Quokka Q-mast is a mobile app security testing product from Quokka, formerly Kryptowire. It scans compiled iOS and Android binaries for security, privacy, and compliance issues without needing source code.
Kryptowire was founded in 2011 and announced its rebrand to Quokka on September 12, 2022. It is the same company under a new name, not an acquisition.

This screenshot from the Jenkins plugin docs dates from 2018, the Kryptowire era. It shows an app’s threat score and NIAP requirements grouped into fail, review, and pass.
Current Q-mast reports still map findings to NIAP, though the interface has likely changed since then.
Quokka says it has worked with the US federal government since 2011. Its site shows logos from DHS, CISA, Orange, Trane Technologies, and UC Berkeley.
What is Quokka?
Quokka sells three products. Q-mast tests the mobile apps you build, Q-scout vets the apps your employees install, and Q-firm tests the firmware and pre-installed apps on Android devices.
This page focuses on Q-mast, the product that belongs in the MAST category. The other two get a short section further down.
| Fact | Details |
|---|---|
| Company | Quokka, Inc. (formerly Kryptowire, Inc.), with offices in San Jose, CA and Arlington, VA |
| Founded | 2011, after DARPA and NIST research grants in 2010 |
| Rebrand | Kryptowire to Quokka, announced September 12, 2022 |
| Funding | Growth investment led by US Venture Partners with Crosslink Capital, announced February 2022 |
| Leadership | Baris Karadogan (CEO, appointed 2026); Angelos Stavrou (founder, Chief Science Officer); Nikos Kiourtis (CTO) |
| Products | Q-mast (MAST), Q-scout (mobile app vetting), Q-firm (Android firmware analysis) |
| Certifications | SOC 2 compliant; member of the Microsoft Intelligent Security Association (2026) |
| Reach | 75+ customer countries, according to the Q-mast solution brief |
Quokka leans on original research more than most MAST vendors I have reviewed. It reports 230+ mobile CVEs, 1,000+ zero-day device vulnerabilities, 11 academic papers, and 350+ academic citations, all vendor-reported figures.
Kryptowire also took part in NIST Special Publications 1800-21 and 1800-22. It contributed to “Automating NIAP Requirements Testing for Mobile Apps”, which explains why NIAP mapping is so central to the product.
What are Q-mast’s key features?
| Feature | Details |
|---|---|
| Input | Compiled iOS and Android binaries; no source code required |
| Obfuscation | Analyzes obfuscated, protected, and signed iOS builds |
| Analysis types | SAST, DAST, IAST, and forced-path execution (FPE) |
| Test devices | DAST on non-rooted, non-jailbroken devices; app simulation on purpose-built emulators |
| Scan time | Under 60 minutes (vendor figure) |
| Accuracy claim | Under 1% false results (vendor figure) |
| Supply chain | Version-precise SBOM, SDK behavior analysis, nested dependencies |
| Standards | NIAP, NIST, and OWASP MASVS checks; reports aligned to MASVS, NIAP, and GDPR |
| Vulnerability data and output | Known CVE identification; SARIF results format |
| Post-release | App Watch List monitors production builds straight from app stores, with no device agents |
| Integrations | GitHub, GitLab, Jenkins, Azure DevOps, Appium, Snyk |
Four analysis types
Q-mast runs four analysis types against the same binary. Quokka describes each one this way on the Q-mast product page.
| Analysis | What Quokka says it does |
|---|---|
| Static (SAST) | Detects insecure patterns, hardcoded secrets, weak crypto, and misconfigurations |
| Dynamic (DAST) | Observes real app behavior on non-rooted, non-jailbroken devices |
| Interactive (IAST) | Links runtime execution paths to specific flows and behaviors |
| Forced-path execution (FPE) | Exercises scripted, repeatable flows, including rare edge cases |
Forced-path execution is the one I rarely see on other MAST product pages. Quokka defines it as forcing every conditional branch to run, including code that normal use never reaches.
That targets logic bombs, hidden triggers, and obfuscated malware. A crawler-style DAST pass usually misses those because nobody taps the right sequence of buttons.
Binary-first testing
Because Q-mast reads the compiled app, the same scan works on code you wrote and on vendor or third-party apps you only have as an APK or IPA.
Quokka says it supports recent iOS and Android versions and signed, protected builds. Teams that ship apps with RASP or obfuscation turned on can test the actual release artifact.
SBOM and SDK behavior
Q-mast builds an SBOM tied to exact library versions, including embedded libraries. Quokka’s pitch is that it goes past CVE lookup and watches what each SDK actually does at runtime.
The product page says Q-mast flags hidden AI libraries, outbound data flows, and SDKs sending user or corporate data offshore. That puts privacy findings in the same report as vulnerabilities.
Kryptowire took part in a DHS and NIAP pilot. The pilot used Kryptowire’s vetting infrastructure to automate testing against NIAP requirements for mobile apps.
Q-mast reports map findings to NIAP alongside OWASP MASVS, which matters if you sell apps to US federal agencies.
