Jenius Security & Privacy Scorecard
by PT. Bank SMBC Indonesia Tbk · iOS
Usage and behavioral data is shared with AppsFlyer, Google Analytics, MoEngage, and Firebase for analytics, attribution, and messaging. Transaction and device activity also flows to NewRelic for performance monitoring. Identity verification is handled via ZOLOZ KYC, and three specialized services monitor for fraud.
Best for
Everyday digital banking with standard analytics
Findings
- 0 critical
- 0 high
- 6 medium
- 7 low
- 9 info
0 issues identified across security and privacy analysis.
Top security issues
- Seciron RASP Keys Hardcoded in Production IPA
- Alipay ZLZ WebContainerLite JS Bridge Exposes Sensitive Device APIs
- No SQLite Encryption — No SQLCipher Evidence
Top privacy issues
- Developer Privacy Manifest Declares Zero Data Collection Despite Active Analytics Stack
- GIBMobileSdk Vendor Manifest Declares Biometric and Precise Location Data Collection
- External IP Lookup via Uncontrolled Third-Party Service (api.ipify.org)
Full analysis
Jenius
What This Means for You
Your identity and banking access are protected by Face ID and hardware-backed security, and your banking traffic is strongly encrypted in transit.
Recommendation: Trustworthy
Jenius implements multiple layers of protection for your banking data, including hardware-bound biometric authentication and device integrity verification. The app's analytics and tracking disclosure in the App Store privacy label does not fully reflect the active attribution and engagement services included. Trustworthy for everyday digital banking.
Best For: Users who want a full-featured digital banking experience with strong biometric security.
Key Findings
Data Security - 4 findings (4 medium)
Network Security - 2 findings (2 low)
Code Safety - 4 findings (1 medium, 3 low)
Privacy - 7 findings (1 medium, 2 low, 4 info)
Privacy Concerns
What Data is Collected
- Account and identity information: shared with Jenius servers to operate your account.
- Device identifiers and external IP address: sent to Seciron fraud detection services and a third-party IP lookup service for fraud prevention.
- App usage and engagement behavior: sent to MoEngage for push notifications and in-app messaging.
- Install attribution data: sent to AppsFlyer to measure marketing effectiveness.
- Biometric and location data: accessed on your device by the Group-IB fraud detection system and may be sent to its servers for anti-fraud analysis.
- Crash and performance data: sent to NewRelic and Firebase Crashlytics.
Third-Party Data Sharing
The following third parties may receive your data:
- AppsFlyer - marketing attribution and install tracking
- MoEngage - push notifications and engagement analytics
- Group-IB (GIBMobileSdk) - fraud detection including biometric and location data
- NewRelic - app performance monitoring
- Firebase Crashlytics - crash reporting
- Firebase Messaging - push notifications
- Seciron IROSWall / RiskManage - fraud prevention and device risk assessment
- api.ipify.org - external IP address lookup for fraud prevention
- TrustKit (Data Theorem) - network security monitoring
- Alipay mPaaS / ZOLOZ - payment processing and identity verification
Understanding the Scores
Security: 84/100
Privacy: 89/100
Security Breakdown
- Data Security: 83/100 - Strong biometric-protected login key storage and encrypted network traffic, with some on-device files that may benefit from additional protection on lost or stolen devices.
- Network Security: 96/100 - Excellent network protection with multiple layers of encryption enforcement and strong server verification across all primary banking connections.
- Code Safety: 91/100 - Solid application security with a modern sandboxed web view and layered hardware device integrity verification.
Privacy Breakdown
- Data Collection: 87/100 - Data collected serves banking operations, fraud prevention, and marketing; the full scope of collection is not fully reflected in the App Store privacy label.
- Data Sharing: 94/100 - Data sharing is largely limited to banking operations, fraud prevention, and standard app services.
- User Control: 92/100 - Standard banking consent flows with tracking transparency infrastructure in place for marketing attribution.
Positive Security Features
- Multiple layers of network encryption with three backup public keys and independent violation reporting on the primary banking backend.
- Secure connections fully enforced with no cleartext exceptions across standard networking channels.
- Modern, sandboxed web view used exclusively throughout the app, with no deprecated alternatives present.
- Biometric-protected login key storage using Face ID and hardware-backed key protection.
- Hardware device integrity verification combined with three independent fraud detection systems.
Areas for Improvement
GDPR / CCPA Compliance
The app's privacy practices could be strengthened by:
App Store Privacy Disclosure Accuracy
The App Store privacy label currently declares no data collection, but the app includes active attribution, engagement, and fraud detection services that send data off-device. Updating this disclosure would improve regulatory compliance and user trust.App Privacy Manifest Completeness
Adding a comprehensive app privacy manifest could make the App Store privacy label more complete and consistent with the data processing performed by bundled third-party frameworks.
Security Enhancements
Security SDK Key Management
Embedded security service configuration keys in the production build are extractable by anyone who downloads the app. Moving these to server-delivered configuration would reduce exposure.On-Device File Protection
Reviewing which files are stored without full device-lock protection would reduce risk on lost or stolen devices. Ensuring financial documents are not accessible through the built-in Files app would reduce exposure on shared or unattended devices.Local Database Encryption
Applying encryption to locally stored app data would protect account and transaction records from unencrypted device backups.
Technical Context
App Type: Mobile banking app, high-sensitivity financial data
Classes Analyzed: 0 (symbol and string analysis only; main binary source was not reconstructed)
Third-Party Services: 12 third-party services identified
Context Tags: financial, sensitive_data, camera, location, biometric
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on iOS applications to help users make informed decisions about app security and privacy.
App Details
Developer: BTPN (Bank Tabungan Pensiunan Nasional)
Version: 4.75.1 (build 9280)
Analysis Date: 2026-06-17
Package: com.btpn.jenius.dc
Analysis Limitations
- Static analysis only (code review without running the app)
- Based on IPA version 4.75.1 analyzed on 2026-06-17
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #6 (current) | 86/100 | |
| #5 | 72/100 |