MagnoSec
MagnoSec Product · Mobile apps

Mobile applications for iOS and Android

One codebase, two stores, backend included. And one difference: the app reaches production after we have tried to break it ourselves.

What mobile app development includes

A mobile app is not a small website. It has a backend, stores, permissions and data on the device. The six phases below cover all of it.

Scope and architecture

Which screens, which roles, which data, and what has to happen for the app to serve the business. We define this before designing anything.

Mobile UX/UI

Flow and screen design built for a thumb and a phone, not for a desktop. A pretty app with a bad flow gets uninstalled in the first session.

iOS and Android app

One codebase with React Native or Flutter, compiled and published to both stores. Or native development if the project demands it.

Backend, API and database

Authentication, session management, business logic, API and admin panel. The part that turns a demo into a product.

Store publication

Developer accounts, App Store and Google Play listings, screenshots, privacy policy, data safety form and rejection responses.

Mobile security review

Token storage, encryption in transit, certificate pinning, obfuscation, permissions and server-side authorisation validation.

When an app makes sense

We will be honest: many app ideas are better solved with a well-built website, and charging €20,000 for something a €5,000 website covers serves nobody. An app makes sense when the user comes back often, when they need offline access, camera, geolocation or notifications, or when usage has to stay in the customer's pocket.

  • Companies that need to digitise a process currently run on paper, spreadsheets or WhatsApp.
  • Service businesses with recurring customers that want bookings, orders or tracking inside an app.
  • Startups that need a first working app to validate the model before investing in an in-house team.
  • Companies with an old app written by a vendor that no longer responds, that needs rescuing and updating.

If you already have an app in production and what you want is to know whether it is secure, that is not development: that is mobile application penetration testing. And if your project is a website or a portal rather than an app, that is under custom web development.

Frequently asked questions about app development

How much does it cost to develop a mobile app?
A mobile app with its own backend starts at €8,000 for a reduced scope: authentication, a few screens, notifications and a simple API. An app with in-app payments, chat, geolocation, corporate system integrations and an admin panel runs between €20,000 and €60,000. The cost is driven by the backend and the integrations, not by the screens: drawing twenty screens is cheap, supporting the logic behind them is not.
Do you build native or cross-platform apps?
Cross-platform by default, with React Native or Flutter, because it gives a single codebase for iOS and Android and halves the maintenance cost. Native development is used when the app depends on something the cross-platform layer does not cover well: deep hardware access, Bluetooth Low Energy, augmented reality, device-level encryption or graphics-heavy performance. In that case we say so before signing, not halfway through the project.
Do you publish the app on the App Store and Google Play?
Yes, publication is included. We handle the developer accounts, the store listing, the copy, the screenshots, the privacy policy and Apple's data safety form, which is where most projects get stuck. We also handle review rejections: a first app submission usually draws objections about privacy or declared permissions, and knowing how to answer them saves weeks.
What about the backend and the database?
An app without a backend is a demo. We build the API, the database, authentication, session management and the admin panel the business needs to operate. That is the invisible part of the quote and the one that decides whether the app is actually useful in production. We deploy on AWS, Azure or Google Cloud, with backups and monitoring.
Do you review the security of the mobile application?
Yes, and it is the reason clients who have already been burned hire us. We review token storage, traffic between app and server, whether the certificate is pinned, whether the code obfuscates embedded credentials, whether the API validates each user's permissions or just the token, and whether sensitive data is left on the device. An app that stores the session token in plain text in local storage can be compromised by anyone with physical access to the phone.
How long does app development take?
Between 8 and 20 weeks for a realistic scope. A first working version of a simple app with a backend can be ready in 8 weeks. Adding payments, corporate system integrations or a complex admin module takes the project to 4 or 5 months. We work in deliverable phases so you can see and test the app working from the first month, not at the end.

Got an app idea in mind?

Tell us about it in a 15-minute call. We will tell you whether it makes sense as an app or as a website, what scope is realistic and what it would cost. No obligation.

Want more info?