Skip to content
Digital Security Consulting

Services

Mobile App Development

iOS, Android and cross-platform apps — with AI on device and the security done properly.

What you get

  • Native iOS and Android applications
  • Cross-platform builds where it genuinely saves time and money
  • AI features on mobile — assistants, capture, transcription, on-device inference
  • App Store and Google Play submission, review handling and release management
  • Mobile device setup, enrolment and management for your team
  • Mobile application security review and hardening

Outcomes

  • An app that ships, passes review, and can be updated without drama
  • Credentials and customer data handled to a standard that survives scrutiny
  • Company devices enrolled, encrypted and remotely wipeable
  • A codebase your next developer can pick up

Capabilities

iOS and Android development

Native Swift and Kotlin where the platform matters, and cross-platform where it does not. We will tell you honestly which one your project is.

AI features on mobile

In-app assistants, photo and document capture that extracts structured data, voice transcription, and on-device inference when data must not leave the handset.

Field and trades apps

The practical ones. Job capture, photo-driven quoting, scheduling, signatures and offline-first sync for crews working where signal is not guaranteed.

Mobile device setup and management

Enrolment, configuration profiles, app distribution, encryption enforcement and remote wipe for phones and tablets across your team.

Mobile app security

Certificate pinning, secure credential storage, API hardening, jailbreak and tamper awareness, and a review of what your app actually leaks.

Release and store management

Build pipelines, signing, TestFlight and internal tracks, staged rollouts, crash reporting, and getting through review without a two-week surprise.

Apps built by people who also do the security

Mobile is where the security assumptions get quietly dropped. API keys compiled into the binary, tokens in plain preferences, an unauthenticated backend endpoint because “only the app calls it,” certificates unpinned.

None of that is exotic, and all of it is routinely found in shipped apps. We build mobile the same way we build everything else — assuming someone will pull the binary apart, because someone will.

What we actually build

Field and trades apps. The unglamorous, genuinely useful category. Capture a job on site, photograph the work, generate the quote, collect the signature, sync when signal returns. Offline-first, because a crew in a basement has no bars.

Customer-facing apps. Accounts, content, payments, notifications. Built to pass review and to be maintainable afterwards.

Internal tools. Sometimes the right answer is not a public app at all but something distributed internally to your own devices, which sidesteps store review entirely.

AI on mobile

Two distinct approaches, and the choice matters:

Cloud models are far more capable. Data leaves the device, so this needs the data-handling conversation we cover in AI and automation before anything is connected.

On-device models are smaller and slower, but the data never leaves the handset. For transcription of sensitive conversations, document classification, or anything where a privacy question would stall the project, this frequently wins on the merits and not just on compliance.

Most real apps use both, routed by sensitivity. We design that routing deliberately rather than sending everything to whichever API is easiest.

Device setup and management

Separate from building apps: getting your team’s phones and tablets into a managed state. Enrolment, configuration, app distribution, enforced encryption, and remote wipe when a device is lost.

This is unfashionable work with a very high return. A lost unmanaged phone with a saved email session is a breach. A lost managed one is an inconvenience.

Frequently asked questions

Native or cross-platform — which should we build?

It depends on what the app does. Heavy camera, sensor, background or performance work favours native. Forms, data entry, dashboards and content are well served cross-platform, at roughly one codebase instead of two. We assess your actual feature list rather than defaulting to whichever we prefer.

How much does an app cost to build?

The honest answer is that it depends on scope, and anyone quoting before understanding the feature set is guessing. What we can do quickly is scope it into phases so you see a working, useful version early rather than paying for twelve months before anything ships.

Can AI run on the device instead of in the cloud?

For many tasks, yes. Modern phones run capable models locally, which means the data never leaves the handset. That is slower and more limited than a frontier model, but for transcription, classification and extraction of sensitive material it is often the right trade, and it removes an entire category of privacy question.

We already have an app but lost the developer. Can you take it over?

Yes, and it is a common request. We audit what exists — code, signing certificates, store accounts, dependencies, backend — and give you a written assessment of what you actually control before quoting any work. Losing access to a signing certificate or store account is a bigger problem than the code, and it is worth establishing that first.

Do you handle App Store and Google Play submission?

Yes, including the review process. Rejections are normal and usually procedural; we handle the back-and-forth and build the release pipeline so subsequent updates are routine.

AI & Automation

AI wired into the work you already do, with the security questions answered first.

Learn more

Software Engineering

Architecture, subscription platforms and data pipelines — built to be maintained.

Learn more

Cybersecurity

Incident response, ransomware recovery, and hardening that holds up under audit.

Learn more

Tell us what is breaking — or what you are trying to build.

You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.

Active incident? Write “URGENT” in your message and we prioritise it.