Every release of your banking app, pentested.

For banks and fintechs whose app is the main channel. Ostorlab logs in, tests the build your customers download, and follows it into the APIs that move money, on every release.

  • Gets in: login, one-time codes and multi-factor
  • Gets past: the store build, with TLS pinning and obfuscation
  • Goes through: the APIs and business logic behind accounts and payments
  • Proves: a working exploit you can replay for each AI-agent finding
Ostorlab research

Banking Report 2025: Security at the Core of Mobile Finance

We analyzed more than 500 top mobile banking apps, in the second edition of our study. The report looks at decade-old codebases, backend centralization and the security flaws that keep showing up in production apps.

  • 50%+of apps had hardcoded secrets such as API keys, tokens or credentials
  • 46%of apps use outdated libraries
  • 20%of apps still use cleartext HTTP

Figures from the Ostorlab Banking Report 2025, a study of 500+ top mobile banking apps.

Read the banking report
Attack surface

Where banking apps get attacked

Attackers go after the flows where identity and money move. Here is what Ostorlab tests in each one, on every release.

  • Login and MFA

    The risk
    Flawed login, one-time code and step-up logic opens the door to account takeover.
    What Ostorlab tests
    Logs in with your test accounts, including one-time codes by SMS, TOTP or email, and tests the authentication logic behind them.
  • Onboarding and KYC

    The risk
    Identity documents and selfies captured during onboarding can be left behind on the device.
    What Ostorlab tests
    Checks where document and selfie artifacts are written, cached or logged, and whether they are protected at rest.
  • Payments and transfers

    The risk
    The APIs behind transfers carry the business logic that moves money.
    What Ostorlab tests
    Intercepts the app's traffic, even with TLS pinning, and tests the APIs and business logic behind payments.
  • Beneficiary management

    The risk
    Adding or changing a payee is a common step before fraud.
    What Ostorlab tests
    Exercises payee flows in the running app and tests the API calls behind them for authorization and logic flaws.
  • Session handling

    The risk
    Tokens that leak into storage, logs or screenshots let an attacker reuse a customer's session.
    What Ostorlab tests
    Looks for session tokens and personal data in local storage, caches, logs and screenshots.
  • Account access

    The risk
    Hidden endpoints, client-side gates and unsafe deep links or WebViews can expose account data.
    What Ostorlab tests
    Finds bypassable client-side controls, hidden endpoints, and injection paths through WebViews and deep links.

Every finding comes with evidence your developers can act on

  • Decompiled source context
    Shows where the risk originates, including third-party components
  • File system evidence
    Shows what was written, where and when
  • Function invocation coverage
    Shows that the affected code paths were actually reached
  • Replayable exploit
    A working exploit you can replay for each AI-agent finding
Platform

Key capabilities for banks

The parts of the Ostorlab platform bank security teams ask about most. Each one has its own page with the details.

Compliance and vendor review

Evidence for your auditors and your vendor review

Ostorlab helps you test your app against the security expectations in the frameworks your auditors ask about, and gives you reports you can reuse as evidence from one release to the next.

Helps you test against and produce evidence for

  • Europe
    Operational resilience, network security, data protection and strong customer authentication
    • DORA
    • NIS2
    • GDPR
    • PSD2 SCA
  • United Kingdom
    Operational resilience for banks and payment firms
    • FCA SYSC 15A
    • PRA SS1/21
  • United States
    Security testing, customer data protection and cybersecurity programs
    • FFIEC
    • GLBA
    • NYDFS 23 NYCRR 500
  • Middle East
    Central bank cybersecurity frameworks in Saudi Arabia, the UAE, Qatar and Bahrain
    • SAMA Cyber Security Framework
    • CBUAE
    • QCB
    • CBB (Bahrain)
  • Africa
    Central bank and data protection rules in Morocco, Egypt, Nigeria, South Africa and Kenya
    • Bank Al-Maghrib
    • CBE (Egypt)
    • CBN Cybersecurity Framework
    • SARB / PA Joint Standard 2
    • POPIA
    • CBK Cybersecurity Guidance
  • Asia-Pacific
    Technology risk and information security rules in Singapore, Hong Kong, India, Japan and Australia
    • MAS TRM
    • HKMA
    • RBI
    • FISC
    • APRA CPS 234
  • Latin America
    Cybersecurity and data protection rules in Brazil
    • BCB
    • LGPD
  • Global standards
    Payment card data and mobile app security
    • PCI DSS
    • OWASP MASVS

Ostorlab's own security

Ostorlab has a SOC 2 Type II report for the Security criteria, covering 18 Nov 2024 – 18 Apr 2025 (the audit for the current period is in progress). Our controls, policies and document requests are in the Trust Center.

Visit the Trust Center

Data residency

On the Enterprise plan, choose where your data is hosted.

  • United States
  • European Union
  • GCC
  • Asia-Pacific

On-premises

Run scans from inside your network, so non-production apps and APIs never need to be exposed.

About on-premises scanning

Trusted by Security Teams Worldwide

Discover why industry experts love working with our platform

4.8 / 5
FAQ

Frequently asked questions

Straight answers on coverage, setup, and how results reach your team.

Can't find your answer? Book a demo or contact us.

See how Ostorlab would pentest your banking app

Book a demo to walk through a scan with our team and get answers to your security and vendor-review questions. Or start with a free scan of your app from the store.