Jenius Security & Privacy Scorecard

by PT. Bank SMBC Indonesia Tbk · iOS

86
Overall trust score
Trustworthy
84
Security
89
Privacy

Usage and behavioral data is shared with AppsFlyer, Google Analytics, MoEngage, and Firebase for analytics, attribution, and messaging. Transaction and device activity also flows to NewRelic for performance monitoring. Identity verification is handled via ZOLOZ KYC, and three specialized services monitor for fraud.

Best for

Everyday digital banking with standard analytics

Findings

  • 0 critical
  • 0 high
  • 6 medium
  • 7 low
  • 9 info

0 issues identified across security and privacy analysis.

Top security issues

  • Seciron RASP Keys Hardcoded in Production IPA
  • Alipay ZLZ WebContainerLite JS Bridge Exposes Sensitive Device APIs
  • No SQLite Encryption — No SQLCipher Evidence

Top privacy issues

  • Developer Privacy Manifest Declares Zero Data Collection Despite Active Analytics Stack
  • GIBMobileSdk Vendor Manifest Declares Biometric and Precise Location Data Collection
  • External IP Lookup via Uncontrolled Third-Party Service (api.ipify.org)

Full analysis

Jenius

What This Means for You

Your identity and banking access are protected by Face ID and hardware-backed security, and your banking traffic is strongly encrypted in transit.

Recommendation: Trustworthy

Jenius implements multiple layers of protection for your banking data, including hardware-bound biometric authentication and device integrity verification. The app's analytics and tracking disclosure in the App Store privacy label does not fully reflect the active attribution and engagement services included. Trustworthy for everyday digital banking.

Best For: Users who want a full-featured digital banking experience with strong biometric security.

Key Findings

Data Security - 4 findings (4 medium)

Network Security - 2 findings (2 low)

Code Safety - 4 findings (1 medium, 3 low)

Privacy - 7 findings (1 medium, 2 low, 4 info)

Privacy Concerns

What Data is Collected

  • Account and identity information: shared with Jenius servers to operate your account.
  • Device identifiers and external IP address: sent to Seciron fraud detection services and a third-party IP lookup service for fraud prevention.
  • App usage and engagement behavior: sent to MoEngage for push notifications and in-app messaging.
  • Install attribution data: sent to AppsFlyer to measure marketing effectiveness.
  • Biometric and location data: accessed on your device by the Group-IB fraud detection system and may be sent to its servers for anti-fraud analysis.
  • Crash and performance data: sent to NewRelic and Firebase Crashlytics.

Third-Party Data Sharing

The following third parties may receive your data:

  • AppsFlyer - marketing attribution and install tracking
  • MoEngage - push notifications and engagement analytics
  • Group-IB (GIBMobileSdk) - fraud detection including biometric and location data
  • NewRelic - app performance monitoring
  • Firebase Crashlytics - crash reporting
  • Firebase Messaging - push notifications
  • Seciron IROSWall / RiskManage - fraud prevention and device risk assessment
  • api.ipify.org - external IP address lookup for fraud prevention
  • TrustKit (Data Theorem) - network security monitoring
  • Alipay mPaaS / ZOLOZ - payment processing and identity verification

Understanding the Scores

Security: 84/100
Privacy: 89/100

Security Breakdown

  • Data Security: 83/100 - Strong biometric-protected login key storage and encrypted network traffic, with some on-device files that may benefit from additional protection on lost or stolen devices.
  • Network Security: 96/100 - Excellent network protection with multiple layers of encryption enforcement and strong server verification across all primary banking connections.
  • Code Safety: 91/100 - Solid application security with a modern sandboxed web view and layered hardware device integrity verification.

Privacy Breakdown

  • Data Collection: 87/100 - Data collected serves banking operations, fraud prevention, and marketing; the full scope of collection is not fully reflected in the App Store privacy label.
  • Data Sharing: 94/100 - Data sharing is largely limited to banking operations, fraud prevention, and standard app services.
  • User Control: 92/100 - Standard banking consent flows with tracking transparency infrastructure in place for marketing attribution.

Positive Security Features

  • Multiple layers of network encryption with three backup public keys and independent violation reporting on the primary banking backend.
  • Secure connections fully enforced with no cleartext exceptions across standard networking channels.
  • Modern, sandboxed web view used exclusively throughout the app, with no deprecated alternatives present.
  • Biometric-protected login key storage using Face ID and hardware-backed key protection.
  • Hardware device integrity verification combined with three independent fraud detection systems.

Areas for Improvement

GDPR / CCPA Compliance

The app's privacy practices could be strengthened by:

  1. App Store Privacy Disclosure Accuracy
    The App Store privacy label currently declares no data collection, but the app includes active attribution, engagement, and fraud detection services that send data off-device. Updating this disclosure would improve regulatory compliance and user trust.

  2. App Privacy Manifest Completeness
    Adding a comprehensive app privacy manifest could make the App Store privacy label more complete and consistent with the data processing performed by bundled third-party frameworks.

Security Enhancements

  1. Security SDK Key Management
    Embedded security service configuration keys in the production build are extractable by anyone who downloads the app. Moving these to server-delivered configuration would reduce exposure.

  2. On-Device File Protection
    Reviewing which files are stored without full device-lock protection would reduce risk on lost or stolen devices. Ensuring financial documents are not accessible through the built-in Files app would reduce exposure on shared or unattended devices.

  3. Local Database Encryption
    Applying encryption to locally stored app data would protect account and transaction records from unencrypted device backups.

Technical Context

App Type: Mobile banking app, high-sensitivity financial data
Classes Analyzed: 0 (symbol and string analysis only; main binary source was not reconstructed)
Third-Party Services: 12 third-party services identified
Context Tags: financial, sensitive_data, camera, location, biometric


About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on iOS applications to help users make informed decisions about app security and privacy.

App Details

Developer: BTPN (Bank Tabungan Pensiunan Nasional)
Version: 4.75.1 (build 9280)
Analysis Date: 2026-06-17
Package: com.btpn.jenius.dc

Analysis Limitations

  • Static analysis only (code review without running the app)
  • Based on IPA version 4.75.1 analyzed on 2026-06-17
  • May not reflect server-side security controls
  • Cannot detect all runtime behaviors

Versions & scan history

ScanDateOverall score
#6 (current) 86/100
#5 72/100