Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

Q-mast review

#13 of 21 in Mobile Application Security Testing Software

A broad, standards-focused testing suite for established mobile security teams.

8.0/10Editor score
Q-mast8.0 Visit Quokka

Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026

Q-mast is Quokka’s automated mobile application security testing solution for security and development teams working with iOS and Android apps. It analyzes compiled application binaries without requiring source code, including obfuscated and protected builds. Its coverage spans static analysis, dynamic analysis on non-rooted and non-jailbroken devices, interactive analysis, forced-path execution, data-flow analysis, and post-deployment monitoring of app-store builds. That makes it a fit for established teams that need standards-based analysis across development and released applications.

Its strongest differentiator is the combination of analysis methods and supply-chain visibility. Q-mast can link runtime execution to application flows, execute scripted application paths, generate software bills of materials with version-specific components, and analyze SDK behavior and third-party dependencies. It also tests sensitive-data storage and network communication. Compliance mapping to NIAP, NIST, OWASP MASVS, and other standards gives teams a structured way to connect technical findings with security requirements.

Q-mast fits development workflows through integrations with GitHub, GitLab, Jenkins, Azure DevOps, Appium, and Snyk, alongside CI/CD and DevSecOps integrations. The product follows a demo-led, contact-sales purchasing model rather than a published tier structure. Teams looking for a broad mobile application security program with runtime, binary, SDK, compliance, and monitoring coverage should consider Q-mast. Organizations that need a narrow scanner, self-serve purchasing, or a simple entry-level workflow may find its scope and buying process less suitable.

Q-mast pros and cons

  • Where it wins
    • Analyzes compiled iOS and Android binaries without source code
    • Combines static, dynamic, interactive, and forced-path analysis
    • Maps findings to NIAP, NIST, OWASP MASVS, and other standards
  • Where it doesn't
    • Pricing requires a contact-sales process
    • The broad feature set may exceed narrow testing needs
    • Teams seeking self-serve purchasing may prefer another option

Q-mast fact sheet, pricing and score →

Advertiser disclosure: iTechGuides is reader-supported. Vendors can pay for top positions in our rankings and for a place on other products' pages, and we may earn a commission when you click some links. How we rank.

Last updated · How we research and update