Skip to content
Quokka

Quokka

Category: Mobile Security
License: Commercial
Suphi Cankurt
Suphi Cankurt
+8 Years in AppSec
Updated October 5, 2026
11 min read
Key Takeaways
  • 2011: the year Kryptowire was founded; it rebranded to Quokka on September 12, 2022, as a rename of the same company, not an acquisition.
  • 4 analysis types in Q-mast: SAST, DAST on non-rooted, non-jailbroken devices, IAST, and forced-path execution, all run against the compiled binary with no source code.
  • Under 60 minutes per scan and under 1% false results, according to Quokka; these are vendor figures, not an independent benchmark.
  • 230+ mobile CVEs, 11 academic papers, and 150,000+ apps analyzed for its State of Mobile App Security 2026 report, according to Quokka.
  • 6 named DevSecOps integrations for Q-mast: GitHub, GitLab, Jenkins, Azure DevOps, Appium, and Snyk. Reports map to NIAP, NIST, OWASP MASVS, and GDPR.

Quokka Q-mast is a mobile app security testing product from Quokka, formerly Kryptowire. It scans compiled iOS and Android binaries for security, privacy, and compliance issues without needing source code.

Kryptowire was founded in 2011 and announced its rebrand to Quokka on September 12, 2022. It is the same company under a new name, not an acquisition.

Quokka (Kryptowire) scan results in Jenkins showing an Android app's threat score and NIAP requirements grouped into fail, review, and pass

This screenshot from the Jenkins plugin docs dates from 2018, the Kryptowire era. It shows an app’s threat score and NIAP requirements grouped into fail, review, and pass.

Current Q-mast reports still map findings to NIAP, though the interface has likely changed since then.

Quokka says it has worked with the US federal government since 2011. Its site shows logos from DHS, CISA, Orange, Trane Technologies, and UC Berkeley.

What is Quokka?

Quokka sells three products. Q-mast tests the mobile apps you build, Q-scout vets the apps your employees install, and Q-firm tests the firmware and pre-installed apps on Android devices.

This page focuses on Q-mast, the product that belongs in the MAST category. The other two get a short section further down.

FactDetails
CompanyQuokka, Inc. (formerly Kryptowire, Inc.), with offices in San Jose, CA and Arlington, VA
Founded2011, after DARPA and NIST research grants in 2010
RebrandKryptowire to Quokka, announced September 12, 2022
FundingGrowth investment led by US Venture Partners with Crosslink Capital, announced February 2022
LeadershipBaris Karadogan (CEO, appointed 2026); Angelos Stavrou (founder, Chief Science Officer); Nikos Kiourtis (CTO)
ProductsQ-mast (MAST), Q-scout (mobile app vetting), Q-firm (Android firmware analysis)
CertificationsSOC 2 compliant; member of the Microsoft Intelligent Security Association (2026)
Reach75+ customer countries, according to the Q-mast solution brief

Quokka leans on original research more than most MAST vendors I have reviewed. It reports 230+ mobile CVEs, 1,000+ zero-day device vulnerabilities, 11 academic papers, and 350+ academic citations, all vendor-reported figures.

Kryptowire also took part in NIST Special Publications 1800-21 and 1800-22. It contributed to “Automating NIAP Requirements Testing for Mobile Apps”, which explains why NIAP mapping is so central to the product.

What are Q-mast’s key features?

FeatureDetails
InputCompiled iOS and Android binaries; no source code required
ObfuscationAnalyzes obfuscated, protected, and signed iOS builds
Analysis typesSAST, DAST, IAST, and forced-path execution (FPE)
Test devicesDAST on non-rooted, non-jailbroken devices; app simulation on purpose-built emulators
Scan timeUnder 60 minutes (vendor figure)
Accuracy claimUnder 1% false results (vendor figure)
Supply chainVersion-precise SBOM, SDK behavior analysis, nested dependencies
StandardsNIAP, NIST, and OWASP MASVS checks; reports aligned to MASVS, NIAP, and GDPR
Vulnerability data and outputKnown CVE identification; SARIF results format
Post-releaseApp Watch List monitors production builds straight from app stores, with no device agents
IntegrationsGitHub, GitLab, Jenkins, Azure DevOps, Appium, Snyk

Four analysis types

Q-mast runs four analysis types against the same binary. Quokka describes each one this way on the Q-mast product page.

AnalysisWhat Quokka says it does
Static (SAST)Detects insecure patterns, hardcoded secrets, weak crypto, and misconfigurations
Dynamic (DAST)Observes real app behavior on non-rooted, non-jailbroken devices
Interactive (IAST)Links runtime execution paths to specific flows and behaviors
Forced-path execution (FPE)Exercises scripted, repeatable flows, including rare edge cases

Forced-path execution is the one I rarely see on other MAST product pages. Quokka defines it as forcing every conditional branch to run, including code that normal use never reaches.

