DaviPlata Security & Privacy Scorecard
Android
Activity, device details, and usage patterns are shared with advertising and analytics companies including Google Ads, Braze, AppsFlyer, and Firebase. The protections around financial data and network communications may not fully meet modern standards for a banking application, and user data may not be fully protected.
Best for
DaviPlata customers comfortable with analytics
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Hostname Verification Disabled
- Hardcoded AES Encryption Key
- WebView Universal File Access Enabled
Top privacy issues
- Comprehensive User Profiling Without Visible Consent
- Session Recording Captures Sensitive Financial Data
- Biometric Data Sent to Third-Party Cloud
Full analysis
DaviPlata
com.davivienda.daviplataapp | Version Android7.1.0 (Build 1501) | Scanned 2026-02-04
What This Means for Users
Activity, device details, and usage patterns are shared with advertising and analytics companies including Google Ads, Braze, AppsFlyer, and Firebase. The protections around financial data and network communications may not fully meet modern standards for a banking application, and user data may not be fully protected.
Recommendation: Use With Caution
Best For: DaviPlata customers comfortable with analytics
Key Findings
Data Security - 3 findings (2 critical, 1 high)
Network Security - 3 findings (1 critical, 1 high, 1 medium)
Code Safety - 0 findings
Privacy - 6 findings (4 high, 2 medium)
Privacy Concerns
What Data is Collected
DaviPlata collects device identifiers, behavioral patterns, and usage activity. This includes information about how users navigate the app, device technical details, and in-app actions over time.
Third-Party Data Sharing
User data is shared with the following third-party companies:
- Google Ads - Advertising targeting
- Braze - Marketing and user engagement
- AppsFlyer - Attribution and analytics
- Firebase Analytics - Usage analytics
- Dynatrace - Performance monitoring
- Instana - Application monitoring
- Statsig - Feature experimentation
- Incode - Identity verification
- TransmitSecurity - Authentication services
- Antelop - Security services
- Valid SDK - Banking security services
- Google Play Integrity - Device integrity checks
Understanding the Scores
| Area | Score |
|---|---|
| Security | 25/100 |
| Privacy | 35/100 |
| Data Security | 20/100 |
| Network Security | 15/100 |
| Code Safety | 30/100 |
| Data Collection | 40/100 |
| Data Sharing | 35/100 |
| User Control | 45/100 |
Positive Security Features
- No standout positive security practices were identified in this version of the app.
Areas for Improvement
- The protections around how financial data is stored and handled need significant strengthening to meet modern standards for a banking application.
- The app's network communications provide less protection than expected for a banking application, and user account information may not be fully protected in transit.
- The number of advertising and analytics companies with access to user usage data is high relative to what is needed for the app's core financial functions.
About This Analysis
This scorecard is generated through automated static analysis of the app's code and configuration. Scores reflect the security and privacy posture observed at the time of the scan.
App Details
- App Name: DaviPlata
- Package ID: com.davivienda.daviplataapp
- Version: Android7.1.0 (Build 1501)
- Scan Date: 2026-02-04
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 30/100 |