A phone can be carefully managed and still be poorly understood. The security team may know its owner, operating system, passcode policy, and installed apps. It may even be able to erase the device. Yet the more interesting questions live one floor below that inventory: What does an app do after it opens? Which third-party libraries came along for the ride? Where does the data go? Quokka.io has spent roughly fifteen years building tools around that gap.
- Quokka tests mobile apps an organization builds, buys, or allows employees to install.
- Its analysis works on compiled apps, so a customer need not own the source code.
- The company now inspects Android firmware and pre-installed system apps before devices ship.
- Its customers include enterprises, government agencies, and teams in regulated industries.
The name is cheerful. The origin is rather less cuddly. The company started in 2011 as Kryptowire, founded by Angelos Stavrou and engineers and scientists from George Mason University. Its first work grew from research supported by DARPA and the Department of Homeland Security. The early question was how to find security and privacy failures in mobile software at scale. That research habit still shows: Quokka describes its work in terms of app behavior, execution paths, vulnerability discovery, and repeatable tests, not just a red warning icon.
The thing a device manager cannot tell you
Mobile device management, or MDM, is useful for the administrative life of a phone. It can enroll devices, enforce settings, and help an employer manage a fleet. A mobile threat defense product looks for suspicious activity on devices and networks. Quokka’s central claim is that neither job fully explains the applications themselves. An approved app can contain a risky software development kit, a hardcoded secret, weak encryption, or a network connection a security team never expected.
That is the opening for Q-scout, Quokka’s app vetting product. It analyzes apps off-device, looking at code structure and observed behavior in isolated environments. It can connect with systems such as Microsoft Intune, Ivanti Neurons for MDM, and Omnissa Workspace ONE so a finding reaches the people who can act on it. The practical sequence is simple: get an inventory, inspect the apps, decide which behaviors violate policy, then alert or restrict accordingly. Quokka says the analysis can work without an agent on every employee phone, an appealing arrangement when personal-device privacy is part of the negotiation.
A managed phone is an orderly phone. It is not necessarily an understood one.
The distinction matters most where the phone is part of a larger institution. A bank’s employees may use apps that were never built by the bank. A hospital may allow clinical tools with their own embedded libraries. A government office has to weigh mission needs against privacy and supply-chain risk. Quokka sells to these teams, as well as to developers who want to check their own apps before release. The company does not publish a verified customer total, but names enterprises, government agencies, and regulated industries as its markets.
Inspect the finished app, not just the recipe
Its other long-running product, Q-mast, belongs earlier in the software life cycle. A development team submits an iOS or Android build and receives an analysis of security, privacy, and compliance issues. Quokka says it combines static inspection with dynamic and interactive testing, including forced execution paths designed to expose behavior a normal user may rarely trigger. It checks components, permissions, network traffic, and known vulnerabilities, then maps findings to standards such as NIAP and OWASP MASVS.
The consequential detail is the input: the compiled app. Source code can be inaccessible when a team is reviewing a vendor’s product, a signed release, or an obfuscated build. Testing the binary is a way to inspect what is actually headed toward users. Quokka advertises scans under an hour and integrations with development workflows including GitHub, GitLab, Jenkins, and Azure DevOps. Those are vendor claims, not a guarantee for every build, but the intended use is clear: repeat the check each time software changes, instead of treating a single annual penetration test as a passport.

Then the factory floor entered the story
In March 2026, Quokka introduced Q-firm. The audience shifted from app developers and enterprise security teams to telecommunications providers and Android device makers. The target was firmware: the bundle of software already inside a device when it is sold. Some of those apps have elevated privileges, some are hidden from the ordinary user, and none can be reviewed by asking the owner to check an app store listing.
Q-firm applies several forms of automated analysis to those embedded applications, then adds expert review. It looks for insecure interfaces, vulnerable libraries, privacy leaks, and paths that might allow privilege escalation. It also produces software bills of materials, lists of components that help teams trace an exposed library to a specific device image. Promethean, an education technology company, was named as an early customer testing Android-based devices before shipment. Its security engineer described the problem plainly: validation is hard to do at scale. The product exists to make that work repeatable across models and build cycles.
The 2026 app report is a reminder that this is not solely a hunt for exotic attacks. In Quokka’s sample of more than 150,000 apps scanned during 2025, familiar weaknesses persisted: unencrypted web links, weak cryptography, and risky dependencies. A useful lesson for a reader building an app is gloriously unromantic. Inspect the release build; examine embedded components; check where information travels; make the test part of the build and update cycle. The same discipline applies to a vendor app before employees use it. A scan is evidence for a decision, not the decision itself.
A lab project learns the procurement process
Research alone does not buy enterprise adoption. In February 2022, Kryptowire announced growth investment led by U.S. Venture Partners with Crosslink Capital participating; outside funding records put the round at $21 million. Later that year it became Quokka and introduced Q-scout with a privacy-first pitch for personal devices used at work. The rebrand exchanged the hard-edged name for an animal famous for looking delighted. A whimsical mascot is no proof of software quality, but the shift told customers that privacy and security did not have to be presented as a contest.
The distribution story has since become more institutional. Quokka worked with Singapore’s Cyber Security Agency on a six-month Safe App Portal pilot launched in October 2025, intended to give developers usable app safety insights. Four Inc. became a public-sector distributor. In 2026 Quokka joined the Microsoft Intelligent Security Association and expanded connections to Microsoft’s security tools, Ivanti, and Omnissa. Each connection closes the same operational loop: an app finding is only useful when someone can see it in the system where they already manage devices or decide what may run.
Public pricing is not listed. The terms describe services accessed through a portal and sold under customer orders, while the site invites prospective buyers to request a demo. For a security leader, that means the business case is local rather than universal. Count the apps and devices in scope, the cadence of releases, the time already spent on manual reviews, and the cost of routing findings to an owner. Quokka’s case is strongest when there is a large or changing mobile estate, limited access to source code, or a need to document why an app was allowed. A tiny, stable app portfolio could justify a simpler review process.
The most interesting thing about Quokka is the direction of travel. It started with the app you choose to install. It moved to the apps already circulating through a workforce. It has now reached the apps a buyer never chose at all. Mobile security, in this telling, is less a wall around the phone than a series of questions about the software inside it. The first question is still the best one: what, exactly, does this app do?