That targets logic bombs, hidden triggers, and obfuscated malware. A crawler-style DAST pass usually misses those because nobody taps the right sequence of buttons.

Binary-first testing

Because Q-mast reads the compiled app, the same scan works on code you wrote and on vendor or third-party apps you only have as an APK or IPA.

Quokka says it supports recent iOS and Android versions and signed, protected builds. Teams that ship apps with RASP or obfuscation turned on can test the actual release artifact.

SBOM and SDK behavior

Q-mast builds an SBOM tied to exact library versions, including embedded libraries. Quokka’s pitch is that it goes past CVE lookup and watches what each SDK actually does at runtime.

The product page says Q-mast flags hidden AI libraries, outbound data flows, and SDKs sending user or corporate data offshore. That puts privacy findings in the same report as vulnerabilities.

Note
Where the NIAP focus comes from

Kryptowire took part in a DHS and NIAP pilot. The pilot used Kryptowire’s vetting infrastructure to automate testing against NIAP requirements for mobile apps.

Q-mast reports map findings to NIAP alongside OWASP MASVS, which matters if you sell apps to US federal agencies.

Indicators of risk

The GitLab integration page lists the indicators of risk (IoRs) that the CI job reports back. They give a concrete picture of what Q-mast flags.

  • Network: HTTP_TRAFFIC, ACCEPTS_ALL_CERTS, TRANSPORT_SECURITY_DISABLED, HIGHRISK_COUNTRY_CONNECTION
  • Secrets: USES_HARD_CODED_CREDENTIALS, HARD_CODED_KEY, PASSWORD_EXPOSED
  • Privacy: PII_LEAKAGE
  • Build hygiene: DEBUGGABLE, MISSING_COMPILE_PROTECTION
  • Malicious behavior: MALWARE_DETECTED, PRIVILEGE_ESCALATION, INDIRECT_FACTORY_RESET
  • Dependencies: CONTAINS_LIBRARY_CVE

What the research data shows

Quokka analyzed 150,000+ apps during 2025 for its State of Mobile App Security 2026 report. The findings are Quokka’s own data, but they show the kind of issues Q-mast is tuned for.

Plain HTTP URLs turned up in 94.3% of Android apps and 61.7% of iOS apps. ECB-mode ciphers appeared in 68.1% of Android apps and 24% of iOS apps.

Hardcoded cryptographic keys were found in 47.8% of Android apps and 17.6% of iOS apps. Critical-severity CVEs appeared in the SBOMs of 11% of Android and 13% of iOS apps.

High-severity CVEs were far more common on Android: 65% of apps, against 14% on iOS.

What does Quokka integrate with?

Q-mast DevSecOps integrations
GitLab GitLab
Jenkins Jenkins
Azure DevOps Azure DevOps
GitHub GitHub
Snyk Snyk
Appium

Several integrations still carry the Kryptowire name. The Jenkins plugin is listed as “Kryptowire” (version 0.4), the Azure DevOps publisher is Kryptowire-Inc, and the GitLab job runs a kryptowireowner/gitlab-ci Docker image.

GitLab CI

The GitLab integration pulls a public template from Quokka’s GitHub organization. These two snippets come from Quokka’s GitLab integration page.

include:
  - remote: "https://raw.githubusercontent.com/Kryptowire/gitlab-ci-template/main/analysis.yml"
mast_analysis:
  stage: test
  variables:
    SCORE_THRESHOLD: $SCORE_THRESHOLD_CUSTOM_VARIABLE
  extends: .analysis

The job reads its settings from GitLab CI/CD variables. Quokka’s screenshot shows six project variables, with the score threshold stored under a custom name and mapped in the job.

GitLab CI/CD variables for the Quokka Q-mast integration: BINARY_FILE_PATH, MAST_REST_API, MAST_REST_API_KEY, MAX_ANALYSIS_TIME, RESULTS_DIR, and a custom score threshold variable
VariablePurpose
BINARY_FILE_PATHPath to the APK or IPA built earlier in the pipeline
MAST_REST_APIQ-mast API endpoint
MAST_REST_API_KEYQ-mast API key
SCORE_THRESHOLDScore threshold passed to the analysis
MAX_ANALYSIS_TIMEMaximum analysis time (120 in Quokka’s example log)
RESULTS_DIRFolder where the results and gl-dast-report.json land
VERSIONOptional image version; defaults to latest if unset

The template writes its output as a GitLab DAST report. You need GitLab Ultimate to see it in the Security dashboard, though the integration itself runs on the free tier.

GitLab pipeline log of the Quokka Q-mast job copying an iOS IPA into the analysis container and starting a scan with a score threshold of 42

Jenkins

The Jenkins plugin adds a kwSubmit pipeline step. It submits the binary, shows scan results inside the build, and archives the PDF reports as build artifacts.

