FAQFrequently Asked
Frequently Asked
Questions
Everything you need to know about Strata Security. Can't find the answer you're looking for? Contact us.
General
Strata Security is a mobile application security analysis platform. You upload an Android APK or iOS IPA file, and Strata Security performs deep static analysis — inspecting the manifest, permissions, binary strings, and configuration against 50+ security checks. Within seconds you receive a structured security report mapped to the OWASP Mobile Top 10.
No. Strata Security is a binary-only scanner. You upload the compiled APK or IPA exactly as it would be distributed — no source code, no build system access required. This makes it ideal for auditing third-party apps, vendor SDKs, or apps you don't own the source for.
Most APKs and IPAs are analysed in under 30 seconds. Larger binaries (150 MB+) typically complete within 90 seconds. Files are processed asynchronously, and you receive an email notification as soon as the report is ready.
Strata Security supports .apk (Android Package files) and .ipa (iOS App Store Package files). Maximum file size is 200 MB on the free plan and 500 MB on Pro and Team.
Currently, Strata Security is a static analysis platform. It does not execute the app, run it in an emulator, or perform network traffic interception. Dynamic analysis is on the roadmap for a future release. Static analysis catches the vast majority of high-severity findings without requiring a running environment.
Security & Privacy
Yes. Uploaded files are stored in a private, encrypted object store (Supabase Storage) accessible only under your account. Files are never shared, indexed, or made publicly accessible. Storage is subject to your plan's retention period — after which files are deleted. You can also delete any scan manually at any time.
On Pro and Team plans, the SHA-256 hash of your file is submitted to the VirusTotal API for malware lookup. Only the hash is shared — not the file itself. If you are auditing a proprietary unreleased app and do not want any data shared externally, you can disable the VirusTotal integration in your project settings.
Strata Security infrastructure runs in the EU (Frankfurt) by default. We use Supabase for authentication and file storage, and all data is encrypted in transit (TLS 1.3) and at rest (AES-256). Enterprise customers can request data residency guarantees — contact us for details.
Yes. Strata Security is designed with GDPR compliance in mind. We collect only the data necessary to provide the service, honour data deletion requests within 30 days, and maintain a Data Processing Agreement (DPA) available on request for Team plan customers.
Analysis & Results
The OWASP Mobile Top 10 is a widely-adopted framework that categorises the 10 most critical mobile application security risks, maintained by the Open Web Application Security Project (OWASP). It covers categories from M1 (Improper Credential Usage) to M10 (Insufficient Cryptography). Strata Security maps every finding to the relevant OWASP category automatically, giving you a compliance-ready security assessment.
Strata Security computes an overall risk score from a weighted combination of finding severity counts (Critical, High, Medium, Low), dangerous API surface area, permission risk profile, and VirusTotal results (when available). The overall score resolves to one of four levels: Critical, High, Medium, or Low.
REST API access is available on the Team plan. You can integrate Strata Security into GitHub Actions, GitLab CI, or any CI system to automatically scan release builds. The API returns structured JSON results that can be parsed to fail builds on critical findings.
Static analysis is inherently context-free — it can't know whether a permission is actually exercised by the app at runtime. As a result, some findings may be informational rather than true vulnerabilities for your specific use case. Strata Security errs toward surfacing potential issues rather than suppressing them. All findings include the specific evidence so you can make an informed triage decision.
Strata Security inspects the binary as-is — obfuscated apps are analysed the same way. Permission declarations and manifest flags are not obfuscated by ProGuard/R8, so those checks are unaffected. DEX string scanning still catches embedded literals (API keys, URLs) that survive obfuscation. Detecting logic hidden behind heavy obfuscation requires dynamic analysis, which is on the roadmap.
Billing & Plans
Yes — both Pro and Team come with a 14-day free trial. No credit card is required to start the trial. At the end of the trial period you'll be prompted to add payment details to continue, or you'll automatically revert to the free plan.
We accept all major credit and debit cards (Visa, Mastercard, Amex) via Stripe. Team plan customers can request invoice-based (net-30) billing and ACH/SEPA bank transfers.
We offer a full refund within 7 days of your first paid charge if you're not satisfied. After that, charges are non-refundable but you can cancel at any time to stop future billing.
Scan limits are per-day (rolling 24-hour window), not per-month, so unused scans don't accumulate or roll over. The daily limit resets at UTC midnight. Team plan users on unlimited scans are not subject to daily limits.
Still have questions?
Get in Touch →Ready to Start?Your First Scan is
Your First Scan is
Completely Free
No setup. No credit card. Upload your APK or IPA and get a security report in under 30 seconds.