Trust & transparency
Security first, always.
Coixa is built with proactive security at its core. We publish audits and stay honest about what still needs work.
96/100
Latest score
Low Risk
Risk level
3
Total scans
0
High vulns
Latest audit snapshot
Most recent MobSF static analysis of the Android app.
Score 96/100
No critical vulnerabilities identified. Remaining findings are non-critical and under continuous review.
Tool
MobSF Static Analysis
Risk
Low
Grade
A
Discovery breakdown
Last updated: March 2026
Track record of improvement
Scores across releases — we track progress instead of hiding it.
v3.3.1
March 2026
Score 96LowImprovedGrade A · 0 high · 1 medium
v2.1.0
January 2026
Score 59LowImprovedGrade B · 0 high · 9 medium
v1.0.0-beta.1
November 2025
Score 51MediumGrade B · 1 high · 9 medium
Continuous hardening
Milestones implemented after audit cycles.
Resolved Issues
- Eliminated high-risk vulnerabilities found in beta versions
- Enforced modern Android SDK constraints for better sandboxing
- Strengthened binary protections including NX, PIE, and RELRO
- Reduced overall attack surface by removing unused dependencies
Security Enhancements
- Implemented encrypted storage for sensitive user data
- Added biometric authentication fallback for critical actions
- Enhanced SSL pinning to prevent man-in-the-middle attacks
- Real-time dependency monitoring for known vulnerabilities
Known limitations
No system is perfect. Here is what we are still working on.
- Clipboard usage is currently under review
- Continuous permission hardening is ongoing as we add new features
- Third-party manual audit + dynamic analysis scheduled for Q2 2026
Methodology
How we keep Coixa a safe place for your assets.
Static Analysis
Automated code scanning using MobSF to identify security flaws before deployment.
Secure Coding
Adhering to industry best practices and OWASP guidelines for mobile application security.
Dependency Monitoring
Continuous tracking of third-party libraries for security disclosures and updates.
Planned Dynamic Analysis
Executing the application in a runtime environment to find logic-based vulnerabilities.
Responsible disclosure
Found a vulnerability? We take reports seriously.