send a build.

Read all questions
Is this a penetration test?

No. Vybebat is a mobile app security assessment, not a penetration test or certification. We agree the release build and the review scope before work begins.

Do you need my source code?

No. We ask for the release artifact and a dependency lockfile. Your source code stays with you.

What do I receive?

A report for the agreed scope. Confirmed findings explain the evidence, impact and practical fix. Rejected candidates keep their reason, and untested controls are explained rather than marked as passed.

What happens to my build?

It is handled in an isolated analysis environment. Client artifacts are deleted within 30 days of report delivery.

Can I check again after a fix?

Standard includes one retest within 60 days. Retest terms for Beta, Indie and Enterprise are agreed in writing before work begins.

Separate product

Mobile release? Vybebat. Web launch? Vybentis.

Your website is a different surface with a different set of questions. Explore Vybentis for website and web app readiness checks.

Planned, not active: code vybebat is proposed for 10% off the first three months of Vybentis. It cannot be redeemed yet, and this link has no referral tracking.

Explore Vybentis (opens in a new tab)
06 · Next step

Ship with a clearer answer.

Bring the build. Get the evidence, the impact and the next step.

A person reviews every beta request. We email you when your access is unlocked.