WHO WE ARE
We read the app, not its privacy policy
A privacy policy tells you what a company promises. We open up the app and check what it does.
CanITrustThat is an independent security and privacy scanner for mobile apps. It decompiles the app that actually ships to your phone, checks how that code handles your data, and turns the result into a plain trust score you can read in seconds. The scorecard is free and needs no account.
What is CanITrustThat?
You tap "Allow" on location, contacts, photos, and card details dozens of times a week. Then the data leaves your phone and you never find out where it goes. The store listing and the privacy policy are written by the same people shipping the app. We read the app instead.
We decompile the shipped build and go through how it handles secrets, encryption, network traffic, storage, and trackers. That becomes a public scorecard: one trust score up top, the security and privacy scores underneath, and the exact lines of code each one rests on.
Who is it for?
Anyone deciding whether to install something. The public scorecard is free, needs no account, and gives you a straight answer before you commit your data to an app.
The detailed report is built for the people who answer for these decisions: security engineers, privacy and compliance leads, product owners, and the consultancies they hire. It shows every finding, where it sits in the code, how bad it is, and how to fix it. A full scan runs in about thirty minutes. A manual mobile assessment takes days.
Why we built it
Checking a mobile app properly has always meant hiring a specialist for a slow, expensive one-off engagement. The findings land in a PDF that maybe six people read, and then the next version ships and the PDF is stale. Meanwhile the gap between what apps claim and what they do keeps widening.
So we publish. A finding that used to sit in a private report becomes a public record on the app's page. Developers get held to it, and everyone else gets to choose with their eyes open. We are still early, and there are plenty of apps we have not gotten to yet.
How we stay independent
An app is scored on what its code does. Who is asking and who is paying changes none of it.
Evidence you can check
Every point on a score traces back to a specific place in the decompiled code. If we can't point at it in the binary, it doesn't go in the report.
The same rules for everyone
Every app runs against one fixed set of checks. Nobody buys a better score, and a polished store listing counts for nothing against the code.
Free and public
The public scorecard costs nothing and stays that way. Locking it up would defeat the point of publishing at all.
Run it again, get the same answer
Rerun a scan and the same app lands on the same evidence. The verdict holds up when someone checks your work.