AI helped write the code. Who tests what you ship?
Bring one mobile app to Booth 1. In 10 minutes we'll run it through Appknox on real devices and show you what's actually exploitable, and what to fix first.
Pick 14, 15 or 16 October and a time of day. We'll email you to confirm.
2
At CyberCon
Bring the app to Booth 1
The build file (APK or IPA), or just its App Store or Google Play link. Either works.
3
10 minutes later
Walk away with the findings
What's exploitable, what isn't, and what to fix first, walked through by our team.
Why Australian teams stop by
What Australian security teams are dealing with.
From conversations on the ground, and from Australia's regulators. Bring yours to Booth 1.
01
Mobile gets tested as a line item in the web pen test.
And manual pen-test costs climb with every new app. Mobile has its own attack surface: on-device storage, bundled SDKs and the build your customers install. Assess every release, and bring in expert pen testers when you need them.
Source: What Australian security teams tell our local team
02
APRA found control testing falls short.
APRA's CPS 234 assessment of more than 300 regulated entities flagged “inadequate definition and execution of control testing programs” and “limited assessment of third-party information security capability”. Testing every mobile release gives you ongoing evidence, not a once-a-year snapshot.
The OAIC is clear that organisations answer for their third-party providers. It received 532 breach notifications in the first half of 2025, with health, finance and government the top three sectors. Know every component you ship.
Fake versions of your app are now a regulatory problem.
The Scams Prevention Framework makes banks, telcos and digital platforms responsible for preventing, detecting and disrupting scams, including brand impersonation, with penalties of up to about A$50 million. Fake apps impersonating major Australian banks have reached Google Play before.
Assess what you build, and monitor what's live. One view of mobile app risk, before and after release.
KnoxIQ
Exploitable, or just noisy?
KnoxIQ validates each finding, shows how to reproduce it and rates how likely it is to be exploited. The fix lands in Cursor, Claude Code and Copilot.
SAST · DAST · API
Real devices, not simulators.
Static analysis of the binary, dynamic testing on real devices and API testing, with under 1% false positives across 150+ test cases. On every release, not once a year.
SCA · SBOM · AI-BOM
What's inside your app?
See the libraries, SDKs and AI components bundled in your build, which of them carry known risk, and an SBOM you can hand to your risk team.
Penetration testing
A pen test when you need one.
Our in-house researchers test by hand, business logic included, and walk you through the findings in the same platform. No waiting for the annual window.
Storeknox
Your app, and the fakes of it.
Continuous monitoring of the App Store and Google Play for clones and impersonation of your brand, and for versions that went live without being tested.
Privacy Shield
Where does personal data go?
See what your app collects, tracks and sends: trackers, dangerous permissions and personal data flows. Evidence for your work under the Australian Privacy Principles.
Who you'll meet in Melbourne
Two people. Ten minutes. Your app.
Harshit Agarwal
Co-founder & CEO
Ask about where mobile app risk is heading, and keeping up with AI-written code.
TK
Tarun Kumar
Associate Director of Sales, APAC
Ask about per-app pricing, one-off pen tests and getting started in Australia.
No. Appknox tests the compiled app, so the build file (APK or IPA) or just its App Store or Google Play link is enough. That also means apps built by a vendor are fair game.
Is it really free?
Yes. The audit is free for anyone at CyberCon Melbourne, with nothing to buy and nothing to sign.
Can I come by without an app?
Of course. Book a slot anyway and use the time to talk through mobile app risk, per-app pricing or a pen test with the team.
What if I can't make my slot?
Reply to your confirmation email and we'll move it, or just come to Booth 1 when you can.
CyberCon Melbourne · 14–16 Oct · Booth 1
See you in Melbourne. Book your 10-minute audit.
Pick a day and a time of day. We'll confirm your slot by email within one working day.