Engineering Methodology

How Strata Approaches a Security Assessment

This is an engineering practice, not a compliance framework — how Strata's engineers actually work through an assessment, from the first conversation to the final walkthrough. Depth and sequence adapt to each engagement's real scope.

From Discovery to Validation

  1. Discovery

    An initial conversation about the application, its goals, and any constraints that shape the engagement.

  2. Scoping

    Engagement tier, boundaries, and authorized targets are defined and agreed in writing.

  3. Environment Review

    Understanding the platforms, frameworks, and deployment model the application actually runs on.

  4. Repository Assessment

    Source code, dependency, secrets, and configuration review where repository access is in scope.

  5. Architecture Review

    How the application's components fit together, and where trust boundaries actually sit.

  6. Manual Analysis

    Hands-on review of authentication, authorization, and application logic by the engineer performing the assessment.

  7. Mobile Reverse Engineering

    Where applicable — hands-on binary analysis of the distributed mobile application artifact.

  8. Risk Prioritization

    Findings are ranked by severity and real-world reachability, not a raw score alone.

  9. Reporting

    Executive and technical findings are documented with evidence and remediation guidance.

  10. Executive Briefing

    Business risk and priorities are presented to stakeholders in plain language.

  11. Developer Walkthrough

    Technical findings are reviewed directly with the engineering team.

  12. Optional Validation

    A follow-up review to confirm remediation, scoped and scheduled separately.

This sequence illustrates how a comprehensive engagement can unfold — it is not a fixed process applied identically to every project. Methodology is adapted to each engagement's actual scope, platform, and goals; a smaller engagement skips stages that don't apply.

What an Engagement Needs From You

The methodology above works best when a few things are in place before assessment work starts. None of this is unusual — it’s the same practical groundwork any engineering engagement needs.

Repository access scoped to what's agreed for the engagement, provisioned before assessment work begins
Build artifacts (an APK, IPA, or a runnable build) where the engagement includes mobile or dynamic analysis
Written authorization confirming Strata is permitted to assess the specified software
A point of contact available for scoping questions during the engagement
Time on the calendar for the kickoff call, executive briefing, and developer walkthrough
Time to review the delivered report and ask follow-up questions
Availability for an optional follow-up validation review, if one is scoped

Common Questions

No. This lifecycle illustrates how a comprehensive engagement can unfold — the actual sequence and depth of each stage is adapted to the specific application, platform, and scope agreed during scoping. A smaller engagement skips stages that don't apply.
No. This describes an engineering practice for finding and communicating real security issues, not a compliance or certification framework. Assessments are designed to improve security posture — they don't certify compliance with any specific standard.
The engineer who scopes an engagement is the same engineer who performs it and writes the report — findings pass through no intermediate reporting layer.
Each tier on the Services page applies this same underlying methodology at a different depth and scope — see the Security Snapshot, Application Security Assessment, and Product Security Assessment pages for how it's applied at each level.

See This Methodology Applied to a Specific Engagement

Security Snapshot

The Security Snapshot is a rapid, focused review built for teams that need a credible read on their security posture without committing to a full engagement. It suits a small repository, a single service, or a specific area of concern — the goal is a fast, prioritized signal, not exhaustive coverage.

Application Security Assessment

The Application Security Assessment is Strata's primary commercial engagement — a structured, engineer-led review that goes beyond what automated scanning alone can surface. It combines source code review with authentication, authorization, dependency, secrets, and configuration analysis, reported with clear risk prioritization and a remediation roadmap.

Product Security Assessment

The Product Security Assessment is Strata's flagship engagement, combining everything in the Application Security Assessment with hands-on mobile reverse engineering and client-side attack surface analysis. It's built for organizations that need the deepest level of manual validation available, culminating in executive-level presentation of findings.

Mobile Reverse Engineering

Mobile reverse engineering is hands-on, engineer-performed analysis of a compiled mobile application — assessing what sensitive information, credentials, authentication artifacts, application logic, or client-side functionality could realistically be extracted or abused from the distributed application. It is manual and tool-assisted work, distinct from and complementary to automated static analysis.

Rules of engagement and full deliverables live on the Services hub.

Discuss Your Assessment

Every engagement starts with a conversation about your application, not a purchase.