Scan results

    a.s.r.

    Android

    a.s.r. is an insurance app for managing a.s.r. products and policies. Customers can access product overviews, report damage, and adjust personal details securely with PIN, fingerprint, or facial recognition login.

    CITT SCORE
    26
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: a.s.r. customers who need account access on the go

    What It Means For You

    In-app behavior is tracked by Microsoft Clarity and Tealium, which record how users interact with screens and buttons. User data passes through several third-party platforms including analytics and feedback tools. Users have limited control over what is collected, and user data may not be fully protected.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (22)

    Data Security

    7 total
    1 High
    3 Medium
    1 Low
    2 Info

    Network Security

    6 total
    1 High
    1 Medium
    2 Low
    2 Info

    Code Security

    6 total
    1 Critical
    2 High
    2 Medium
    1 Info

    Privacy

    2 total
    1 High
    1 Medium

    Permission Usage

    1 total
    1 Medium

    Third-Party Services

    OneWelcome (Onegini) SDK, Microsoft AppCenter Analytics, Microsoft AppCenter Crashes, Microsoft Clarity, Tealium, OneTrust, Firebase Messaging, Mopinion, YouTube Player, OkHttp, Retrofit, Dagger Hilt, Google Play Services

    Security Strengths

    • Certificate pinning implemented for authentication servers (ciam.asr.nl, login.asr.nl) via OneginiSDK
    • ADB backup disabled (android:allowBackup=false)
    • Cleartext HTTP traffic blocked at OS level (usesCleartextTraffic=false)
    • OneginiSDK stores authentication credentials in AES-256 encrypted SQLCipher database
    • No server-side secrets found in the binary
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    insurance
    sensitive data
    gdpr
    session recording
    oauth
    biometric
    location

    Package

    com.asr.mobileapp

    Version

    1.4.9 (versionCode 94)

    Analysis Date

    Feb 17, 2026

    Classes Analyzed

    19,213

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 7 findings (1 high, 3 medium, 1 low, 2 info)

    Network Security - 6 findings (1 high, 1 medium, 2 low, 2 info)

    Code Safety - 0 findings

    Privacy - 2 findings (1 high, 1 medium)

    Privacy Concerns

    What Data is Collected

    The app collects behavioral data about how users interact with it, including which screens are visited, which buttons are tapped, and how long users spend in each section. Crash reports and diagnostic information are also gathered. Device details and usage patterns are accessible to multiple analytics providers operating within the app.

    Third-Party Data Sharing

    User data is shared with the following third parties:

    • Microsoft Clarity: Records user in-app interactions and screen activity for behavioral analysis
    • Tealium: Manages and routes user behavioral data to connected marketing and analytics platforms
    • Microsoft AppCenter: Receives app usage statistics and diagnostic reports
    • Mopinion: Collects in-app feedback or survey responses users submit
    • OneTrust: Handles consent preference management
    • Firebase Messaging: Delivers push notifications to users' devices
    • YouTube Player: Processes video playback activity when users view embedded content

    Understanding the Scores

    CategoryScore
    Overall Security28/100
    Overall Privacy25/100
    Data Security48/100
    Network Security42/100
    Code Safety30/100
    Data Collection22/100
    Data Sharing55/100
    User Control20/100

    Positive Security Features

    • No notable positive security practices were identified for this version of the app.

    Areas for Improvement

    • The app shares user behavioral and usage data with multiple third-party platforms, giving users little visibility into what is collected, where it goes, or how it is used.
    • Data handled by the app is not consistently protected during transmission, which means some user information travels with less protection than expected.
    • The app provides very limited options for users to manage, restrict, or opt out of data collection, leaving users with minimal control over their information.

    About This Analysis

    Scores reflect the app's security and privacy posture based on the version analyzed. Individual scores range from 0 to 100, where higher scores indicate better practices.

    App Details

    FieldValue
    App Namea.s.r.
    Package IDcom.asr.mobileapp
    Version1.4.9 (build 94)
    Analysis Date2026-02-17

    Right of Reply

    Developer not yet contacted