MATRIX
Automated security testing and reporting for mobile apps, powered by iOS and Android virtual devices. Discover vulnerabilities in your mobile apps in minutes.
Revolutionize mobile app pentesting with MATRIX™
Corellium simplifies mobile security testing by removing the limitations of physical devices and bringing high-cost and high-risk outsourced testing services in-house. Corellium is a comprehensive mobile app security testing (MAST) platform, and is offered as a Corellium cloud solution or as onsite Corellium server and desktop appliances.
Lower Costs
Unlike other solutions and services that are priced per-test or per-app, Corellium provides a cost-efficient “all-you-can-test” pricing model.
Accelerate Testing
Alleviate up to 75% of the mundane, routine work required of pentesters for every test run. Execute hundreds of security tests in minutes.
Mitigate Risks
Outsourcing to service providers introduces risks for your mobile app IP and security policies, while Corellium empowers you to do everything in-house.
Increase Consistency
Establish baseline assessment reports to increase test coverage consistency and reproducibility, and easily identify security vulnerability regressions.
Test Continuously
Incorporate continuous security testing earlier into your CI/CD flows (shift left) to improve DevSecOps and achieve faster time-to-time market for your mobile apps.
Facilitate Compliance
Automated AppSec reporting facilitates standards adherence and compliance submissions that are otherwise cumbersome and time-consuming.
Accelerate security testing cycles
MATRIX automates a significant portion of dynamic and static testing recommended by the OWASP Mobile App Security Testing Guide for iOS and Android apps. This alleviates as much as 75% of the mundane, routine work required of pentesters, freeing up their time for more advanced security testing where their skills really shine.
Upload your app
Test for iOS and Android app vulnerabilities on virtual devices, eliminating the need for physical phones.
Identify keywords
Define a collection of sensitive strings for targeted analyses and reduction of false positives.
Run hundreds of tests
One click to begin analyzing your application for static and dynamic security issues.
Track your progress
Track the number of vulnerabilities over time and evaluate the strength of your product’s security posture.
Generate AppSec reports
MATRIX produces an easy to understand security assessment that includes pass/fail results, information about the tests, evidence identified, and recommended remediations.
Click to preview the sample report that contains over 70 authorization, code, cryptographic, network, and storage checks.
Save more than just time
MATRIX can help save countless hours and costs associated with mobile security testing.
Executive Summary
Mobile app security testing is of paramount importance, and we can significantly benefit from adopting the latest technology for improving our current software testing processes. This report presents an in-depth analysis of the estimated cost savings and efficiency gains achievable through the use of the Corellium platform and MATRIX automation technology. By automating routine security assessments and streamlining penetration testing, we estimate that we can reduce internal security testing hours by days per year, and achieve an additional per year on external testing services.
What this means for
Corellium’s analysis of teams performing similar security tests indicates that automating our internal assessments with Corellium MATRIX could save up to 90% of the effort, equating to approximately fewer days annually spent on this work. This efficiency boost is critical, as it enables our team to transition from repetitive, manual tasks to more strategic, high-value initiatives. Currently, we rely on physical devices for testing, which not only require acquisition and ongoing maintenance costs but also introduce logistical challenges due to our geographically dispersed team. Shipping devices across locations can lead to significant delays in our testing processes.
Corellium eliminates these issues by offering virtual devices with capabilities that surpass what we can achieve with physical hardware. The platform allows us to spin up virtual devices on demand, with configurations that are often impossible or impractical to replicate physically. Moreover, Corellium includes many of the necessary testing tools within its commercially supported platform—tools that are typically open-source and prone to instability. By using Corellium, we save considerable time and effort that would otherwise be spent building, maintaining, and troubleshooting our own testing environments.
By integrating Corellium into our mobile app development pipeline, we can conduct security assessments more frequently or even continuously. This aligns perfectly with our overarching objectives of boosting productivity while consistently applying robust security protocols. The time saved from eliminating manual processes and logistical delays can be redirected toward innovation and strengthening our security posture, ensuring we remain agile and effective in our security operations.
