FAQ
Frequently asked questions.
Straight answers about what the platform tests, how it handles your data, how it deploys and integrates, and how to get started - written for the security and engineering teams who evaluate it.
Platform basics
What is Mobexa?
Mobexa is a mobile application security platform. It continuously tests the Android and iOS applications an organisation builds or ships, combining static, dynamic and runtime analysis with reporting, evidence export and integrations into the tools engineering and security teams already use.
What kinds of problems does it find?
It surfaces issues such as hardcoded credentials and secrets, insecure data storage, weak or missing transport protection, exposed components, risky permissions, vulnerable bundled dependencies and gaps against recognised mobile security baselines - each reported with the evidence needed to reproduce and fix it.
Who is the platform for?
Engineering, application-security and compliance teams in organisations that publish mobile apps - from a single flagship app to large portfolios - including regulated sectors that need repeatable evidence for audits.
Coverage and methodology
What is the difference between static, dynamic and runtime analysis?
Static analysis inspects the application package without running it. Dynamic analysis observes the app while it executes, including how it stores data and talks to the network. Runtime analysis examines behaviour and protections in a live environment. Using all three reduces the blind spots that any single method leaves.
Which standards and frameworks does the platform map to?
Findings are mapped to widely used open baselines for mobile security and secure development, so results can be read against criteria that auditors and security teams already recognise rather than a proprietary score alone.
Do you support both Android and iOS?
Yes. The platform analyses both Android and iOS application packages.
How often should an app be scanned?
Most teams scan on every build and on a schedule. Because new weaknesses are disclosed against components you have already shipped, continuous re-evaluation catches issues that appear after release even when your own code has not changed.
Data handling and privacy
What does the platform need access to?
It needs the application package to analyse and, for dynamic testing, an environment to run it in. It does not require your source code to perform its core analysis.
How is uploaded data stored and protected?
Applications and results are isolated per tenant, access is controlled, and artefacts are retained or deleted according to your configured policy. Customer environments can be separated further for organisations with stricter requirements.
Can our data be deleted on request?
Yes. Retention is configurable, and applications and their results can be removed in line with your data-retention policy.
Can we keep data in a specific location or run it ourselves?
Yes. Alongside the hosted service, the platform can be deployed in a dedicated or on-premise configuration for organisations with data-residency or isolation requirements.
Deployment and integration
Can the platform run on-premise or in our own cloud?
Yes. It is available as a hosted service and as a self-managed deployment for teams that require it.
Does it integrate with CI/CD and ticketing?
Yes. Scans can be triggered from build pipelines, and findings can flow into issue trackers, messaging, SIEM and log destinations.
Can we automate everything through an API?
Yes. A REST API and webhooks let teams submit scans, pull findings and reports, and react to scan lifecycle events without using the web console.
Reporting and evidence
What do the reports contain?
Reports include an executive summary, a prioritised list of findings with severity, the evidence to reproduce each issue, remediation guidance and a mapping to recognised frameworks. Technical exports are available in machine-readable formats for pipelines and other tools.
How are findings prioritised?
Findings are classified by severity and risk so teams can address the most serious issues first, with the context needed to decide what to fix, defer or accept.
Can reports be used for audits or customer security reviews?
Yes. The evidence and framework mapping are designed to support internal audits and external security reviews. They describe how an application maps to open standards and do not, by themselves, constitute a certification.
Getting started
How do we get started?
The fastest path is a walkthrough on one of your own applications. We scan an app you nominate and share the evidence so you can evaluate the platform on real output rather than a demo tenant.
How is the platform priced?
Pricing is offered as transparent yearly tiers, with a custom enterprise option for dedicated or on-premise deployment.
Maintained by the Mobexa research team. Still have a question our answers do not cover? Talk to us and we will point you to the right person or document.