Improper Credential Usage
API keys or credentials embedded in the app and usable outside it.
ANDROID & iOS / OFFENSIVE SECURITY
Find what an attacker can extract,
change and exploit.
Hands-on testing of your app, its device footprint and the APIs behind it.
Scope your mobile assessment
OWASP MOBILE TOP 10 / 2024
Recognizable weaknesses, mapped to
OWASP’s mobile risk categories.
API keys or credentials embedded in the app and usable outside it.
Vulnerable third-party SDKs or dependencies included in the build.
Bypassed login checks or APIs that expose another user’s account.
Unsafe deep-link, WebView or API input that triggers unintended behavior.
Sensitive traffic exposed by cleartext connections or weak certificate checks.
Unnecessary data collection or personal information shared with third parties.
App tampering or reverse engineering that defeats intended security controls.
Debug settings, exposed components or excessive permissions in release builds.
Personal data or session tokens exposed in files, logs, caches or backups.
Weak algorithms, predictable randomness or poorly protected encryption keys.
Reference: OWASP Mobile Top 10 — 2024 final release ↗ (opens in new tab). These are risk categories, not a claim that every app has these issues.
HOW WE TEST YOUR MOBILE APP
Inspect what ships. Challenge what runs.
Prove what an attacker can actually do.
Build + test accounts + critical journeys
Package, permissions & embedded data
Review configuration, embedded credentials and identifiable dependencies; check files, logs and backups produced during use.
Two complementary test tracks
Instrument, intercept & manipulate
Exercise sessions, deep links, WebViews and in-scope APIs. Modify requests and compare permissions across test users.
Actionable findings. Verified remediation.
OWASP MASVS / MASTG informed · Techniques and device access agreed before testing · Limitations documented
MAKE THE NEXT RELEASE A MORE INFORMED ONE
Engineer-led scoping · Mutual NDA available
SpotDefence is operated by Eioneus Systems Private Limited, Pune, Maharashtra, India (“we”, “us”). This notice explains how we handle personal information from website visitors, business contacts and prospective clients. For privacy questions, requests or grievances, email support@spotdefence.com, addressed to the Privacy and Grievance Contact.
We determine how website enquiries and business-contact information are used. Information processed during a client assessment is also subject to the signed engagement agreement and, where applicable, data-processing instructions. Where we act on a client's behalf, requests concerning that client's data may need to be directed to the client. No contract or notice removes rights or obligations imposed by applicable law.
Providing information is voluntary. Required fields help us respond and understand your enquiry; without suitable contact details we may be unable to respond. Do not submit passwords, access tokens, production credentials, personal records or confidential vulnerability evidence through the public form. Arrange an appropriate secure channel before sharing sensitive assessment material.
We use information to respond to requests, discuss scope, prepare requested proposals, manage agreed services and business relationships, operate and protect the website, address abuse, meet legal obligations and handle disputes. Information voluntarily provided for an enquiry is used for that request and related follow-up. We obtain consent where applicable law requires it and rely on other permitted grounds only where they apply.
Where European or UK data-protection law applies, relevant grounds may include steps requested before a contract with you, performance of that contract, compliance with a legal obligation, or legitimate interests in business-contact communications and website security, subject to your rights. Where consent is required, it may be withdrawn by contacting us; withdrawal does not invalidate earlier lawful processing.
An enquiry does not subscribe you to a marketing list. The website does not offer an advisory subscription. We do not use website enquiries for decisions based solely on automated processing that have legal or similarly significant effects on you.
The website uses BigRock for hosting and server-side enquiry processing, SMTP2GO for enquiry email delivery, and externally hosted Google Fonts and cdnjs resources. These providers receive information needed for their respective services. Enquiries and subsequent correspondence may also be handled through our business email and communication providers. Information is shared with personnel and providers as needed for the purposes described here, subject to applicable confidentiality and data-protection requirements.
Choosing WhatsApp opens an external service subject to its own terms and privacy practices. Our website does not automatically place your completed form fields into the WhatsApp link. Information you choose to send there is handled through that service. You may use the enquiry form or email instead.
We do not sell personal information. We may disclose information where legally required or lawfully necessary to protect rights, investigate abuse, or establish, exercise or defend legal claims. A lawful business restructuring may involve relevant records, subject to applicable protections and notice requirements.
