Skip to content
Product

Security answers you can use.

We assess the mobile release build you plan to ship. A person checks possible issues, then records what the evidence supports and what to do next.

From signal to finding

A signal is only a starting point.

Automated output is a candidate, not a finding. A reviewer checks it against evidence from the submitted release build and records why it was confirmed or rejected.

Follow the assessment
Illustrative finding recordMASVS-RESILIENCE-4

Debuggable release build

A possible issue becomes useful only when the submitted release artifact confirms it.

AndroidManifest.xmlandroid:debuggable=true
Evidence
The setting appears in the submitted release manifest.
Impact
Debugging a production build can make runtime inspection easier.
Practical fix
Disable debug flags in the release variant and block them in CI.

Illustration only. Not a customer report.

01 · The record

Every result leaves a trail.

Evidence, decisions and next steps stay connected in the report.

A

Candidate

A tool can surface a possible issue. That signal stays unconfirmed until reviewed.

B

Decision

A reviewer checks the signal against the submitted build and records the reasoning.

C

Action

A confirmed finding carries evidence, impact and a practical fix. A rejected candidate keeps its reason.

02 · What this is

Assessment. With clear limits.

Vybebat assesses a named Android or iOS release build. It is not a penetration test or certification. Other work needs a separate written scope.

How the assessment differs from automated scanning and penetration testing
ScopeVybebatAutomated scanPenetration test
Human reviewEvery candidateNot inherentScope dependent
Release buildCore artifactTool dependentScope dependent
24 MASVS controlsStandard profileNot inherentScope dependent
03 · Boundaries

Before a build changes hands.

The boundaries are agreed before technical work begins.

Permission comes first

Ownership proof, a mutual NDA and written authorisation are required before testing.

The release, not source code

We request an APK, AAB or IPA and a dependency lockfile. Source code is not requested.

A defined close

Client artifacts are handled in an isolated analysis environment and deleted within 30 days of report delivery.