Find the bug
before someone else does.
SparkSec runs hands-on, manual security testing on Android apps and APIs — the business-logic and authorization flaws automated scanners miss. Every engagement starts with written authorization.
Permission-first, always. No testing begins without your explicit written go-ahead.
What we test
Focused scope, manual technique. No blind vulnerability scans dressed up as a report.
Android App Testing
Static & dynamic analysis, SSL pinning bypass, insecure storage, root/tamper detection, and reverse-engineering of app logic on a real device.
API & Business Logic
Authorization flaws (IDOR), broken access control, parameter and price tampering, and abuse of payment or transaction flows.
Web Application Testing
Manual review of authentication, session handling, and input validation — mapped to OWASP Top 10, explained in plain language.
How an engagement runs
Four steps, in order — nothing happens out of sequence.
Scope & authorization
We agree on what's in scope, and you send written sign-off before any testing starts.
Manual testing
Hands-on testing against the agreed scope — not an automated scan with your logo on it.
Report & severity
Each finding gets a severity rating, proof of concept, business impact, and a fix.
Retest
Once you've shipped a fix, we confirm it actually closes the issue.
Manual, not automated
Every finding is verified by hand before it reaches your report.
Authorization first
Written permission is confirmed before testing begins — no exceptions.
Plain-language reports
Severity, impact, and fix steps — written for engineers and founders alike.
Have an app that needs testing?
Send scope details and we'll confirm authorization terms before anything else happens.