
Queryella provides an AI-automated platform that analyzes mobile app binaries for security vulnerabilities and GDPR data protection violations without requiring source code access. The platform combines static, dynamic, and hybrid analysis techniques to detect data leaks, identify vulnerable third-party libraries, and uncover hidden or obfuscated code. It serves data protection experts, companies, and certification bodies seeking efficient, precise app assessments.
Funding
Funding not disclosed
Founders
Product
Problem
Mobile apps increasingly handle sensitive personal data, yet manual security and data protection assessments are time-consuming, expensive, and often fail to keep pace with evolving threats and regulatory requirements like GDPR. Companies and certification bodies struggle to efficiently identify vulnerabilities, data leaks, and compliance gaps in apps, especially when source code is unavailable or obfuscated.
Solution
Queryella offers a fully automated analytics platform that performs in-depth inspections of mobile app binaries for security vulnerabilities and data protection violations. The platform combines static, dynamic, and hybrid analysis techniques powered by artificial intelligence, enabling it to identify data flows, detect leaks of sensitive data, and uncover hidden code even when common obfuscators have been used. Analyses can be customized into workflows tailored to individual customer needs, and reports can be generated at different levels of abstraction—from executive summaries to detailed technical documentation. The platform also detects third-party libraries and compares them against known vulnerabilities, providing a comprehensive security and privacy assessment without requiring access to the app's source code.
Target Audience
Primary customers are data protection experts, companies needing to satisfy GDPR and IT security requirements, and certification bodies that assess mobile apps according to established standards.
Features
- Binary-focused analysis that works without source code and remains reliable even when obfuscators are applied
- Static analysis to identify data sources and sinks, mapping data flows and checking vulnerability accessibility from main application code
- AI-powered dynamic analysis with automated instrumentation to track real-time data flows and detect anti-debugging measures
- Library detection that identifies third-party libraries, their versions, and correlations with known vulnerabilities
- Obfuscation analysis that deobfuscates strings and replaces dynamic loading with actual code to expose hidden vulnerabilities
- Hybrid analytics that combine static and dynamic methods in configurable sequences to uncover more data flows
- Customizable analysis workflows and reports tailored to different abstraction levels for business or technical audiences