Product Security Assessment

The Product Security Assessment is Strata's flagship engagement, combining everything in the Application Security Assessment with hands-on mobile reverse engineering and client-side attack surface analysis. It's built for organizations that need the deepest level of manual validation available, culminating in executive-level presentation of findings.

Starting at $15,000

Who This Is Built For

  • Mobile-first products, especially those handling credentials, payment data, or sensitive personal information
  • Organizations preparing for a major launch, enterprise deal, or fundraising milestone that depends on demonstrable security rigor
  • Products where the client-side attack surface (mobile app, embedded credentials, local storage) is a meaningful part of overall risk
  • Teams that want the most comprehensive assessment available before considering the work complete

Typical Engagement Scope

Engagements are scoped collaboratively — this describes typical coverage, not a fixed checklist applied uniformly.

Typically Included

  • Everything in the Application Security Assessment
  • Mobile reverse engineering (see the dedicated Mobile Reverse Engineering page)
  • Client-side attack surface analysis
  • Certificate pinning and SSL/TLS implementation observations

May Be Included, Depending on Scope

  • Dynamic analysis, where applicable to the platform and artifact
  • Executive presentation and technical walkthrough
  • Optional remediation validation review

Outside This Engagement

  • Infrastructure or network penetration testing
  • Social engineering or physical security testing
  • Any activity beyond the specific, explicitly authorized application artifact

Representative Deliverables

Risk prioritization
Executive presentation
Technical walkthrough
Optional remediation validation

Deliverables reflect agreed scope — not every engagement includes every item. See the full deliverables breakdown on the Services hub.

What a Report for This Engagement Looks Like

Structure only — no findings are shown here. Every real report reflects the engagement's actual scope and results.

Sample Report Structure — Demonstration Only

Executive Reporting

Executive Summary

A plain-language overview of business risk and overall posture, for stakeholders who don't need technical detail.

Business Risk Overview

What the findings mean in terms of business impact, not just technical severity.

Executive Dashboard

A single-page visual summary of risk distribution and posture, built for a quick stakeholder read.

Executive Recommendations

Strategic, prioritized next steps aimed at leadership, not implementation detail.

Findings & Risk Analysis

Technical Findings

Each finding documented in full engineering detail — what it is, where it lives, and why it matters.

Risk Prioritization

Findings ranked by severity and real-world reachability, not a raw score alone.

CVSS Summary

Standardized severity scoring applied where a CVSS score genuinely applies to the finding.

OWASP Mapping

Findings mapped to OWASP categories where a mapping is applicable.

Affected Components

The specific files, endpoints, or modules a finding touches, so engineers know exactly where to look.

Attack Paths

How a finding could realistically be chained or exploited, explained in plain engineering terms.

Evidence & Documentation

Evidence Collection

Supporting artifacts — code excerpts, request/response captures, or configuration snippets — behind each finding.

Screenshots

Visual evidence captured during manual review, referenced directly from the relevant finding.

Remediation Guidance

Developer Guidance

Implementation-level detail aimed at the engineer who will actually make the fix.

Remediation Roadmap

Findings grouped and sequenced by priority and dependency, not an unordered list.

Estimated Fix Effort

A rough sense of engineering effort per finding, to help with sprint planning.

Reverse Engineering Findings

Reverse Engineering Summary

A plain-language overview of what manual binary analysis covered and found.

Binary Analysis

Findings from static and, where applicable, dynamic analysis of the compiled application artifact.

Authentication Review

How the mobile application implements authentication and session handling, observed directly in the binary.

Local Storage Review

What the application stores on-device, and how it's protected.

Certificate Pinning Review

Whether and how the application validates the server certificates it connects to.

Sensitive Data Exposure Review

Where sensitive information could realistically be exposed client-side.

Architecture & API Observations

Architecture Observations

How the application's components and trust boundaries fit together.

API Surface Observations

Endpoints and API behavior discovered through manual analysis of the client.

Assessment Process

  1. Discovery

    An initial conversation about the application, goals, and constraints.

  2. Scope Definition

    Engagement scope, tier, and boundaries are agreed in writing before work begins.

  3. Kickoff

    Access, authorization, and points of contact are confirmed with the client.

  4. Assessment

    Manual and tool-assisted review of the authorized application, repository, or artifact.

  5. Engineering Review

    Findings are validated and prioritized by the engineer who performed the assessment.

  6. Report Preparation

    Executive and technical findings are documented with evidence and remediation guidance.

  7. Executive Briefing

    Business risk and priorities are presented to stakeholders in plain language.

  8. Developer Walkthrough

    Technical findings are reviewed directly with the engineering team.

  9. Optional Validation

    A follow-up review to confirm remediation, scoped and scheduled separately.

For the full engineering practice behind every engagement, see the Methodology page.

Common Questions

It includes everything that engagement covers plus hands-on manual mobile reverse engineering — genuinely different, more time-intensive work that automated tooling and a source-code-only review can't reach.
Not necessarily. Mobile reverse engineering works from the compiled application artifact (APK/IPA); source code can help but isn't required. See the dedicated Mobile Reverse Engineering page for detail.
No. This is manual and tool-assisted analysis of an authorized application artifact — not an attempt to exploit production systems or live infrastructure. See Rules of Engagement on the Services hub.
Final pricing depends on application complexity, platform count (Android, iOS, or both), and agreed scope — it's confirmed during scoping, before work begins, never after.

Scope Your Assessment

Every engagement starts with a conversation, not a purchase.