Skip to content

Service

A mobile app, its backend, and a review of both before the store sees it

Nearly every mobile app is a thin client in front of an API, and nearly every serious security problem in one is in the API rather than the app. So we build both, and we review both — because an endpoint that trusts the app is an endpoint anybody can call with a script, and the app cannot keep a secret no matter how it is compiled.

Tell us about your app

A person reads it and replies, usually within two working days.

What it costs

Fixed price per phase after scoping, the same way as web work. Store accounts and their annual fees are yours directly rather than billed through us, because an app that lives in somebody else's developer account is an app you do not really control.

Who it suits

Three situations this is for

  • Your product needs to be on a phone

    Push notifications, a camera, offline use, or simply being an icon on a home screen. If a website would do, we will tell you — it is cheaper and it ships sooner.

  • You have an app and no confidence in its API

    A review of the endpoints behind an existing app, with the app itself checked for the things that should never have been shipped inside it: keys, tokens, and trust placed in the client.

  • You are about to submit to a store

    Reviewing before submission is much cheaper than after. A rejection costs a week; a permission or data-handling disclosure that turns out to be wrong costs a release cycle.

How it goes

The engagement, step by step

Written out because the thing people actually want to know before sending an enquiry is what happens next, and how easy it is to stop.
  1. Scoping, including whether you need an app at all

    The honest answer is sometimes a responsive website, and it is a much smaller project. We will say so — a native app you did not need is an app you will resent maintaining.

  2. A written scope with a fixed price per phase

    Usually: the API and one platform first, then the second platform, then submission. You can stop after any of them and still have something that works.

  3. You get builds on your own device early

    TestFlight and an internal Android track from the first phase. Reviewing an app on a phone is not the same as reviewing screenshots, and it changes what you ask for.

  4. Review, submission, and the keys handed over

    The review runs before submission rather than after. Signing keys and store accounts are yours throughout — we work inside your accounts, so there is nothing for you to reclaim at the end.

    A developer who holds your signing key holds your ability to ship.

What you end up with

  • An application for iOS and Android from one codebase, in your developer accounts
  • The API behind it, with authentication, authorization and rate limiting on every endpoint
  • A review of both: the endpoints as an attacker would call them, and the app for anything sensitive that ended up compiled into it
  • Store submission handled, including the data-handling disclosures, which take longer to get right than people expect
  • Handover notes covering the release process, the signing keys and where each secret lives

Boundaries

What this does not include

Better to find the edge here than after an invoice.
  • No games, and no augmented or virtual reality. Both are real disciplines and we do not practise them.
  • We do not promise a store will approve a submission. We can make rejection unlikely and handle the resubmission; we cannot make a decision on Apple's behalf.
  • We do not maintain an app we did not build without reviewing it first, and that review is a separate piece of work.
  • Passing a review before submission is not a guarantee about the app's security. It is a statement about the checks we ran.

Questions

About custom app development

Native or cross-platform?

React Native, unless something in your requirements genuinely needs otherwise — sustained background processing and heavy real-time media are the usual reasons. One codebase across both platforms is normally the difference between shipping and choosing which half of your users to disappoint.

Who owns the App Store listing?

You do. We work inside your Apple and Google accounts from the start. Transferring a listing later is possible and unpleasant, so we skip it.

Can you review an app somebody else built?

Yes, and it is a good place to start. It is scoped as a review rather than as development, and it usually tells you whether the app needs work or the API does.

Send an enquiry

Tell us about your app

Enough detail that we can give you a real answer rather than ask for a call to find out what you meant.
No obligation, no automatic charge

Sending this does not commit you to anything and does not start any billing. You will get a confirmation with a reference straight away, and a reply from a person after that.

Incluye el prefijo del país, por ejemplo +34.

Opcional.

Opcional. Nos ayuda a revisar tu infraestructura previa.

Qué tienes, qué necesitas y los plazos previstos. Unas pocas frases son suficientes.

Opcional.

Un especialista lee cada solicitud. Recibirás una confirmación con número de referencia de inmediato y una respuesta técnica personalizada. No hay cargo automático.