Built Around
Industry Standards
Every Strata finding maps to the frameworks your clients, auditors, and compliance teams already use. Six standards. Automatic. No manual tagging.
Six Frameworks. One Scan.
Click any framework to jump to its full mapping details below.
All mappings are automatic — no configuration required.
The Mobile-Specific Baseline
Every Strata scan maps applicable findings to all ten OWASP Mobile Top 10 (M1–M10) categories across Android, iOS, and repository scans — the framework the other five standards on this page build on for mobile-specific context.
Application Security Verification Standard
ASVS defines Level 1, 2, and 3 security verification requirements. Strata findings map to the specific ASVS chapters where non-compliance is detected.
Level coverage: Strata findings are relevant across all three ASVS levels. L1 findings represent the most critical baseline — every application should meet them. L2 findings apply to applications that handle sensitive data (banking, healthcare, enterprise). L3 findings apply to high-assurance applications (government, critical infrastructure, financial).
40+ CWE IDs Mapped Automatically
Every finding category in Strata maps to one or more CWE identifiers — providing a standardised vocabulary for reporting, ticketing, and compliance documentation.
| CWE ID | Weakness | OWASP | Severity |
|---|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | M1 | Critical |
| CWE-321 | Use of Hard-coded Cryptographic Key | M1, M10 | Critical |
| CWE-287 | Improper Authentication | M3 | Critical |
| CWE-295 | Improper Certificate Validation | M3, M5 | Critical |
| CWE-922 | Insecure Storage of Sensitive Information | M9 | Critical |
| CWE-312 | Cleartext Storage of Sensitive Information | M9 | High |
| CWE-327 | Use of Broken or Risky Cryptographic Algorithm | M10 | High |
| CWE-330 | Use of Insufficiently Random Values | M10 | High |
| CWE-319 | Cleartext Transmission of Sensitive Information | M5 | High |
| CWE-749 | Exposed Dangerous Method or Function | M8 | High |
| CWE-926 | Improper Export of Android Application Components | M8 | High |
| CWE-1104 | Use of Unmaintained Third-Party Components | M2 | High |
| CWE-20 | Improper Input Validation | M4 | High |
| CWE-89 | SQL Injection | M4 | High |
| CWE-359 | Exposure of Private Personal Information | M6 | Medium |
| CWE-532 | Insertion of Sensitive Information into Log File | M6 | Medium |
| CWE-693 | Protection Mechanism Failure | M7 | Medium |
| CWE-656 | Reliance on Security Through Obscurity | M7 | Medium |
This table shows the primary CWE mappings. Strata maps to 40+ CWE IDs in total — additional mappings appear in scan reports based on detected finding types.
CVSS Scoring, Calculated Automatically
Strata assigns a CVSS v3.1 Base Score to applicable findings, calculated from the standard metrics without manual input.
Scope note: CVSS Base Scores represent the intrinsic severity of a vulnerability independent of environment. Temporal and Environmental scores can be calculated by your team using the Strata Base Score as a starting point. All CVSS scores in Strata conform to the CVSS v3.1 specification published by FIRST.
14 Technique IDs Mapped to Findings
Strata maps applicable findings to MITRE ATT&CK Mobile techniques — providing adversarial context beyond vulnerability classification.
ATT&CK technique mapping contextualises findings for red team and threat modelling use cases. Strata maps to the MITRE ATT&CK Mobile (v14) matrix. Not all findings produce an ATT&CK mapping — only those with a clear adversarial technique correlation.
Secure Development Practice Alignment
The NIST Secure Software Development Framework (SSDF) defines practices for reducing software vulnerabilities throughout the SDLC. Strata output can support evidence collection toward SSDF alignment.
Mappings are provided to support analysis and reporting. They do not by themselves establish compliance.
Run Your First Scan.
First Results in 30 Seconds.
No credit card. No setup. Upload an APK, IPA, or repository URL.