The website's application code does not include advertising pixels or a marketing-analytics integration. External providers may process technical information or use technologies necessary for delivery, security and abuse prevention. Browser settings can restrict cookies, although some external functionality may be affected. If non-essential tracking is introduced, the notice and consent controls will be updated as required before its use.
Hosting, form processing and communications may involve processing outside India or your country of residence. Applicable transfer restrictions and safeguards govern such processing; we do not represent that all information remains in India. Contact us for information about the providers and transfer arrangements relevant to your enquiry or engagement.
These periods apply to copies under our control, including relevant provider-held submissions and correspondence. Provider default retention is not a substitute for this schedule. Deletion must account for mailbox copies and provider systems; restricted backup copies may remain until the applicable backup cycle expires. Where lawful retention is necessary, access and use are limited to that purpose. You may request earlier deletion, subject to applicable obligations and exceptions.
Reasonable technical and organisational safeguards are used as appropriate to the information and processing involved. Engagement-specific controls and secure transfer arrangements should be agreed before access is provided. No transmission or storage method can be guaranteed completely secure. Notifications of personal-data breaches are handled in accordance with applicable legal and contractual requirements.
You may contact us to request access to, correction of, or deletion of your personal information, withdraw consent, or raise a privacy grievance. Depending on applicable law and its commencement, additional rights may include completion or updating, restriction, portability, objection and nomination of another person to exercise specified rights in the event of death or incapacity. Where available, you may object to direct marketing at any time.
Email support@spotdefence.com with enough information to identify your request, without sending unnecessary sensitive documents. We may make proportionate identity or authority checks. Requests are handled within applicable statutory time limits; exceptions and permitted extensions may apply. Where lawful, we will explain material limitations or refusals. You may escalate to a competent authority or court as applicable, after following any legally required grievance process. This notice does not waive statutory remedies.
This is a business-services website and is not directed to persons under 18. If you believe a child has supplied personal information, contact us so we can assess and address it. We update this notice when our practices or legal requirements change and provide additional notice or obtain fresh consent where required. Changes do not retrospectively authorise unrelated processing.
This website is operated by Eioneus Systems Private Limited, Pune, Maharashtra, India, trading as SpotDefence. These terms govern use of the public website to the extent enforceable under applicable law. Contact support@spotdefence.com about these terms.
Service descriptions, examples, sample reports and other materials are general information, not a binding quotation, certification or assessment of your systems. Submitting an enquiry, receiving an acknowledgement or holding a scoping discussion does not create a security-testing engagement, reserve capacity or execute an NDA.
Information may become outdated or contain errors. Confirm material scope, price, timing and deliverable details in writing before relying on them for procurement or security decisions.
Paid services require an agreed written engagement covering scope, authorised targets, techniques, access, testing windows, fees, applicable taxes, payment milestones, deliverables and relevant safeguards. Retest eligibility, cancellation, refunds, rescheduling, dependencies and service commitments must be specified there. A website statement does not replace those agreed terms.
The signed engagement agreement governs that engagement and takes precedence over conflicting website descriptions. Website updates do not amend an existing signed agreement. Statutory rights and obligations remain unaffected.
You must own the proposed targets or have documented authority to authorise testing, including permissions required under applicable third-party terms or law. Possession of credentials, a domain name or an IP address is not sufficient evidence of authority. No testing is authorised merely by submitting target details.
Testing may begin only after written authorisation and agreement on scope and rules of engagement. Production safeguards, backups, permitted techniques, rate limits, stop-work triggers and escalation contacts must be agreed as appropriate. Additional systems or techniques require approval before testing. Testing may be paused where authority is unclear or agreed safety boundaries cannot be maintained.
Assessments are limited by scope, time, access, techniques and the condition of systems when tested. Manual validation improves the quality of findings but cannot guarantee that every finding is correct, every vulnerability is discovered, or a system remains secure after testing.
A report is not a guarantee of uninterrupted operation, absence of future incidents, regulatory compliance or successful certification. Remediation and retest conclusions apply only to the changes and evidence examined within the agreed scope. Customers remain responsible for their security decisions and ongoing system operation, subject to the signed agreement.