What this means for
Each quarter, we are tasked with conducting penetration tests on critical mobile app binaries— for iOS and for Android. These tests are essential, serving as the final safeguard before our apps are released to users. However, they require a significant time commitment. Currently, each penetration test takes five days to complete, meaning with four rounds of testing each year, we dedicate a total of days annually to this process—over half the working year. While the value of these tests is unquestionable, the time they consume is substantial, diverting resources from other critical security efforts like threat hunting and incident response.
Moreover, we currently rely on physical devices for testing, which require acquisition and ongoing maintenance costs. As a geographically dispersed team, we often need to ship devices between locations, causing delays in testing. This logistical burden not only increases the overall time spent but also adds complexity and inefficiencies to our testing processes.
Corellium with MATRIX offers a solution to both the time-intensive nature of penetration testing and the physical device limitations. By automating much of the baseline penetration testing, Corellium can reduce our testing time by up to 50%, saving approximately days annually. Additionally, Corellium provides virtual devices with capabilities we simply cannot achieve using physical hardware. This allows us to spin up devices on demand, with the flexibility to configure endless combinations of operating systems and device models, without the need for physical shipments or procurement delays. Corellium also integrates many required testing tools—tools that are typically open source and unstable—into a commercially supported platform, saving us the time normally spent building and maintaining our own testing environments.
This time-saving benefit is about more than just increased efficiency; it’s about enabling our team to focus on more complex, high-impact security initiatives that require human expertise. By allowing Corellium with MATRIX to handle the routine, automated portions of penetration testing, our team can dedicate more time to identifying advanced threats, exploring zero-day vulnerabilities, and proactively defending against evolving attack vectors. This strategic shift is crucial, as cybersecurity threats continue to grow in complexity, requiring deeper human oversight and innovation to stay ahead.
In the bigger picture, adopting Corellium doesn’t just cut our penetration testing time in half—it transforms our operational capabilities. Reclaiming days per year equates to gaining nearly a third of the working year back, which translates into greater agility, more focused security efforts, and the ability to push the envelope in protecting our users. According to industry research, teams that automate repetitive security tasks see up to a 40% increase in productivity, enabling them to respond more swiftly to new vulnerabilities and incidents.
In essence, Corellium with MATRIX doesn’t just accelerate our testing process; it enhances the overall effectiveness of our security team. By automating routine testing and removing the reliance on physical devices, we can focus on addressing extraordinary challenges, driving innovation, and continuously improving our security posture.
What this means for
With Corellium, the savings are immediate and substantial— annually—but the benefits extend far beyond cost reduction. Unlike traditional third-party testing services that often charge per test or per app, Corellium offers an "all-you-can-test" license, meaning we have unlimited access to its platform for any number of tests or applications. This flexibility alone can lead to massive savings over time, especially compared to external providers that charge per app for security assessment testing.
Corellium with MATRIX allows our security team to spin up virtual devices on demand, configure limitless combinations of operating systems and device models, and conduct both static and dynamic testing directly within our own environment. No more waiting on external schedules, logistics, or third-party reports. The certainty and thoroughness of our internal assessments are now fully within our control, freeing us from the limitations and bottlenecks of outsourced testing.
This is more than just cost savings—it’s a strategic transformation. By adopting Corellium, our company not only reduces expenses but also gains complete control over its security testing processes. Our team now has the tools to perform comprehensive, in-depth security assessments whenever needed, without the delays or compromises that come with third-party services. And because Corellium does not charge per app or test, we can conduct as many assessments as necessary to stay ahead of emerging threats without worrying about escalating costs.
In the end, what began as a quest to cut costs has become a key driver of our company’s security strategy. Corellium delivers both financial relief and enhanced security capabilities, giving us the flexibility to test as much as needed without incurring additional charges. It doesn't just change how we spend our budget; it transforms our approach to mobile security, empowering us to future-proof our applications and strengthen our overall security posture.