Indicators of risk
The GitLab integration page lists the indicators of risk (IoRs) that the CI job reports back. They give a concrete picture of what Q-mast flags.
- Network:
HTTP_TRAFFIC,ACCEPTS_ALL_CERTS,TRANSPORT_SECURITY_DISABLED,HIGHRISK_COUNTRY_CONNECTION - Secrets:
USES_HARD_CODED_CREDENTIALS,HARD_CODED_KEY,PASSWORD_EXPOSED - Privacy:
PII_LEAKAGE - Build hygiene:
DEBUGGABLE,MISSING_COMPILE_PROTECTION - Malicious behavior:
MALWARE_DETECTED,PRIVILEGE_ESCALATION,INDIRECT_FACTORY_RESET - Dependencies:
CONTAINS_LIBRARY_CVE
What the research data shows
Quokka analyzed 150,000+ apps during 2025 for its State of Mobile App Security 2026 report. The findings are Quokka’s own data, but they show the kind of issues Q-mast is tuned for.
Plain HTTP URLs turned up in 94.3% of Android apps and 61.7% of iOS apps. ECB-mode ciphers appeared in 68.1% of Android apps and 24% of iOS apps.
Hardcoded cryptographic keys were found in 47.8% of Android apps and 17.6% of iOS apps. Critical-severity CVEs appeared in the SBOMs of 11% of Android and 13% of iOS apps.
High-severity CVEs were far more common on Android: 65% of apps, against 14% on iOS.
What does Quokka integrate with?
Several integrations still carry the Kryptowire name. The Jenkins plugin is listed as “Kryptowire” (version 0.4), the Azure DevOps publisher is Kryptowire-Inc, and the GitLab job runs a kryptowireowner/gitlab-ci Docker image.
GitLab CI
The GitLab integration pulls a public template from Quokka’s GitHub organization. These two snippets come from Quokka’s GitLab integration page.
include:
- remote: "https://raw.githubusercontent.com/Kryptowire/gitlab-ci-template/main/analysis.yml"
mast_analysis:
stage: test
variables:
SCORE_THRESHOLD: $SCORE_THRESHOLD_CUSTOM_VARIABLE
extends: .analysis
The job reads its settings from GitLab CI/CD variables. Quokka’s screenshot shows six project variables, with the score threshold stored under a custom name and mapped in the job.

| Variable | Purpose |
|---|---|
BINARY_FILE_PATH | Path to the APK or IPA built earlier in the pipeline |
MAST_REST_API | Q-mast API endpoint |
MAST_REST_API_KEY | Q-mast API key |
SCORE_THRESHOLD | Score threshold passed to the analysis |
MAX_ANALYSIS_TIME | Maximum analysis time (120 in Quokka’s example log) |
RESULTS_DIR | Folder where the results and gl-dast-report.json land |
VERSION | Optional image version; defaults to latest if unset |
The template writes its output as a GitLab DAST report. You need GitLab Ultimate to see it in the Security dashboard, though the integration itself runs on the free tier.

Jenkins
The Jenkins plugin adds a kwSubmit pipeline step. It submits the binary, shows scan results inside the build, and archives the PDF reports as build artifacts.
The Jenkins plugin page currently flags version 0.4 for an unresolved warning: the API key is stored in plain text. The SECURITY-3525 advisory rates it low severity and lists versions 0.2 and earlier.
kwSubmit filePath: "app/build/outputs/apk/debug/app-debug.apk", platform: 'android'
Azure DevOps, Snyk, and Appium
The Azure DevOps extension is free on the Visual Studio Marketplace. It runs a Q-mast analysis after the build step.
Quokka links to a Q-mast entry in Snyk’s partner directory. Appium is listed as a DevSecOps integration, but Quokka’s site does not describe how it works.
Quokka vs NowSecure
NowSecure is a mobile-only security platform that runs automated SAST, DAST, and IAST on iOS, Android, and OTT apps. Its privacy engine tracks data flows, third-party sharing, and GDPR, CCPA, and HIPAA gaps.
NowSecure also offers PTaaS, an on-prem Workstation toolkit, and authorized lab status for Google’s App Defense Alliance MASA program. Those are services Quokka’s Q-mast pages do not list.
Quokka’s distinct strengths are forced-path execution, NIAP-first reporting, and binary-only testing of obfuscated builds. Its sister products cover MDM app vetting and Android firmware, a wider scope than app testing alone.
Pick NowSecure if you need OTT apps, pentesting from the same vendor, or the MASA badge on Google Play. Pick Quokka if NIAP evidence or behavior hidden behind rarely used code paths matters more.
Quokka vs Appknox
Appknox also scans compiled APK, AAB, and IPA binaries instead of source code. It runs binary SAST, AI-led DAST on real physical devices, and API security testing.
Appknox adds manual penetration testing by certified researchers with a sub-24-hour turnaround. Its Storeknox module watches app stores for fake or unauthorized copies of your app.
Quokka matches the binary-first model and the real-device DAST. It adds IAST, forced-path execution, and NIAP mapping. Appknox maps findings to OWASP MASVS, PCI-DSS, HIPAA, and NIST.
