Compliance

OWASP MASVS

Introduction

The Mobile Application Security Verification Standard (MASVS) from OWASP is the recognised baseline for mobile app security. It covers data storage, cryptography, authentication and network communication.

Why it's needed

Mobile apps often handle sensitive user data, personal information and payments. Without a standard test framework, security audits are subjective and miss basic flaws such as insecure IPC mechanisms or weak certificate pinning.

How TrustDyne works

TrustDyne takes APK and IPA files. It analyses both statically, using MobSF and its own checks. Android apps are also run in an emulator while network traffic and system logs are captured. The report gives an OWASP MASVS pass or fail and covers areas such as data storage, network communication and resistance to reverse engineering.