BasiKarah
Helping software companies identify and remediate vulnerabilities in production Android applications before they become business risks.
Four ways to work with a specialist Android security consultancy — from a single production assessment to an ongoing engineering partnership.
Black-box assessment of production Android applications: reverse engineering, runtime analysis, authentication, authorisation, local storage, WebViews, deep links, certificate pinning, obfuscation, exported components, API interaction, and business logic.
Security assessment of new Android releases before or immediately after deployment, so vulnerabilities are caught ahead of each ship cycle.
Independent validation of reported vulnerabilities and confirmation that remediation is effective.
Ongoing, monthly strategic technical advice for Android engineering teams — a fractional Android security advisor.
Assess the deployed Android application using black-box techniques.
Confirm exploitability and evaluate technical and business impact.
Provide practical recommendations developers can implement.
Retest fixes and confirm vulnerabilities have been addressed.
We serve engineering teams across the Nordics — Norway, Sweden, Finland, Iceland — and the Gulf — the UAE, Saudi Arabia, Bahrain, Oman, Qatar and Kuwait.
BasiKarah assesses the security of mobile applications before they go live, so teams can ship on a fixed timeline with a clear picture of where they stand.
The engagement is deliberately simple. You submit your final, signed APK. We run expert-led static and dynamic analysis mapped to the OWASP MASVS/MASTG standard, covering authentication and session handling, data storage, network and certificate security, and the business-logic flaws automated tools tend to miss. You receive one consolidated report: findings triaged by severity and exploitability, with clear reproduction steps and remediation guidance.
We see this as the right pre-launch step — not a replacement for a live bug bounty programme, but the assessment that comes before one.
Every engagement is priced in advance against a written scope. No hourly billing and no open-ended reward pool — you approve a number, and that is the number.
Prices are in USD and exclude VAT where applicable. Final scope and fee are confirmed after a 30-minute scoping call.
An independent, black-box evaluation of a production Android application covering reverse engineering resistance, runtime behaviour, authentication and authorisation, local storage, WebViews, deep links, certificate pinning, obfuscation, exported components, API interaction, and business logic.
BasiKarah is not a bug bounty company or a generalist penetration testing shop. We are a specialist Android application security consultancy focused exclusively on Android, staffed by engineers who analyse applications from an attacker's perspective.
FinTech, banking, digital wallets, healthcare, e-commerce, logistics, telecommunications, and SaaS companies with Android products — across the Nordics (Norway, Sweden, Finland, Iceland) and the Gulf (UAE, Saudi Arabia, Oman, Qatar, Kuwait).
An executive summary, a technical report with risk ratings, proof-of-concept evidence for each finding, practical remediation guidance, and a verification session once fixes are deployed.
Yes. Vulnerability Verification is a standalone service — we independently validate previously reported vulnerabilities and confirm whether remediation is effective.
Email us with your Android application and timeline. We respond within one business day to scope the assessment.
Tell us about your Android application and timeline. We respond within one business day. Engagements start at $2,500 for a First Look and $6,000 for a full pre-launch assessment.