Arrange a suitable confidentiality agreement and secure channel before disclosing sensitive assessment information. A public enquiry does not itself create a mutual NDA. Do not submit credentials, secrets or personal records in the public form.
The Privacy Policy describes website personal-information handling. Confidentiality, permitted disclosures, secure access, processing roles, evidence retention and incident notification for client work are governed by the engagement documents and applicable law. Do not provide another person's information without a lawful basis or appropriate authority.
Website branding and materials are owned by Eioneus Systems Private Limited or their respective rights holders. You may view them and make reasonable internal copies to evaluate our services, retaining relevant notices. No right is granted to resell materials, misrepresent affiliation or use another party's trademarks without permission or a legal entitlement.
Ownership or licensing of reports, authorised sharing, third-party reliance and rights to underlying methods or tools are determined by the signed engagement agreement. Sample materials do not create reliance rights. Client and third-party materials retain their existing ownership.
Do not impersonate others, submit unlawful content, send spam, introduce malicious code or disrupt website access. These terms do not authorise testing against SpotDefence or any third party. Any testing permission must arise from an applicable written authorisation or the express boundaries of the responsible-disclosure policy.
External links and services have their own terms and privacy practices. Their inclusion does not guarantee availability or security. Website access may be restricted when reasonably necessary for maintenance, security, abuse prevention or compliance with law.
To the extent permitted by law, the public website is provided without warranties of uninterrupted availability, accuracy, error-free operation or suitability for a particular purpose. This does not disclaim express obligations for paid services.
Liability, exclusions, insurance requirements and any negotiated cap for an engagement must be addressed in its signed agreement. No engagement liability cap is imposed by these website terms. Nothing excludes or restricts liability, remedies or consumer protections that cannot lawfully be excluded, or excuses fraud or fraudulent misrepresentation.
These website terms are governed by the laws of India, including applicable laws in Maharashtra. Subject to mandatory statutory rights and any forum whose jurisdiction cannot lawfully be excluded, courts of competent jurisdiction in Pune, Maharashtra, have exclusive jurisdiction over disputes concerning these website terms. Engagement disputes follow the applicable signed agreement, subject to mandatory law.
Please first raise concerns at support@spotdefence.com so we can seek a resolution. This does not prevent urgent relief, interrupt statutory time limits or restrict a legally available complaint or remedy.
Updated terms will carry a revised date, with further notice where legally required. Changes do not apply retrospectively to signed engagements. If a provision is unenforceable, the remaining provisions continue to the extent permitted by law. A delay in enforcing a right does not by itself waive that right.
SpotDefence, operated by Eioneus Systems Private Limited, welcomes good-faith reports about security vulnerabilities in the SpotDefence systems listed below. This policy explains what you may test, how to report safely, and how we coordinate remediation and disclosure. It does not authorise testing of any client or third-party system.
Email support@spotdefence.com with the subject [Security Disclosure]. If the report contains sensitive information, send only a short description initially and ask us to arrange a suitable secure transfer method. Do not use the public enquiry form for vulnerability details, credentials, personal data or exploit code.
This policy covers the web applications and content served from spotdefence.com, www.spotdefence.com, and the official preview at spotdefence-zeta.vercel.app, but only to the extent that the affected component is controlled by Eioneus Systems Private Limited. Another asset is covered only when we confirm that in writing before testing.
Hosting providers, email providers, form processors, content-delivery networks, social networks and other third-party services are governed by their own disclosure programmes. A SpotDefence name, link, DNS record or embedded component does not by itself authorise testing of the provider's underlying infrastructure.
Scanner output, missing security headers, version banners, best-practice observations, clickjacking without a sensitive action, self-XSS, open redirects without demonstrated security impact, and reports about unsupported or obsolete browsers may be closed as informational unless they demonstrate a credible exploit and material impact.
These are response targets, not contractual service levels. Remediation time depends on severity, complexity, third-party dependencies, active exploitation and operational risk. Duplicate, previously known, non-reproducible or out-of-scope reports may be closed with an explanation where practicable.