Pick Appknox for automated scanning plus manual pentesting from one vendor, with pentests billed per engagement. Pick Quokka if your buyers or auditors ask for NIAP, or you also need employee app vetting.
Quokka vs Zimperium zScan
Zimperium zScan is an automated MAST product that combines SAST, DAST, and IAST. Zimperium says it returns prioritized findings in 15 to 30 minutes.
zScan’s distinct angle is control validation. It checks whether certificate pinning, root detection, and anti-tampering actually work, and it sits inside Zimperium’s MAPS suite next to zShield and zDefend.
Quokka’s angle is behavior: forced-path execution, SDK data-flow tracking, and malware-style indicators like privilege escalation. Both vendors also sell an enterprise product for employee devices.
Pick zScan if you want a 30-day free trial and a path to in-app protection from the same vendor. Pick Quokka if hidden app behavior and NIAP reporting come first.
How much does Quokka cost?
Quokka does not publish pricing for Q-mast, Q-scout, or Q-firm. Its site points buyers to a demo request or contact form, and I found no public tier list or per-app price.
| Option | What you get |
|---|---|
| Free assessment | Security report for one iOS or Android app: static and dynamic analysis, secrets detection, library and API inventory, MASVS, NIAP, and GDPR mapping |
| Q-mast | Not publicly listed; contact Quokka or request a demo |
| Azure DevOps extension | Free to install; it needs a Q-mast account to run |
| Public sector | Available through Four Inc. on NASA SEWP V and ITES-SW2 contract vehicles |
The free assessment produces a report on your own app. Quokka also offers a Q-mast sample report behind a short form.
How do you get started with Quokka?
- Request the free app assessment or a demo on quokka.io to get a sample report on your own binary.
- Once licensed, get your Q-mast API endpoint and API key.
- Add the integration for your CI: the GitLab template, the Jenkins
kwSubmitstep, or the Azure DevOps extension. - Set the score threshold and maximum analysis time variables for your pipeline.
- Review findings against the OWASP MASVS and NIAP mappings, and send the SBOM to whoever owns third-party SDKs.
When should you use Quokka?
Quokka fits teams that ship mobile apps to US federal agencies or other regulated buyers who ask for NIAP evidence. Quokka lists DHS and CISA as customers and took part in NIST mobile publications.
It also fits security teams that need to test apps they did not build. Vendor apps, acquired apps, and outsourced builds can all be scanned from the binary alone.
Organizations that want both MAST for in-house apps and vetting for employee apps can buy both from one vendor. Q-scout ties into Microsoft Intune, Ivanti, Hexnode, and Omnissa Workspace ONE.
It is a weaker fit for small teams that want transparent self-serve pricing, or a free tool. MobSF covers basic static and dynamic analysis at no cost.
What are alternatives to Quokka?
- NowSecure : mobile-only testing with a privacy engine, OTT support, and PTaaS.
- Appknox : binary-based scanning with real-device DAST and manual pentesting as a separate service.
- Zimperium zScan : automated MAST with security control validation and a free trial.
- Oversecured : automated vulnerability scanner for Android and iOS apps.
- MobSF : free, open-source static and dynamic analysis.
For a wider list, see NowSecure alternatives and MobSF alternatives . The mobile app pentesting guide explains where automated MAST stops and manual testing begins.
What else does Quokka sell?
Q-scout vets the apps on employee devices. It pulls app inventories from MDM tools and analyzes each app in the cloud, with no agent on the device.
Quokka says Q-scout saves 10 to 12 hours per app compared with manual app vetting. It also feeds findings into Microsoft Sentinel.
Q-firm launched in 2026 for telcos and Android device makers. It scans pre-installed and privileged system apps for privilege escalation and data leaks before devices ship.
Q-firm works on any device running Android OS, including IoT hardware. Quokka’s experts review the automated results and write the final report.
What are Quokka’s limitations?
Strengths
- Binary-only analysis that handles obfuscated and signed iOS builds
- Forced-path execution for code paths that normal DAST never reaches
- NIAP mapping backed by Kryptowire’s role in the DHS and NIAP automated-testing pilot
- A research team with 230+ mobile CVEs behind the detection engines (vendor figure)
- One vendor for app testing, employee app vetting, and Android firmware
Limitations
- No public pricing; Quokka’s site routes buyers to a demo request or contact form.
- The headline numbers (under 60 minutes, under 1% false results) are vendor claims; Quokka does not cite independent validation for them.
- Product docs sit behind a customer login, so I could not review the full rule set. The sample report shows the report format.
- CI integrations still use the Kryptowire name and have small public footprints; the Azure DevOps extension shows 42 installs.
- Viewing results inside GitLab’s security dashboard requires GitLab Ultimate.
- The Jenkins plugin catalog flags the current Kryptowire plugin for an unresolved low-severity warning: the API key is stored in plain text.
- Q-mast pages describe an automated product. Quokka positions manual pentesting as a complement rather than listing a pentest service for Q-mast.