The Jenkins plugin page currently flags version 0.4 for an unresolved warning: the API key is stored in plain text. The SECURITY-3525 advisory rates it low severity and lists versions 0.2 and earlier.

kwSubmit filePath: "app/build/outputs/apk/debug/app-debug.apk", platform: 'android'

Azure DevOps, Snyk, and Appium

The Azure DevOps extension is free on the Visual Studio Marketplace. It runs a Q-mast analysis after the build step.

Quokka links to a Q-mast entry in Snyk’s partner directory. Appium is listed as a DevSecOps integration, but Quokka’s site does not describe how it works.

Quokka vs NowSecure

NowSecure is a mobile-only security platform that runs automated SAST, DAST, and IAST on iOS, Android, and OTT apps. Its privacy engine tracks data flows, third-party sharing, and GDPR, CCPA, and HIPAA gaps.

NowSecure also offers PTaaS, an on-prem Workstation toolkit, and authorized lab status for Google’s App Defense Alliance MASA program. Those are services Quokka’s Q-mast pages do not list.

Quokka’s distinct strengths are forced-path execution, NIAP-first reporting, and binary-only testing of obfuscated builds. Its sister products cover MDM app vetting and Android firmware, a wider scope than app testing alone.

Pick NowSecure if you need OTT apps, pentesting from the same vendor, or the MASA badge on Google Play. Pick Quokka if NIAP evidence or behavior hidden behind rarely used code paths matters more.

Quokka vs Appknox

Appknox also scans compiled APK, AAB, and IPA binaries instead of source code. It runs binary SAST, AI-led DAST on real physical devices, and API security testing.

Appknox adds manual penetration testing by certified researchers with a sub-24-hour turnaround. Its Storeknox module watches app stores for fake or unauthorized copies of your app.

Quokka matches the binary-first model and the real-device DAST. It adds IAST, forced-path execution, and NIAP mapping. Appknox maps findings to OWASP MASVS, PCI-DSS, HIPAA, and NIST.

Pick Appknox for automated scanning plus manual pentesting from one vendor, with pentests billed per engagement. Pick Quokka if your buyers or auditors ask for NIAP, or you also need employee app vetting.

Quokka vs Zimperium zScan

Zimperium zScan is an automated MAST product that combines SAST, DAST, and IAST. Zimperium says it returns prioritized findings in 15 to 30 minutes.

zScan’s distinct angle is control validation. It checks whether certificate pinning, root detection, and anti-tampering actually work, and it sits inside Zimperium’s MAPS suite next to zShield and zDefend.

Quokka’s angle is behavior: forced-path execution, SDK data-flow tracking, and malware-style indicators like privilege escalation. Both vendors also sell an enterprise product for employee devices.

Pick zScan if you want a 30-day free trial and a path to in-app protection from the same vendor. Pick Quokka if hidden app behavior and NIAP reporting come first.

How much does Quokka cost?

Quokka does not publish pricing for Q-mast, Q-scout, or Q-firm. Its site points buyers to a demo request or contact form, and I found no public tier list or per-app price.

OptionWhat you get
Free assessmentSecurity report for one iOS or Android app: static and dynamic analysis, secrets detection, library and API inventory, MASVS, NIAP, and GDPR mapping
Q-mastNot publicly listed; contact Quokka or request a demo
Azure DevOps extensionFree to install; it needs a Q-mast account to run
Public sectorAvailable through Four Inc. on NASA SEWP V and ITES-SW2 contract vehicles

The free assessment produces a report on your own app. Quokka also offers a Q-mast sample report behind a short form.

How do you get started with Quokka?

  1. Request the free app assessment or a demo on quokka.io to get a sample report on your own binary.
  2. Once licensed, get your Q-mast API endpoint and API key.
  3. Add the integration for your CI: the GitLab template, the Jenkins kwSubmit step, or the Azure DevOps extension.
  4. Set the score threshold and maximum analysis time variables for your pipeline.
  5. Review findings against the OWASP MASVS and NIAP mappings, and send the SBOM to whoever owns third-party SDKs.

When should you use Quokka?

Quokka fits teams that ship mobile apps to US federal agencies or other regulated buyers who ask for NIAP evidence. Quokka lists DHS and CISA as customers and took part in NIST mobile publications.

It also fits security teams that need to test apps they did not build. Vendor apps, acquired apps, and outsourced builds can all be scanned from the binary alone.

Organizations that want both MAST for in-house apps and vetting for employee apps can buy both from one vendor. Q-scout ties into Microsoft Intune, Ivanti, Hexnode, and Omnissa Workspace ONE.

It is a weaker fit for small teams that want transparent self-serve pricing, or a free tool. MobSF covers basic static and dynamic analysis at no cost.

What are alternatives to Quokka?

