INDEPENDENT ANDROID SECURITY CONSULTANCY

Android Application Security Specialists

Helping software companies identify and remediate vulnerabilities in production Android applications before they become business risks.

Request an Android Security Assessment Serving the Nordics & the Gulf
SERVICES

Assessment, review, verification, advisory.

Four ways to work with a specialist Android security consultancy — from a single production assessment to an ongoing engineering partnership.

01

Android Security Assessment

Black-box assessment of production Android applications: reverse engineering, runtime analysis, authentication, authorisation, local storage, WebViews, deep links, certificate pinning, obfuscation, exported components, API interaction, and business logic.

02

Release Security Review

Security assessment of new Android releases before or immediately after deployment, so vulnerabilities are caught ahead of each ship cycle.

03

Vulnerability Verification

Independent validation of reported vulnerabilities and confirmation that remediation is effective.

04

Security Advisory

Ongoing, monthly strategic technical advice for Android engineering teams — a fractional Android security advisor.

METHODOLOGY

Discover. Validate. Remediate. Verify.

01 — DISCOVER

Discover

Assess the deployed Android application using black-box techniques.

02 — VALIDATE

Validate

Confirm exploitability and evaluate technical and business impact.

03 — REMEDIATE

Remediate

Provide practical recommendations developers can implement.

04 — VERIFY

Verify

Retest fixes and confirm vulnerabilities have been addressed.

IDEAL CLIENTS

Built for organisations where a mobile security failure carries real consequence.

We serve engineering teams across the Nordics — Norway, Sweden, Finland, Iceland — and the Gulf — the UAE, Saudi Arabia, Bahrain, Oman, Qatar and Kuwait.

WORKING AREA
Oslo · Stockholm · Helsinki · Reykjavík · Dubai · Abu Dhabi · Riyadh · Manama · Muscat · Doha · Kuwait City
A remote-first, distributed team. Engagements run remotely across all time zones we serve; on-site work available on request.
FinTech
Banking
Digital Wallets
Healthcare
E-commerce
Logistics
Telecommunications
SaaS with Android Products
WHY BASIKARAH

Ship on a fixed timeline, with a clear picture of where you stand.

BasiKarah assesses the security of mobile applications before they go live, so teams can ship on a fixed timeline with a clear picture of where they stand.

The engagement is deliberately simple. You submit your final, signed APK. We run expert-led static and dynamic analysis mapped to the OWASP MASVS/MASTG standard, covering authentication and session handling, data storage, network and certificate security, and the business-logic flaws automated tools tend to miss. You receive one consolidated report: findings triaged by severity and exploitability, with clear reproduction steps and remediation guidance.

We see this as the right pre-launch step — not a replacement for a live bug bounty programme, but the assessment that comes before one.

Less operational load
One assessment, one report, one point of contact — no queue of duplicate submissions to triage, no scanner output for your team to verify.
Predictable cost
A fixed scope and fixed price you can budget and approve in advance, rather than an open-ended reward pool.
Confidence before release
An independent, methodology-driven assessment before your app reaches production — aligned with security testing expectations under frameworks like DORA in Europe, and SAMA and the NCA in the Gulf.
ENGAGEMENTS

Fixed scope, fixed fee, quoted before we start.

Every engagement is priced in advance against a written scope. No hourly billing and no open-ended reward pool — you approve a number, and that is the number.

First Look
A fast, low-commitment read on where you stand.
$2,500 fixed · 3–4 days
One APK, triaged across the highest-risk areas: manifest and exported components, data storage, network and certificate pinning, obfuscation posture.
Prioritised findings list and a walkthrough call. Not a full report.
If nothing material surfaces, you don't pay.
Pre-Launch Assessment MOST COMMON
The full engagement before you ship.
from $6,000 · 2 weeks
Expert-led static and dynamic analysis mapped to OWASP MASVS/MASTG, covering authentication and session handling, data storage, network security, and business-logic flaws automated tools miss.
Consolidated report with severity ratings and reproduction steps, one retest after your fixes, and an engineering walkthrough.
Full Application Review
App, backend and integrations together.
from $12,000 · 3–4 weeks
Everything in the Pre-Launch Assessment, plus backend API surface, third-party SDK and payment-integration review, and deep-link and IPC attack surface.
Includes a written summary suitable for customers, partners or auditors.
Release-Cycle Review from $2,500 per release
For teams already assessed once. Delta review against the previous baseline, sized to your release cadence.
Founding clients — 30% off
Our first three clients receive 30% off any engagement, in exchange for a reference and — if you're willing — a named testimonial.

Prices are in USD and exclude VAT where applicable. Final scope and fee are confirmed after a 30-minute scoping call.

FAQ

Common questions

What is an Android application security assessment?

An independent, black-box evaluation of a production Android application covering reverse engineering resistance, runtime behaviour, authentication and authorisation, local storage, WebViews, deep links, certificate pinning, obfuscation, exported components, API interaction, and business logic.

How is this different from a bug bounty programme or a generic penetration test?

BasiKarah is not a bug bounty company or a generalist penetration testing shop. We are a specialist Android application security consultancy focused exclusively on Android, staffed by engineers who analyse applications from an attacker's perspective.

Which industries and regions does BasiKarah work with?

FinTech, banking, digital wallets, healthcare, e-commerce, logistics, telecommunications, and SaaS companies with Android products — across the Nordics (Norway, Sweden, Finland, Iceland) and the Gulf (UAE, Saudi Arabia, Oman, Qatar, Kuwait).

What is included in an Android security assessment?

An executive summary, a technical report with risk ratings, proof-of-concept evidence for each finding, practical remediation guidance, and a verification session once fixes are deployed.

Can BasiKarah verify that a vulnerability has been fixed?

Yes. Vulnerability Verification is a standalone service — we independently validate previously reported vulnerabilities and confirm whether remediation is effective.

How do we start an engagement with BasiKarah?

Email us with your Android application and timeline. We respond within one business day to scope the assessment.

Request an Android Security Assessment

Tell us about your Android application and timeline. We respond within one business day. Engagements start at $2,500 for a First Look and $6,000 for a full pre-launch assessment.

Email hello@basikarah.com Follow on LinkedIn