FAQ
Questions banking teams ask
Common questions from CISOs, AppSec, fraud, compliance and engineering teams.
How is MobAIsec different from MobSF?+
MobSF is a community static-analysis tool. MobAIsec is an enterprise governance platform: it adds MASVS / banking-mandate mapping, fraud readiness scoring, evidence-linked findings, executive reporting, continuous monitoring and regulator intelligence on top of static analysis.
Does MobAIsec support MASVS?+
Yes — MASVS L1, L2 and L3 controls are mapped end-to-end with per-domain coverage scores, evidence references and remediation playbooks.
How are UAE banking mandates mapped?+
Our governance crawler ingests CBUAE supervisory guidance and aligns each control to MASVS categories with evidence links, exposed in the country mandate explorer at /country-mandates.
Can MobAIsec integrate into CI/CD?+
Yes — REST APIs and signed-URL uploads support GitHub Actions, GitLab CI, Bitbucket Pipelines and Jenkins, with policy-as-code release gates.
How does APK governance work end-to-end?+
Upload → static / runtime analysis → MASVS + mandate mapping → executive PDF + evidence pack. Every step is deterministic and evidence-linked.
Does MobAIsec detect Frida and hooking?+
Yes — we surface anti-Frida, anti-Xposed, native security modules and RASP coverage, with severity-weighted scoring and remediation guidance.
Can MobAIsec replace penetration testing?+
It complements pen-testing by providing continuous, repeatable, evidence-linked coverage between annual or quarterly pen-test engagements.
How are reports generated?+
Executive, technical, MASVS, governance, fraud and country mandate PDFs are generated server-side and stored as immutable evidence artifacts.
Is the platform deterministic or AI-generated?+
Findings are deterministic — derived from explicit signals and verifiable artifacts. AI is used only for content surfacing, never for synthesizing security findings.
What does enterprise deployment look like?+
Cloud-native with regional residency options, SSO, RBAC, API-first, and audit-trail-by-design. Banks can also deploy in private VPC tenancy on request.