Every control, by name.
Standard is assessed against OWASP MASVS v2.1, MAS-L1 testing profile. The profile covers 24 controls; it is scope, not a result for any particular app.
The assessment stays accountable.
Each control receives a recorded outcome or a clear reason it could not be tested. No silence is treated as a pass.
Storage
Sensitive information should stay protected on the device, including when the app stores it by accident.
02 controls- MASVS-STORAGE-1
Protect stored data
Check how the app stores sensitive information on the device.
- MASVS-STORAGE-2
Prevent unintended leaks
Look for data exposed through logs, backups or other storage paths.
Cryptography
Encryption helps only when the app uses sound methods and handles its keys safely.
02 controls- MASVS-CRYPTO-1
Use strong cryptography
Review the cryptographic methods the app uses to protect data.
- MASVS-CRYPTO-2
Manage keys safely
Check how cryptographic keys are created, stored and used.
Authentication
Signing in and approving sensitive actions need the right protection in the app.
03 controls- MASVS-AUTH-1
Use secure sign-in protocols
Review how the app uses authentication and authorisation protocols.
- MASVS-AUTH-2
Protect local sign-in
Check local PIN or biometric flows against platform practices.
- MASVS-AUTH-3
Recheck sensitive actions
Look at extra authentication for actions that need stronger confirmation.
Network
Connections should protect data in transit and establish which endpoint the app trusts.
02 controls- MASVS-NETWORK-1
Protect network traffic
Review secure transport and whether insecure connections can slip through.
- MASVS-NETWORK-2
Pin trusted endpoints
Check identity pinning for endpoints controlled by the app developer.
Platform
The app needs safe boundaries when it talks to the operating system, other apps and web content.
03 controls- MASVS-PLATFORM-1
Secure app-to-app access
Review inter-process communication and exposed app components.
- MASVS-PLATFORM-2
Secure WebViews
Check embedded web content and bridges into app features.
- MASVS-PLATFORM-3
Protect sensitive screens
Look for information leaking through the user interface.
Code quality
Release settings, dependencies and untrusted input can all change the app's security.
04 controls- MASVS-CODE-1
Require current platforms
Check the minimum operating-system versions the app supports.
- MASVS-CODE-2
Enforce important updates
Review how the app can require an update when a critical issue is found.
- MASVS-CODE-3
Check components
Look for known vulnerabilities in software components used by the app.
- MASVS-CODE-4
Treat input as untrusted
Review how the app validates data entering from users, files and other systems.
Resilience
These are extra defences against tampering and reverse engineering, chosen with the app's threat model in mind.
04 controls- MASVS-RESILIENCE-1
Check platform integrity
Review how the app responds to a modified device or operating system.
- MASVS-RESILIENCE-2
Detect tampering
Look at safeguards against modified app code or resources.
- MASVS-RESILIENCE-3
Resist static analysis
Review measures that make offline inspection of the app harder.
- MASVS-RESILIENCE-4
Resist runtime analysis
Review measures against debugging or manipulation while the app runs.
Privacy
The app should limit collection, explain its use of data and leave people in control.
04 controls- MASVS-PRIVACY-1
Collect only what is needed
Review access to sensitive data, device resources and third-party SDKs.
- MASVS-PRIVACY-2
Limit identification
Look at identifiers and tracking that could link activity to a person.
- MASVS-PRIVACY-3
Explain data use
Check whether collection and sharing are made clear to users.
- MASVS-PRIVACY-4
Give users control
Review ways to manage data, privacy choices and consent.
Control IDs and topics follow OWASP MASVS v2.1.0 . Explanations are plain-language summaries. The test method depends on the app and platform.
Scope is not a verdict.
This list names the Standard profile. It does not mark an app secure, and it does not describe results from a completed assessment.
- Standard covers all 24 controls.
- Other tiers have written scopes agreed before work.
- This is an assessment, not a penetration test or certification.