Neobank app for credit building with instant approval, cash advances, and credit score tracking. Requires identity verification and linked bank account.
This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.
The five trust checks
Quick Verdict
Best for: Credit applicants comfortable with identity verification
What It Means For You
Financial account connections via Plaid, document scans, and biometric checks are processed as part of identity verification. App usage and attribution data flow to AppsFlyer, Segment, and Google Tag Manager. Fraud detection signals are shared with TransUnion. User financial data may not be fully protected in all storage scenarios.
Quick Verdict
Best for: Credit applicants comfortable with identity verification
What It Means For You
Financial account connections via Plaid, document scans, and biometric checks are processed as part of identity verification. App usage and attribution data flow to AppsFlyer, Segment, and Google Tag Manager. Fraud detection signals are shared with TransUnion. User financial data may not be fully protected in all storage scenarios.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
6 totalNetwork Security
2 totalCode Security
5 totalPrivacy
3 totalThird-Party Risk
1 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
ai.cred.robocred
Version
1.9.22 (build 20251123100)
Analysis Date
Jun 17, 2026
Feedback helps us improve our analysis
This credit-building neobank earns strong marks for network security and data sharing controls. However, a private signing key is distributed inside the app where it can be extracted from any installed copy, and your advertising ID is sent to attribution services without the iOS permission prompt that gives you a choice. These issues are worth keeping in mind for a financial app that handles identity verification and bank account access.
Data Security - 6 findings (1 critical, 4 low, 1 info)
Network Security - 2 findings (1 medium, 1 info)
Code Safety - 6 findings (1 medium, 2 low, 3 info)
Privacy - 3 findings (1 medium, 1 low, 1 info)
The following third parties may receive your data:
Security: 67/100
Privacy: 85/100
The app's privacy practices could be strengthened by:
Advertising Tracking Consent
The standard iOS permission prompt for advertising tracking is absent. Adding this step would give you a clear choice about whether your advertising ID is sent to attribution services before any data leaves your device.
Financial Behavior Linked to Advertising
Your in-app activity is linked to your identity and used for the developer's own advertising purposes. Providing a clear opt-out for this data use would better align with user expectations for a financial app.
Server-Side Key Management
A private signing key is distributed inside the app where it can be extracted from any installed copy. Storing this key on a server rather than in the app bundle would prevent it from being accessible to anyone who obtains the app file.
Stronger File and Keychain Protection
Some stored data may be accessible before you unlock your device. Using the strongest available iOS protection settings would ensure your financial information stays locked until you authenticate.
App Type: Financial services (neobank, credit building, sensitive data)
Classes Analyzed: 0
Third-Party Services: 19
Context Tags: financial, sensitive_data, location, ads
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on iOS applications to help users make informed decisions about app security and privacy.
Developer: Not available
Version: 1.9.22 (build 20251123100)
Analysis Date: 2026-06-17
Package: ai.cred.robocred
Developer not yet contacted