Decompile mobile APK and/or IPA to look inside
Check if your Android app kept any logs in your release build
Check and monitor mobile applications permissions
Check and monitor mobile applications sizes
Scan source code to extract all HTTP/HTTPS URLs and execute an analysis of those URLs with SSLLabs