NEW Continuous mobile application security across every release. See the platform overview
Mobexa
Features
The platform

Continuous mobile AppSec

Every release scanned with static, dynamic and runtime analysis for Android and iOS, with signed evidence.

Analysis Static analysisSAST · source & bytecode Dynamic analysisDAST · runtime behaviour Runtime instrumentationIAST · live hooks Secret detectionbundled credentials
Supply chain Software bill of materialsSBOM · dependency risk Framework coverageOWASP MASVS / MASTG Ecosystemconnectors & webhooks
Operations IntegrationsCI / SIEM / ticketing SSO & access controlSAML 2.0 · OIDC · RBAC Flexible deploymentSaaS · VPC · air-gap
Use Cases
By team Product & Engineeringfail builds on new criticals Application Securityone unified portfolio view
  Compliance & Auditsigned evidence bundles Leadershipportfolio risk over time
Compare

Mobexa vs Competitor

How continuous, evidence-first testing differs from point-in-time scans.

View comparison
Resources Compare Pricing
Company
Company About Uswho we are Careersopen roles Contacttalk to us
Legal Terms of Use Privacy Policy Trust Center
Evaluate

See it on your own app

We scan one of your applications and hand over the evidence bundle.

Request a demo
Console login Free Trial
Mobexa
Features Use Cases Resources Ecosystem Compare Pricing About Us Contact Careers Console login
Start Free Trial See how it works

Legal

Data Processing Agreement (DPA)

Last updated: 20 April 2026 · Version 1.0

Incorporated by reference. This DPA is incorporated into the Terms of Service between us and any Customer that submits personal data through the Services. PDF versions, including the EU SCCs, are available upon request at .

1. Scope & roles

This DPA governs processing of Customer Personal Data by Seccops Siber Güvenlik Teknolojileri A.Ş. ("Seccops", "we", "us"), the company that operates the Mobexa platform, on Customer's behalf. Customer is the data controller; we are the data processor.

2. Subject-matter, duration, nature, purpose (GDPR Art. 28(3))

  • Subject-matter. Provision of the mobile application security platform described in the Order Form.
  • Duration. For the term of the subscription plus a 30-day export window.
  • Nature. Collection, storage, analysis, and reporting of mobile application binaries and associated personal data contained therein (if any).
  • Purpose. Identifying security vulnerabilities and producing audit-ready evidence for the Customer.
  • Types of personal data. Business contact data of Customer's users; any personal data incidentally present in uploaded binaries.
  • Categories of data subjects. Customer's employees, contractors, and any data subjects whose personal data appears in uploaded binaries.

3. Processor obligations

We will: (a) process personal data only on documented instructions from Customer; (b) ensure persons authorised to process the data are under obligations of confidentiality; (c) implement appropriate technical and organizational measures as set out in Schedule 1; (d) assist Customer, taking into account the nature of processing, in meeting its obligations under Articles 32-36 GDPR; (e) upon termination, delete or return all personal data unless retention is required by law; (f) make available to Customer all information necessary to demonstrate compliance, and allow for and contribute to audits.

4. Sub-processors

Customer grants us a general authorisation to engage sub-processors. We notify Customer of planned changes to the sub-processor list with at least 30 days' notice via email or a changelog page. Customer may object in writing within 15 days; if the parties cannot agree on an alternative, Customer may terminate the affected Services without penalty.

The current sub-processor list is available inside the platform and on request at .

5. International transfers

For transfers of personal data from the EEA or UK to a country outside the EEA without an adequacy decision, the parties agree the EU Commission Standard Contractual Clauses (2021/914), Module 2 (controller to processor), incorporated by reference, plus the UK International Data Transfer Addendum where applicable. Supplementary measures include encryption in transit (TLS 1.2+), encryption at rest (AES-256), and strict access-control logging.

6. Security incidents

We will notify Customer of a personal data breach without undue delay and no later than 48 hours after becoming aware. The notification will include the information required by GDPR Art. 33(3) to the extent known at the time, and will be updated as new information becomes available.

7. Data subject requests

We will assist Customer in responding to data-subject requests through appropriate technical and organizational measures, including providing tools to search, export, and delete data inside the platform.

8. Audit rights

Customer may, at its own expense and with reasonable advance notice (at least 30 days), audit our compliance with this DPA once per calendar year. Audits must be performed during business hours without disrupting the Services and must respect our confidentiality and security obligations to other customers.

9. Term & termination

This DPA applies for as long as we process personal data on Customer's behalf and survives termination of the subscription to the extent of any remaining processing.

Schedule 1 - Technical and Organisational Measures

See our Security & Trust statement for the full list of technical and organisational measures applied. That statement is incorporated by reference into this DPA.

Schedule 2 - Sub-processor list

Available on request.

Customer-executed PDF version, including EU SCCs Module 2 and UK IDTA, is available at .

Mobexa

Continuous mobile application security for every organization that ships a mobile app.

Product updates and mobile security research. No spam, unsubscribe anytime.

Product

Features Android App Security iOS App Security Use Cases Blog Glossary Standards Resources FAQ Ecosystem Careers Mobexa vs Competitor Pricing Penetration Testing Manual Pentest API Docs

Industries

Banking Fintech Insurance Healthcare Public Sector E-commerce Telecom Gaming Education Logistics

Company

About Us Contact System Status Customer console

Legal

Terms of Use Trust Center Privacy Policy Cookie Policy Data Processing Agreement Explicit Consent Acceptable Use Refund Policy Service Level Agreement

OWASP, OWASP MASVS and OWASP MASTG are marks of the OWASP Foundation. NIST, ISO, PCI-DSS, HIPAA, KVKK and GDPR are standards of their respective bodies. References describe how the platform maps to these open standards; they do not imply certification, partnership or endorsement.

© 2026 Seccops Siber Güvenlik Teknolojileri A.Ş. All rights reserved. · Essential cookies only.
20ms

Contact us

Send us a message - we reply by email.

Message sent

Thanks for reaching out. We'll get back to you by email shortly.

Spam-protected. Only your name & email are required.