Mobile Application Vetting
Mobile Application Vetting enables organizations to evaluate third-party mobile applications available on Google Play, the Apple App Store, and Huawei AppGallery before approving them for employee installation or enterprise deployment.
Each App Vetting report provides a unified, objective security and privacy assessment computed from automated security scans, app store metadata, and AI-assisted analysis.
Key Benefits
- Shared Public Verdicts: Vetting assessments are shared across organizations. If an application has already been analyzed, results are available immediately without re-running scans.
- Multi-Platform Support: Native support for Android, iOS, and HarmonyOS applications.
- Objective 0-100 Scoring: Standardized scoring across 5 core security, privacy, and operational dimensions.
- Privacy-Preserving: App Vetting reports summarize security posture without exposing internal organizational scan infrastructure or sensitive raw data.
Searching and Requesting an App Vetting Assessment
To view or request an App Vetting assessment:
- Navigate to Scanning > App Vetting from the left navigation menu.

-
Search for the application by typing its Application Title or Package Name / Bundle ID (e.g.,
com.example.app). -
If the application has not been vetted yet, click Request App Vetting Scan:
- Select the target platform (Android, iOS, or HarmonyOS).
- Enter the official Package Name / Bundle ID.
- Enter the Application Title and click Submit.

An automated security scan will be dispatched in the background to build the App Vetting report.
Evaluation Criteria & Scoring System
Every App Vetting assessment evaluates the target mobile application across 5 core criteria, producing a score from 0 (Severe Concern) to 100 (Clean / Best) along with a detailed rationale:
| Criterion | Evaluation Scope |
|---|---|
| Security | Evaluates technical vulnerability exposure, including insecure data storage, weak cryptography, cleartext network traffic, exported components, injection flaws, hardcoded secrets, and vulnerable dependencies. |
| Privacy | Analyzes user data handling, including tracking SDKs, excessive device permissions, collection of personal or device identifiers, and potential sensitive data leaks. |
| Safety / Maliciousness | Detects harmful or abusive behaviors, such as malware or spyware indicators, deceptive functionality, command-and-control behavior, and dangerous capability usage. |
| Adoption | Measures store adoption and community trust using download volumes and user ratings. |
| Maintainability | Assesses developer maintenance activity based on update recency and release cadence. |

Overall Weighted Score Calculation
The overall App Vetting score is computed as a weighted average across all 5 criteria:
- Safety / Maliciousness: 35%
- Security: 25%
- Privacy: 20%
- Adoption: 10%
- Maintainability: 10%
Score Ranges and Risk Bands
App Vetting uses visual color coding for both top-level report status banners and individual criterion score chips.
Overall Assessment Banners
The top status banner on an App Vetting report categorizes overall risk into 3 primary verdict bands:
| Overall Score | Banner Status | Color | Recommendation |
|---|---|---|---|
| 70 - 100 | Verified Safe to Install | Green | Approved: Low risk. Safe for enterprise deployment. |
| 50 - 69 | Install with Caution | Orange | Moderate Risk: Medium-severity findings detected. Security review advised. |
| 0 - 49 | Not Safe to Install | Red | High Risk: Critical security vulnerabilities or abusive behavior detected. Do not install. |
Criterion & Badge Scoring Ranges
Individual criteria scores and table badges map to 4 score bands:
| Score Range | UI Badge | Rating Level | Scope |
|---|---|---|---|
| 90 - 100 | Green | Excellent | Exceptional security, privacy, and maintenance posture. |
| 70 - 89 | Blue | Good | Solid overall posture with minor low-risk observations. |
| 50 - 69 | Orange | Moderate | Moderate risk areas requiring attention or configuration hardening. |
| 0 - 49 | Red | Poor / Severe | High risk or critical vulnerability findings. |
Assessment Status Lifecycle
An App Vetting assessment progresses through the following status states during its lifecycle:
- Pending: The scan request is queued for processing.
- Scanning: An automated mobile security scan is currently running.
- Scored: Analysis is complete and criterion scores are published.
- Failed: The scan or scoring process encountered an error and requires re-triggering.
Reviewing Detailed Audit Findings
Clicking on any application opens the full App Vetting Report:
- Header & Store Metadata: View store rating, age rating (e.g., PEGI 3 / 4+), country, price, and last updated date.
- Detailed Audit Panels: Expand individual criteria (Security Audit, Privacy Audit, Malware Sandbox, Trust & Adoption, Maintainability) to review specific findings, severity ratings, and AI-generated rationales.

Sharing App Vetting Reports
You can share an App Vetting assessment with external vendors, auditors, or team members:
- Open the target App Vetting report.
- Click Share Report or View Full Scan in the top action bar.
- Copy the generated secure shared link.

Shared access links allow external reviewers to inspect the security assessment safely without requiring organization membership or exposing sensitive internal infrastructure.