Please do not publish, sell or share vulnerability details until we confirm remediation or agree a disclosure date. We will work toward a reasonable disclosure plan, commonly within 90 days, but the period may change where a fix is complex, a supplier is involved, users require time to update, active exploitation changes the risk, or law requires earlier reporting. We may notify affected parties, service providers, regulators, CERT-In or law-enforcement authorities where required or reasonably necessary.
Research that follows this policy, stays within the listed systems and is performed in good faith will be treated by us as authorised security research for our systems. We do not intend to initiate legal action solely because of an accidental, good-faith breach of this policy where the researcher promptly stops, reports it and cooperates to reduce harm. This statement cannot authorise activity against third parties, bind another organisation, excuse unlawful or reckless conduct, or prevent us from acting where there is harm, bad faith, extortion, privacy abuse or a legal obligation.
This is a disclosure programme, not a paid bug bounty. Testing costs, rewards and compensation are not promised. With your consent, we may acknowledge a helpful report after remediation. Reporter contact details and report content are used to investigate, communicate, remediate, meet legal obligations and prevent recurrence, subject to our Privacy Policy and applicable law.
SpotDefence is the cybersecurity-services brand of Eioneus Systems Private Limited, Pune, Maharashtra, India. Our work can involve source code, test credentials, technical evidence and sensitive business context. This Trust Center summarises how engagements are governed. The signed NDA, proposal, statement of work and rules of engagement define the controls for a particular client and take precedence where they set stricter requirements.
Testing begins only after the parties document the legal entity requesting the work, in-scope assets, ownership or authority to test, excluded systems, permitted techniques, testing window, rate limits, production safeguards, escalation contacts and stop conditions. The client remains responsible for obtaining authorisation from relevant asset owners, cloud providers and other third parties. An enquiry, quotation or NDA alone is not permission to test.
No assessment can eliminate all risk or guarantee that every vulnerability will be found. Deliverables describe the tested scope, timing, assumptions and limitations so results are interpreted appropriately.
Clients should provide dedicated, scoped test accounts with the minimum permissions needed and multi-factor authentication where appropriate. Credentials, tokens, private keys, production secrets and personal records must not be sent through the public enquiry form or ordinary chat. The parties agree a suitable transfer method before exchange. Temporary access should be rotated or revoked promptly after testing and retesting.
Public website enquiries are scheduled for deletion after 3 months. Final client reports are scheduled for deletion after 6 months from final delivery. Working evidence, credentials, source extracts and other artefacts follow the written engagement instructions and should be minimised throughout the work. A different period may apply where the client agrees it in writing, a dispute or legal hold requires preservation, or law requires retention. Deletion from active working locations may not immediately remove protected backup copies, which remain subject to access restrictions and ordinary backup expiry.
The public website uses BigRock for hosting and server-side enquiry processing, SMTP2GO for enquiry email delivery, and externally hosted font and interface resources as described in the Privacy Policy. An engagement may require other infrastructure or specialist providers. Material providers that may receive client confidential information, along with relevant location or transfer requirements, are identified and agreed before that information is shared. A client may state restrictions on subprocessors, jurisdictions and remote access during scoping.
Security concerns affecting SpotDefence systems can be reported under the Responsible Disclosure policy. Suspected incidents involving client material are assessed, contained and escalated through the agreed engagement contacts. We preserve relevant information, coordinate remediation and notify affected clients or authorities where required by contract or law. Applicable Indian obligations may include reporting specified cyber incidents to CERT-In within the required period and maintaining records required by lawful directions.
Engagement deliverables may include an executive summary, scope and limitations, methodology, risk-ranked findings, reproducible evidence, business impact, practical remediation guidance and a retest status. The exact deliverables and acceptance process are stated in the proposal or statement of work. Reports are point-in-time assessments of the tested scope and are not certifications, guarantees of security, or permission for third-party reliance unless expressly agreed.
Prospective clients may request a mutual NDA, methodology information, a sanitised sample report, data-handling details, provider disclosures and answers to a security questionnaire. Availability is subject to relevance, confidentiality and the signed engagement. SpotDefence does not claim a certification, audit opinion or compliance status unless it is expressly identified and supported by current written evidence.
For RFPs, NDA coordination, security questionnaires, data-handling requirements or incident escalation, contact support@spotdefence.com. Do not include credentials, exploit evidence or sensitive client information in the first email; request an appropriate secure channel.