IPAScope scans an .ipa or .app bundle for
security issues — entirely on your Mac, entirely offline. No account, no
backend, no upload. Point it at a build and get MASVS-mapped findings in
seconds, plus an optional AI-written pentest report.
App Transport Security (global and per-domain cleartext exceptions),
permission purpose strings, custom URL schemes, background modes,
provisioning profile expiry and get-task-allow.
FairPlay encryption status, PIE/ASLR, stack canaries, arm64e pointer authentication, and linked dylibs — across fat and thin Mach-O binaries.
Trackers, ads, analytics, and crash-reporting SDKs detected from an
offline signature list, cross-referenced against each SDK's own
PrivacyInfo.xcprivacy manifest.
AWS, GCP, Stripe, Slack, and GitHub keys, private keys, and JWTs — detected in the bundle. Only a redacted preview is ever stored; raw secrets never leave your machine.
Every finding is mapped to an OWASP MASVS category and ranked by severity. Generate a full written report on demand — only redacted evidence is sent, directly from your Mac to the provider you configure, using an API key you supply. IPAScope never sees it.
Your key is stored in the macOS Keychain and never leaves this machine except as the provider's auth header. There's no IPAScope backend to trust — the static scan is fully offline, and the report step is a direct connection you control.
$79.99 one-time
Sandboxed build — static analysis plus AI report generation. Fully unlocked at download, no subscription. Coming soon.