Audit mobile apps, backed by evidence

The web, you know how to audit. The mobile app stays a black box. Skanopy opens it, and finally gives you the tooling for mobile.

The banner, criterion by criterion

Every criterion recorded as the user actually meets it.

Link to the privacy policyReject at first level
Settings button presentReject button present

Mobile is no longer your blind spot.

The CNIL itself notes that the mobile environment carries more risk than the web for personal data. A browser is a window; a phone is a device, with its location, its sensors, its address book, and permissions an app asks for and then uses out of your sight. Yet you have no simple way to see what it does with them. On the web, you open the browser’s tools; on mobile there is no equivalent, and what the publisher declares is not always what the app does.

Skanopy opens that black box. Every third-party actor contacted, every piece of personal data transmitted, every gap with the consent banner is captured on a real phone, documented and dated. You get reproducible findings, backed by evidence, pointing to where the app departs from the GDPR and the ePrivacy directive (and, in France, the CNIL’s mobile-app recommendation).

This is the material you are missing for your accountability: enough to document your compliance, feed your records and mapping, decide and prioritize. The analysis does the technical work for you, and its findings read without technical skills.

What you gain.

The concrete gain, exactly as it appears in the report you receive.

Findings, not assumptions

Every observation is reproducible and dated, backed by evidence: enough to document your compliance.

Your blind spot covered

What an app does on the device: the data that leaves it, the permissions it actually uses. Audits often stop at the web and the declared.

Hours saved

The analysis does the technical work: capturing real behavior and tying each piece of data to who receives it.

The gaps before the regulator

Actors fired without consent, data sent with no basis: you fix them before a check.

The report you present.

What every analysis delivers: a dated, reproducible report where each finding cites its evidence. The document you put in front of a regulator, a committee, or a client.

How Skanopy works.

  1. Point us to the app

    Two ways in:

    • A Google Play Store link
    • A .apk file, for a pre-release before it ships
  2. Skanopy analyzes it

    On real phones, a real journey replayed automatically:

    • Tracking refused
    • Signed in
    • Article opened
    • Form submitted

    Every third-party actor that fires is mapped.

  3. You receive your report

    Every fact, named:

    • Active third-party actors
    • Identifiers shared
    • Permissions requested
    • Storage access
    • Consent-banner compliance

Your questions, our answers.

  • No. Skanopy runs the technical analysis and delivers readable findings, tied to every piece of evidence.

  • Yes. They are factual, dated and reproducible: the evidence expected to document your compliance.

  • Yes. The actors and data observed feed straight into your mapping and the tracking of your processors.

  • Yes, on any Android app you are entitled to audit. A Google Play link or an .apk file is enough.

  • Skanopy is a French company, and your analyses are processed in the European Union.

  • Skanopy analyzes Android apps.

Do I need technical skills?

No. Skanopy runs the technical analysis and delivers readable findings, tied to every piece of evidence.

The first finding costs nothing.