Product Security Assessment
The Product Security Assessment is Strata's flagship engagement, combining everything in the Application Security Assessment with hands-on mobile reverse engineering and client-side attack surface analysis. It's built for organizations that need the deepest level of manual validation available, culminating in executive-level presentation of findings.
Starting at $7,500
Who This Is Built For
- Mobile-first products, especially those handling credentials, payment data, or sensitive personal information
- Organizations preparing for a major launch, enterprise deal, or fundraising milestone that depends on demonstrable security rigor
- Products where the client-side attack surface (mobile app, embedded credentials, local storage) is a meaningful part of overall risk
- Teams that want the most comprehensive assessment available before considering the work complete
Typical Engagement Scope
Engagements are scoped collaboratively — this describes typical coverage, not a fixed checklist applied uniformly.
Typically Included
- Everything in the Application Security Assessment
- Mobile reverse engineering (see the dedicated Mobile Reverse Engineering page)
- Client-side attack surface analysis
- Certificate pinning and SSL/TLS implementation observations
May Be Included, Depending on Scope
- Dynamic analysis, where applicable to the platform and artifact
- Executive presentation and technical walkthrough
- Optional remediation validation review
Outside This Engagement
- Infrastructure or network penetration testing
- Social engineering or physical security testing
- Any activity beyond the specific, explicitly authorized application artifact
Representative Deliverables
Deliverables reflect agreed scope — not every engagement includes every item. See the full deliverables breakdown on the Services hub.
Assessment Process
Discovery
An initial conversation about the application, goals, and constraints.
Scope Definition
Engagement scope, tier, and boundaries are agreed in writing before work begins.
Kickoff
Access, authorization, and points of contact are confirmed with the client.
Assessment
Manual and tool-assisted review of the authorized application, repository, or artifact.
Engineering Review
Findings are validated and prioritized by the engineer who performed the assessment.
Report Preparation
Executive and technical findings are documented with evidence and remediation guidance.
Executive Briefing
Business risk and priorities are presented to stakeholders in plain language.
Developer Walkthrough
Technical findings are reviewed directly with the engineering team.
Optional Validation
A follow-up review to confirm remediation, scoped and scheduled separately.
For the full engineering practice behind every engagement, see the Methodology page.
Common Questions
Scope Your Assessment
Every engagement starts with a conversation, not a purchase.