Scan results

    Instagram

    iOS

    Instagram is a social media platform for sharing photos, videos, and reels with a global community. The app enables direct messaging, stories, and personalized content discovery powered by on-device machine learning.

    CITT SCORE
    76
    out of 100
    TRUSTish

    Quick Verdict

    Best for: General use with standard privacy expectations

    What It Means For You

    Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (8)

    Data Security

    1 total
    1 Medium

    Network Security

    1 total
    1 Medium

    Code Security

    2 total
    2 Low

    Privacy

    4 total
    3 Medium
    1 Low

    Third-Party Services

    GoogleCast 4.8.3, SpotifyiOS 6.1.0, FFmpeg/libavcodec (Meta custom build), FBSharedFramework (Facebook SDK — FBSDKAppEvents, FBSDKApplicationDelegate), Stripe (embedded IAB JavaScript), Mastercard SRC (embedded IAB JavaScript), Shopify (IAB), Meta AR / FBAR, PyTorch (embedded on-device ML), sqlite-vec, FBAnalytics, MerlinLog, XDSPData, FOA

    Security Strengths

    • API traffic is protected by multi-layer certificate pinning (FBSSLPinningVerifier + SPKI-based proxygen pinner), raising the bar for interception attacks against Instagram's own communications
    • Opt-in end-to-end encrypted Direct Messages via the Instamadillo protocol with a dedicated encrypted iCloud backup container — Meta cannot read E2EE DM content even on its servers
    • On-device ML inference via embedded PyTorch — AI and recommendation features process data locally with no confirmed server egress
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    social
    ads
    location
    camera
    contacts
    sensitive data

    Package

    com.burbn.instagram

    Version

    442.0.0 (Build 1035455812 — compiled 2026-08-07)

    Analysis Date

    Aug 11, 2026

    Classes Analyzed

    101,000

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on App Store

    Recommendation: Solid

    This app has some areas that could be strengthened but rests on a solid foundation for typical use.

    Key Findings

    Data Security: 5 findings (1 medium, 2 low, 2 info)

    Network Security: 3 findings (1 medium, 1 low, 1 info)

    Code Security: 5 findings (3 low, 2 info)

    Privacy: 9 findings (3 medium, 4 low, 2 info)

    Third-Party Risk: 1 finding (1 info)

    Permission Usage: 1 finding (1 low)

    Privacy Concerns

    What Leaves the Device

    The app's store listing and in-app privacy notices carry its full disclosure of what is sent off the device.

    What Stays on the Device

    Any data the app processes only on the device stays under the user's control and is not sent off it.

    Third-Party Data Sharing

    The following third parties may receive user data:

    • GoogleCast 4.8.3
    • SpotifyiOS 6.1.0
    • FFmpeg/libavcodec (Meta custom build)
    • FBSharedFramework (Facebook SDK — FBSDKAppEvents, FBSDKApplicationDelegate)
    • Stripe (embedded IAB JavaScript)
    • Mastercard SRC (embedded IAB JavaScript)
    • Shopify (IAB)
    • Meta AR / FBAR
    • PyTorch (embedded on-device ML)
    • sqlite-vec
    • FBAnalytics
    • MerlinLog
    • XDSPData
    • FOA

    Understanding the Scores

    Security: 82/100
    Privacy: 74/100

    Security Breakdown

    • Data Security: 87/100. How the app handles stored data.
    • Network Security: 82/100. How the app handles data in transit.
    • Code Safety: 92/100. Overall code hygiene signals.

    Privacy Breakdown

    • Data Collection: 74/100. Scope of data collected.
    • Data Sharing: 85/100. Third-party data sharing behavior.
    • User Control: 74/100. Controls the app offers over personal data.

    Positive Security Features

    • API traffic is protected by multi-layer certificate pinning (FBSSLPinningVerifier + SPKI-based proxygen pinner), raising the bar for interception attacks against Instagram's own communications
    • Opt-in end-to-end encrypted Direct Messages via the Instamadillo protocol with a dedicated encrypted iCloud backup container — Meta cannot read E2EE DM content even on its servers
    • On-device ML inference via embedded PyTorch — AI and recommendation features process data locally with no confirmed server egress

    Areas for Improvement

    • The category summary above shows where the app could strengthen its practices.
    • Keeping the app on its latest version brings the newest security improvements from the developer.

    About This Analysis

    This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on mobile applications to help users make informed decisions about app security and privacy.

    App Details

    Developer: Unknown developer
    Version: 442.0.0 (Build 1035455812 — compiled 2026-08-07)
    Analysis Date: 2026-08-11
    Package: com.burbn.instagram

    Analyzed 2026-08-11 · ruleset citt-ruleset-2026-08-v1 · artifact binary not retained

    Right of Reply

    Developer not yet contacted