  • NowSecure : mobile-only testing with a privacy engine, OTT support, and PTaaS.
  • Appknox : binary-based scanning with real-device DAST and manual pentesting as a separate service.
  • Zimperium zScan : automated MAST with security control validation and a free trial.
  • Oversecured : automated vulnerability scanner for Android and iOS apps.
  • MobSF : free, open-source static and dynamic analysis.

For a wider list, see NowSecure alternatives and MobSF alternatives . The mobile app pentesting guide explains where automated MAST stops and manual testing begins.

What else does Quokka sell?

Q-scout vets the apps on employee devices. It pulls app inventories from MDM tools and analyzes each app in the cloud, with no agent on the device.

Quokka says Q-scout saves 10 to 12 hours per app compared with manual app vetting. It also feeds findings into Microsoft Sentinel.

Q-firm launched in 2026 for telcos and Android device makers. It scans pre-installed and privileged system apps for privilege escalation and data leaks before devices ship.

Q-firm works on any device running Android OS, including IoT hardware. Quokka’s experts review the automated results and write the final report.

What are Quokka’s limitations?

Strengths

  • Binary-only analysis that handles obfuscated and signed iOS builds
  • Forced-path execution for code paths that normal DAST never reaches
  • NIAP mapping backed by Kryptowire’s role in the DHS and NIAP automated-testing pilot
  • A research team with 230+ mobile CVEs behind the detection engines (vendor figure)
  • One vendor for app testing, employee app vetting, and Android firmware

Limitations

  • No public pricing; Quokka’s site routes buyers to a demo request or contact form.
  • The headline numbers (under 60 minutes, under 1% false results) are vendor claims; Quokka does not cite independent validation for them.
  • Product docs sit behind a customer login, so I could not review the full rule set. The sample report shows the report format.
  • CI integrations still use the Kryptowire name and have small public footprints; the Azure DevOps extension shows 42 installs.
  • Viewing results inside GitLab’s security dashboard requires GitLab Ultimate.
  • The Jenkins plugin catalog flags the current Kryptowire plugin for an unresolved low-severity warning: the API key is stored in plain text.
  • Q-mast pages describe an automated product. Quokka positions manual pentesting as a complement rather than listing a pentest service for Q-mast.
Tip
Best For
Teams that need NIAP-mapped evidence for mobile apps, or that must test binaries they have no source for, including vendor and third-party apps.
Note: Formerly Kryptowire, Inc. (founded 2011); rebranded to Quokka on September 12, 2022. Growth investment from US Venture Partners and Crosslink Capital announced February 2022.

Frequently Asked Questions

What is Quokka Q-mast?
Q-mast is Quokka’s automated mobile application security testing product for iOS and Android apps. It scans the compiled binary, not source code, using SAST, DAST, IAST, and forced-path execution. Quokka says a scan takes under 60 minutes.
Is Quokka the same company as Kryptowire?
Yes. Kryptowire, Inc. announced its rebrand to Quokka on September 12, 2022. It is a rename, not an acquisition. Some integrations still carry the old name, including the Jenkins plugin and the Azure DevOps publisher, Kryptowire-Inc.
Does Quokka need source code to scan a mobile app?
No. Q-mast analyzes compiled app binaries, including obfuscated, protected, and signed iOS builds. That lets you test third-party and vendor apps you have no source access to, not only apps your own team builds.
How much does Quokka cost?
Quokka does not publish pricing for Q-mast; its website directs buyers to contact the company or request a demo. It also offers a free security assessment report for an iOS or Android app, with OWASP MASVS, NIAP, and GDPR mapping.
Which CI/CD tools does Quokka Q-mast integrate with?
Quokka lists GitHub, GitLab, Jenkins, Azure DevOps, Appium, and Snyk. GitLab uses a public CI template that runs a Docker container and writes a GitLab DAST report. Jenkins uses the kwSubmit pipeline step from the Kryptowire plugin, which the Jenkins catalog currently flags for an unresolved low-severity issue (API key stored in plain text).
How does Quokka compare to NowSecure?
Both test compiled iOS and Android apps with automated SAST, DAST, and IAST. NowSecure adds a privacy engine, OTT app support, PTaaS, and Google ADA MASA lab status. Quokka adds forced-path execution, NIAP-focused reporting, and sister products for MDM app vetting and Android firmware.
What compliance standards does Quokka map findings to?
Quokka says Q-mast checks apps against NIAP, NIST, and OWASP MASVS, and its reports are aligned to OWASP MASVS, NIAP, and GDPR. Quokka’s use-case page also lists PCI DSS and HIPAA mapping. Separately, Q-mast flags known CVEs and supports SARIF, a format for exchanging scan results. Kryptowire’s vetting infrastructure ran the DHS and NIAP pilot that automated testing against NIAP requirements.