Hey,

Currently, I'm running a startup venture developing mobile applications. Such applications and websites are considered to be amongst the cheapest and perhaps the most effective advertising tools for any business. The electronic systems used in our company operates with all kinds of sensitive and confidential data.

The flawed data security puts all the clients at risk, and as a consequence also the future of the business. So, the data security is vital to our venture. I have decided to hire a professional firm providing IT security services Please help me find the right choice. Your suggestions will be highly appreciated!

rproffitt commented: What don't you do? Pharma, Construction and now an app company. Amazing. +0
happygeek commented: It depends on which outfit he's spamming at the time -4

Dani AI

Generated

For a startup building mobile apps that hold sensitive customer data (as described), selecting a security firm should be driven by fit and outcomes rather than brand alone. ’s note about large vendors is useful background, but the right partner for a small, fast-moving product is usually one that demonstrates mobile-specific expertise, practical remediation guidance, and a process that leaves the codebase and operations measurably safer.

Recommended approach: start with a scoped risk assessment and threat model to map data flows and priorities, then contract a combined manual penetration test (mobile client + backend/API) and targeted source-code review (if available). Require a prioritized remediation plan with concrete fix examples, a retest clause, and optional secure-SDLC coaching so fixes stick. For ongoing coverage, add dependency/secret scanning in CI, regular dependency updates, and an incident-response playbook.

Practical vetting checklist (ask every vendor):

  • Describe recent mobile projects (iOS/Android) and provide redacted sample reports or case studies.
  • Do tests include real devices, backend/API logic, and cloud storage/configuration review?
  • What manual techniques are used beyond automated scanners? Are business-logic flaws tested?
  • Will the deliverable include prioritized findings, reproduction steps, example fixes, and a retest?
  • What standards/methodologies are followed (e.g., OWASP mobile guidance) and can references be provided?
  • How is customer data handled during testing (NDAs, data deletion, safe labs)?
  • What post-engagement support, training, or retainer options are available?

Cautions: avoid firms that only run automated scans or deliver checklist reports. Prefer short pilot engagements with a clear retest clause and budget for remediation and a follow-up validation or bug-bounty program once live.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.