BoursoBank Security & Privacy Scorecard
Android
In-app behavior, taps, and navigation patterns are collected by Heap Analytics and ContentSquare and used to analyze how users interact with the app. Adjust and Firebase track user activity across sessions. Payment interactions touch third-party services including Visa, Samsung Pay, and Google Pay.
Best for
Everyday banking with standard analytics tradeoffs
Avoid if
You want a bank that does not share behavior data
Findings
- 5 critical
- 7 high
- 5 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- WebView HTTP Authentication Credentials in Plaintext
- SSL Certificate Validation Bypass Risk
- Widget API Credentials Stored Unencrypted
Top privacy issues
- Excessive Analytics SDK Usage and Pre-Consent Tracking
- Android Backup Includes Sensitive Data
- NP6 Push Notification Tracking Indefinite Retention
Full analysis
BoursoBank
What This Means for You
In-app behavior, taps, and navigation patterns are collected by Heap Analytics and ContentSquare and used to analyze how users interact with the app. Adjust and Firebase track user activity across sessions. Payment interactions touch third-party services including Visa, Samsung Pay, and Google Pay.
Recommendation: Use With Caution
Best For: Everyday banking with standard analytics tradeoffs
Avoid If: You want a bank that does not share behavior data
Key Findings
Data Security - 6 findings (3 critical, 1 high, 2 medium)
Network Security - 3 findings (1 critical, 2 high)
Code Safety - 0 findings
Privacy - 2 findings (1 high, 1 medium)
Privacy Concerns
What Data is Collected
User taps, screen interactions, and in-app navigation patterns are collected by Heap Analytics and ContentSquare. Adjust and Firebase Analytics record user sessions and activity over time. Payment flow interactions pass through Visa Digital Enablement, Samsung Pay, and Google Pay. IBM Trusteer and AriadNext IDCheckIO process device and identity signals during security checks.
Third-Party Data Sharing
Behavioral data from user sessions is shared with Heap Analytics and ContentSquare for usage analysis. Adjust receives attribution and session data. Payment activity is processed by Visa, Samsung Pay, and Google Pay integrations. Identity and device data is shared with IBM Trusteer and AriadNext IDCheckIO. Google Maps and Google Play Integrity receive data during normal app use. Didomi SDK manages user consent preferences across these data flows.
Understanding the Scores
- Security Score: 45/100
- Privacy Score: 55/100
- Data Security: 35/100
- Network Security: 50/100
- Code Safety: 55/100
- Data Collection: 60/100
- Data Sharing: 70/100
- User Control: 65/100
Positive Security Features
- IBM Trusteer integration provides active fraud detection to help protect accounts from unauthorized transactions.
- AriadNext IDCheckIO adds identity verification during account-sensitive actions.
- Google Play Integrity checks confirm the app is running in an unmodified environment.
- Didomi SDK provides a consent management layer, giving users some control over data collection preferences.
Areas for Improvement
- Sensitive data stored on the device may not be fully protected, which could expose account information if the phone is accessed by someone else.
- Data sent between the app and its servers travels with less protection than expected.
- Behavioral tracking by multiple analytics platforms operates broadly, giving users limited visibility into how in-app activity is used beyond the app itself.
About This Analysis
This scorecard is based on automated static analysis of the BoursoBank Android app. Scores reflect the security and privacy posture observed at the time of the scan. Real-world risk depends on how the app is used and the user's personal threat model.
App Details
- App: BoursoBank
- Package: com.boursorama.android.clients
- Version: 7.60.5
- Platform: Android
- Scan Date: 2026-02-08
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 50/100 |