Meet us at Black Hat 2026

See what senior security leaders across finance, healthcare, high tech and retail report, how their answers compared to AI model predictions, and the strategic recommendations you need to close the gap.

2026 Mobile App Risk Management Survey promo image
New: AI-native capabilities built for the speed and risk of AI-driven app development. New: AI-native capabilities built for the speed and risk of AI-driven app development. Learn More.
magnifying glass icon

Company News

Decoding Apple Privacy Manifests for iOS Developers

By Amy Schurr / November 15, 2023 / Comments Off on Decoding Apple Privacy Manifests for iOS Developers

Developers of iOS apps and SDKs should mark their calendars for upcoming changes to Apple privacy requirements and block out time to familiarize yourselves with them to avoid App Store rejections. Apple announced at the Worldwide Developers Conference (WWDC) 2023 in June new initiatives to increase transparency about mobile app privacy. All mobile app developers […]

NowSecure Earns ISO Accreditation for Mobile Application Security Testing Services

By Tim Neighbors / November 1, 2023 / Comments Off on NowSecure Earns ISO Accreditation for Mobile Application Security Testing Services

In a significant milestone for mobile penetration testing, NowSecure proudly announces it recently attained ISO/IEC 17025:2017 accreditation from the esteemed American Association for Laboratory Accreditation (A2LA). Specifically, NowSecure Mobile Application Security Assessment services, which test OWASP MASVS Level 1, are accredited by the A2LA under ISO/IEC 17025.  This accolade solidifies the company’s position as a […]

Q&A: Inside the OWASP Mobile Application Security Project

By Amy Schurr / February 14, 2023 / Comments Off on Q&A: Inside the OWASP Mobile Application Security Project

Mobile security standards from the Open Web Application Security Project (OWASP) help align mobile application security analysts and mobile app developers’ expectations about what needs to be remediated prior to release. Standards drive consistency, repeatability and speed. NowSecure has long embraced the value of mobile security standards built by industry experts and validated by the […]

NowSecure Debuts New OWASP MASVS Mobile Pen Tests

By NowSecure Marketing / March 22, 2022 / Comments Off on NowSecure Debuts New OWASP MASVS Mobile Pen Tests

Highly regulated and strongly-branded organizations and organizationes that embrace industry standards should ensure that their mobile apps comply with the OWASP Mobile Application Security Verification Standard (MASVS) security requirements. To support these needs, NowSecure recently expanded its expert mobile application penetration tests to offer OWASP MASVS compliance and incorporated OWASP MASVS findings into NowSecure Platform […]

It’s Not About the Bike: Vulnerabilities in Peloton’s Mobile Apps and APIs

By Tim Neighbors / December 8, 2021 / Comments Off on It’s Not About the Bike: Vulnerabilities in Peloton’s Mobile Apps and APIs

Peloton has become perhaps the most well known and successful fitness equipment company today. It makes several connected fitness products including popular Internet-connected stationary exercise bikes and publishes an impressive library of live and on-demand course content. The class platform offers an immersive experience that makes exercise fun and competitive. But this blog post isn’t […]

New NowSecure GitHub Action Helps Devs Easily Test Mobile App Security

By Tim Neighbors / November 15, 2021 / Comments Off on New NowSecure GitHub Action Helps Devs Easily Test Mobile App Security

Updated on July 6, 2022 Facing tight delivery deadlines and high expectations from the organization, mobile app development teams rely on DevOps tools and GitHub repos to ship mobile apps faster. Today’s teams want developer-first, integrated security in the software development pipeline to deliver high-quality releases on time and avoid vulnerable software dependencies to safeguard […]

Announcing the World’s First Dynamic Software Bill of Materials (SBOM) for Mobile Apps

By NowSecure Marketing / October 5, 2021 / Comments Off on Announcing the World’s First Dynamic Software Bill of Materials (SBOM) for Mobile Apps

NowSecure announces an early access program for the world’s first dynamic Software Bill of Materials (SBOM) for mobile apps with support for PDF and industry-standard OWASP CycloneDX formats.

NowSecure Completes SOC 2 Audit for Security

By Tim Neighbors / September 23, 2021 / Comments Off on NowSecure Completes SOC 2 Audit for Security

For the second year, NowSecure has completed a SOC 2 Type 2 security audit covering the NowSecure Platform for automated mobile app security testing. NowSecure remains the only enterprise-grade provider with a SOC 2 certified cloud platform for mobile application security testing (MAST).

NowSecure Workstation 7 Speeds Mobile App Pen Testing

By Amy Schurr / August 2, 2021 / Comments Off on NowSecure Workstation 7 Speeds Mobile App Pen Testing

The latest version of the NowSecure Workstation flagship mobile app pen testing toolkit improves productivity, performance and collaboration with a new modern user experience. Workstation automation closes the productivity gap to enable mobile security analysts to pen test a mobile app in a single day.

New NowSecure API Security Testing Reduces Mobile App Risk

By NowSecure Marketing / September 21, 2020 / Comments Off on New NowSecure API Security Testing Reduces Mobile App Risk

NowSecure recently added API Security Testing to its portfolio of automated mobile application security testing solutions. Based on the OWASP API Security Top 10, the new capabilities enable app development and security teams to dynamically discover API risks and vulnerabilities and address them quickly before software release. NowSecure API Security Testing taps the NowSecure advanced dynamic test engine to discover and generate a list of all mobile-connected APIs; warn of any mobile-connected APIs that may violate OWASP API Top 10 and recommend further action; and help users identify unapproved “shadow APIs” that put their organizationes at risk.