DaviPlata Security & Privacy Scorecard

Android

30
Overall trust score
Don't Trust
25
Security
35
Privacy

Activity, device details, and usage patterns are shared with advertising and analytics companies including Google Ads, Braze, AppsFlyer, and Firebase. The protections around financial data and network communications may not fully meet modern standards for a banking application, and user data may not be fully protected.

Best for

DaviPlata customers comfortable with analytics

Findings

  • 0 critical
  • 0 high
  • 0 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Hostname Verification Disabled
  • Hardcoded AES Encryption Key
  • WebView Universal File Access Enabled

Top privacy issues

  • Comprehensive User Profiling Without Visible Consent
  • Session Recording Captures Sensitive Financial Data
  • Biometric Data Sent to Third-Party Cloud

Full analysis

DaviPlata

com.davivienda.daviplataapp | Version Android7.1.0 (Build 1501) | Scanned 2026-02-04

What This Means for Users

Activity, device details, and usage patterns are shared with advertising and analytics companies including Google Ads, Braze, AppsFlyer, and Firebase. The protections around financial data and network communications may not fully meet modern standards for a banking application, and user data may not be fully protected.

Recommendation: Use With Caution

Best For: DaviPlata customers comfortable with analytics

Key Findings

Data Security - 3 findings (2 critical, 1 high)

Network Security - 3 findings (1 critical, 1 high, 1 medium)

Code Safety - 0 findings

Privacy - 6 findings (4 high, 2 medium)

Privacy Concerns

What Data is Collected

DaviPlata collects device identifiers, behavioral patterns, and usage activity. This includes information about how users navigate the app, device technical details, and in-app actions over time.

Third-Party Data Sharing

User data is shared with the following third-party companies:

  • Google Ads - Advertising targeting
  • Braze - Marketing and user engagement
  • AppsFlyer - Attribution and analytics
  • Firebase Analytics - Usage analytics
  • Dynatrace - Performance monitoring
  • Instana - Application monitoring
  • Statsig - Feature experimentation
  • Incode - Identity verification
  • TransmitSecurity - Authentication services
  • Antelop - Security services
  • Valid SDK - Banking security services
  • Google Play Integrity - Device integrity checks

Understanding the Scores

Area Score
Security 25/100
Privacy 35/100
Data Security 20/100
Network Security 15/100
Code Safety 30/100
Data Collection 40/100
Data Sharing 35/100
User Control 45/100

Positive Security Features

  • No standout positive security practices were identified in this version of the app.

Areas for Improvement

  • The protections around how financial data is stored and handled need significant strengthening to meet modern standards for a banking application.
  • The app's network communications provide less protection than expected for a banking application, and user account information may not be fully protected in transit.
  • The number of advertising and analytics companies with access to user usage data is high relative to what is needed for the app's core financial functions.

About This Analysis

This scorecard is generated through automated static analysis of the app's code and configuration. Scores reflect the security and privacy posture observed at the time of the scan.

App Details

  • App Name: DaviPlata
  • Package ID: com.davivienda.daviplataapp
  • Version: Android7.1.0 (Build 1501)
  • Scan Date: 2026-02-04

Versions & scan history

ScanDateOverall score
#2 (current) 30/100