Honest limits first
App Transport Security, cleartext exceptions, and certificate pinning live in the binary. A listing scan that pretends to check them is marketing fiction.
AuditHQ records those as out of scope on the listing security card so a clean score never implies a binary review.
What the public page still reveals
Privacy policy URL resolves over HTTPS (or fails to load).
Tracking / collection labels that contradict privacy copy.
Review themes that cluster on “hacked,” “charged,” or “asks for my password.”
Weak publisher identity: no website, no support URL, free-email contact.
The same website security scanner run against the developer and privacy hosts — reusable evidence, not a new invention.
Use it before you promote an app
Create an iOS project for the App Store URL, enable the listing security scan, and fix Fail/Improve items on the linked site and privacy page first.
Reply to security-themed reviews with a real remediation path — silence reads as confirmation.