What this means for
We manage mobile app binaries— for iOS and for Android—that require rigorous penetration testing each year. Given the critical importance of securing these applications, we’ve been outsourcing this vital task to third-party vendors. Each penetration test through these external services costs us per binary, and with four rounds of testing annually, our total annual expenditure has skyrocketed to .
That’s each year solely for third-party penetration testing services to ensure our apps are secure before going to market. While these tests are crucial, the cost has become a significant burden on our budget. We’ve considered it a necessary expense due to the expertise that external vendors bring, but as the company grows, so does the need to find a more cost-effective solution—without compromising on the quality and depth of our security testing.
Enter Corellium with MATRIX. For just a year—only a fraction of what we’ve been paying for third-party services—Corellium allows us to bring penetration testing in-house. Their platform provides the tools and capabilities needed to perform comprehensive, reliable security tests ourselves, without the need for external vendors. Corellium’s "all-you-can-test" model eliminates per-binary fees, granting us unlimited testing capabilities for one flat rate.
The savings are immense. By switching to Corellium with MATRIX, we’re looking at an annual cost reduction of . However, the benefits extend beyond just financial relief. This shift grants us greater control over our security processes, allowing us to test as frequently as needed, adjust our approach on the fly, and ensure our apps are secure—all without relying on external schedules or third-party reports.
What started as an effort to cut costs has turned into a strategic shift in how we approach mobile app security. With Corellium, we’re not only saving a year—we’re gaining autonomy, flexibility, and peace of mind. This decision isn’t just about the numbers; it’s about transforming our security strategy, making our operations more efficient, and future-proofing our mobile applications.
The generation of this report was performed with the assistance of Corellium, Inc, and customized for the specific use and needs of .
© 2024 Corellium, Inc. All rights reserved.
Innovate mobile security testing
Integrate into SDLC workflows
When integrated into a CI/CD pipeline, the Corellium platform can be actioned to bring up virtual mobile devices, install and run apps, execute security testing, and output results.
FAQ
Why and how is MATRIX different?
No, the Corellium platform, whether hosted on onsite appliances or in the cloud, is a R&D platform extension for your internal teams to use. This is why pricing is "all-you-can-test" because it's yours to use as much and as often as you need. You can continue to use periodic outsourced testing services if you'd like, while Corellium is purpose-built to add continuous security testing into your SDLC.
Yes, but so much more. MATRIX automation is part of the complete Corellium security testing platform, so you get turnkey AppSec reports and have the entire platform at your fingertips. The Corellium platform includes powerful tools for advanced manual pentesting, vulnerability research, malware analysis, and team collaboration to accelerate remediation work across developer, test, and security teams.
MATRIX targets comprehensive, baseline security testing that's extremely time consuming and difficult for teams to consistently execute, and do so with adequate test coverage. This is why we say we eliminate 75% of the mundane but yet critical work, to free up your teams for more advanced and tailored security testing.
Yes, both static and dynamic, especially as our platform utilizes actual running virtual devices with live apps. And for iOS, since we natively enable jailbreaking, we simplify and run security tests better than anyone else. We've taken a fresh approach to mobile security testing, concentrating on contemporary security vulnerability techniques. As such, we've purposely steered away from adding many superfluous and irrelevant security checks that only clutter and defocus test results.
MATRIX is commonly adopted by Security Testing and AppSec Compliance teams. As they work on remediations with Developer teams, those teams often discover that virtual devices are also great for their needs, and they can even use our APIs to integrate continuous security testing into their DevSecOps processes.
At the root cause of false positives, MATRIX takes a fresh approach by leaving out numerous useless tests that other vendors include that often raise false alarms that are no longer industry-relevant. MATRIX also leverages tester-defined keyword identification to focus vulnerability analyses on the right areas. And we're working on the ability to customize severity levels for individual tests to better classify assessment results. Contact us to learn more.
We're continually adding and evolving security tests with each release. And we'll soon enable the MATRIX automation platform to allow you to add your own tests to cover more advanced and tailored use cases.