mobile-security
Safeguard articles tagged "mobile-security" — guides, analysis, and best practices for software supply chain and application security.
53 articles
Implementing SSL/TLS certificate pinning in Node.js
HTTP Public Key Pinning died in Chrome 67 back in 2018, yet Node.js apps still need pinning for mobile backends and server-to-server calls — here's how to do it without bricking your own API.
Dart and Flutter Security Best Practices: Storage, Transport, and the pub.dev Supply Chain
A Flutter binary ships to both stores from one codebase — including any hardcoded secret, any disabled TLS check, and any vulnerable pub.dev package. Here is how to close each gap.
Android application security best practices
A practical, evidence-based guide to Android app security: data storage, network hardening, SDK risk, and CI/CD signing, with concrete CVEs and stats.
Mobile App Security Testing with OWASP MASVS in 2026
How to build a practical mobile app security testing program around OWASP MASVS 2.1, with the verification techniques that actually catch real issues.
Jailbreak Meaning: What It Is in AI and Devices
Jailbreak has two meanings today: removing restrictions on a device, and tricking an AI model into ignoring its safety rules. This guide covers both.
iOS app supply chain risk from third-party SDKs and ad li...
Third-party SDKs and ad libraries run inside your iOS app with your app's permissions. Here's how ios sdk supply chain risk hides in plain sight — and what Safeguard does about it.
react-native-confirmation-code-field: Building Secure OTP Input
This tiny React Native library gives you a clean OTP entry UI, but a secure one-time-code flow is mostly about what happens around the field, not in it.
Mobile app dependency vulnerability trends
Mobile apps now ship more third-party code than first-party. Safeguard's analysis breaks down where dependency vulnerabilities cluster and why.
Best software composition analysis tools for mobile appli...
A no-hype comparison of mobile SCA tools for scanning iOS and Android dependencies, generating SBOMs, and catching open-source vulnerabilities before release.
@twotalltotems/react-native-otp-input: A Security Guide
This popular OTP input component for React Native has not shipped an update in years. Here is a security guide to using @twotalltotems/react-native-otp-input, or moving off it.
Mobile Application Penetration Testing: A Practical Guide
How mobile application penetration testing actually works — the methodology, the tools, and what to expect from a good engagement — from someone who runs them.
React Native Cookies: Managing and Securing Session Cookies
A guide to react-native-cookies for reading and writing HTTP cookies in React Native apps, the platform gotchas, and how to keep session cookies secure.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.