What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
- Current product names within the portfolio: confirm against vendor site
- Integration catalog: confirm against vendor docs
- On premises deployment options and requirements: confirm
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
NowSecure analyzes mobile binaries with static inspection plus automated dynamic testing executed on physical devices rather than emulators. The static pass covers what you would expect: manifest and entitlement review, exported component exposure, embedded libraries, cryptographic usage and hardcoded material. The dynamic pass is where the platform puts its weight. It installs the build on a real handset, exercises it, and instruments the running process, capturing what is written to device storage, what appears in logs, which certificates are accepted, and what the app sends to its backends.
The instrumentation lineage matters here. The company has long been associated with open source dynamic instrumentation work in this space, and the platform's runtime hooking reflects that depth rather than being a thin wrapper around an emulator. Alongside the automated platform there is an analyst workstation product for manual deep dives and a services arm doing human led penetration testing, which is how most customers handle what automation cannot reach. Reporting is aligned to the widely used mobile verification and testing standards, which makes the output usable as evidence rather than only as a ticket list.
Where it fits
This is a security team owned platform that gates releases and provides periodic assurance. Builds arrive from the pipeline or by upload, results route into the issue tracker, and the report goes to auditors or customers who ask. The real device angle matters when your app depends on hardware attestation, biometrics or radio behavior, because those do not reproduce in an emulator. You need a named owner for triage and an agreement about what blocks a release.
Strengths
- Automated dynamic testing on physical devices surfaces hardware dependent behavior that emulator based testing misses or misreports.
- Deep runtime instrumentation rather than surface level hooking.
- Reporting aligned to recognized mobile testing standards, useful for audit and customer questionnaires, with a path to expert manual testing within one vendor.
Limitations
- Automated exercising only reaches what it can navigate. Authenticated flows, enrollment and payments need scripting or manual testing, and the gap is not always visible in the report.
- Binary based findings point at decompiled locations, so remediation is slower than with a source level scanner.
- This is a platform adoption, with the onboarding and administration that implies. A team with one app and light requirements will find the overhead disproportionate.
Who it suits
Organizations with mobile apps in regulated contexts, or a portfolio large enough that consistent automated testing beats ad hoc assessments, especially where hardware backed features make emulator testing inadequate. Small teams with one app and strong internal skills will get further with open source instrumentation and an annual assessment.
Used NowSecure? Recommend it under your own name and title.
Recommend this tool