Designed for app development, Q-mast embeds security directly into your workflow to identify security, privacy, and compliance risks before the mobile app is released. From code to supply chain, it performs comprehensive testing to pinpoint vulnerabilities early and ensure secure app releases from the start.
Q-mast by Quokka is its automated mobile application security testing solution built for teams that need deep visibility, operational speed, and strong compliance across both in-house and/or third party mobile apps. Q-mast performs full-spectrum testing across the mobile software development lifecycle (from design to deployment) covering static, dynamic, and interactive analysis, even in obfuscated or binary-only builds. The solution generates a complete, version specific software bill of materials (SBOM), including embedded libraries, to surface vulnerable components and dependencies with pinpoint accuracy. Designed to fit into modern pipelines, Q-mast automates mobile app testing within CI/CD workflows like GitHub, GitLab, and Jenkins.
Highlights
Comprehensive static (SAST), dynamic (DAST), interactive (IAST) and forced-path execution app analysis
Automated scanning in minutes, no source code needed, even for latest OS versions
Analysis of compiled app binary, regardless of in-app or run-time obfuscations
Malicious behavior profiling, including app collusion
Checks against privacy & security standards: NIAP, NIST, MASVS
Precise SBOM generation and analysis for vulnerability reporting to specific library version, including embedded libraries
Cloud-based platform to avoid drag on hardware or bandwidth
Fewer false negatives with fewer false positives
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy Quokka Q-mast for Mobile Application Security Testing through a single contract dimension billed in units. This is a flat unit-based commitment, not a set of tiers or instance sizes. You choose the number of units you need, and pricing scales with that quantity. Each unit covers the same automated mobile app security testing capability, so there are no separate add-ons or feature levels to compare. The structure keeps billing simple: pick your unit count for the contract term and pay based on that quantity.
Top-of-mind questions for buyers
What does one Q-mast unit cover — is it per app scan, per app, or per user?
The marketplace listing bills Q-mast in units under a single contract dimension, but it does not define what one unit maps to (a scan, an app, or a user seat). Contact Quokka to confirm how units are counted for your app portfolio and scan volume.
What testing capabilities are included in each unit?
Each unit covers automated mobile app security testing for iOS and Android. This includes static, dynamic, interactive, and forced-path analysis of compiled binaries, with no source code needed. It also generates a software bill of materials and maps findings to privacy and security standards.
Do I need developer access or source code to run scans under my units?
No. Q-mast scans the compiled app binary, even when obfuscated or signed. It requires zero source code and no developer access. This lets you test third-party and vendor apps, not just your own builds, without changing how units are consumed.
www.quokka.io+1
Helpful?
Vendor refund policy
Services are not refundable
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Conviso’s AI Security Penetration Testing identifies and mitigates security risks in AI-driven applications, machine learning models, and cloud-based AI services. Our expert team combines manual testing with automated assessments to uncover vulnerabilities, adversarial threats, and data integrity risks, ensuring your AI ecosystem remains secure.
Conviso’s Mobile Application Penetration Testing identifies and mitigates security risks across iOS and Android applications. Our expert team blends manual testing with automated scanning to simulate real-world attacks, ensuring your mobile apps remain resilient against evolving cyber threats.
Achieve PCI DSS compliance with Conviso’s QSA-led audit service tailored for Cardholder Data Environments (CDE) hosted in AWS. Gain your official Attestation of Compliance (AoC) and demonstrate trust and security.
Conviso’s IoT & Hardware Penetration Testing identifies and mitigates security risks in connected devices, embedded systems, and industrial IoT environments. Our expert team blends manual testing with automated assessments to uncover vulnerabilities that could be exploited in real-world attacks, ensuring your IoT ecosystem remains secure.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.