Intesa Sanpaolo Mobile Security & Privacy Scorecard
Android
User activity is shared with analytics, marketing, and behavioral tracking services including Adjust and Salesforce Marketing Cloud. Crash reports and device data are collected by third parties. User data may not be fully protected during transmission and in storage, which is a significant concern for an app that handles sensitive financial information.
Best for
Intesa Sanpaolo customers who need mobile banking
Avoid if
You use the app on shared or work-managed devices
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Complete SSL/TLS Certificate Validation Bypass
- Google Cloud Service Account Private Key Embedded in Code
- Hardcoded OAuth Credentials and Encryption Keys
Top privacy issues
- Session Tokens and Financial Data in Analytics Events
- Pre-Authentication Third-Party Data Collection
- Missing Screenshot Protection (FLAG_SECURE)
Full analysis
Intesa Sanpaolo Mobile
com.latuabancaperandroid | Version 4.0.4 (Build 25120101) | Scanned: January 31, 2026
What This Means for You
User activity is shared with analytics, marketing, and behavioral tracking services including Adjust and Salesforce Marketing Cloud. Crash reports and device data are collected by third parties. User data may not be fully protected during transmission and in storage, which is a significant concern for an app that handles sensitive financial information.
Recommendation: Unsafe
Best For: Intesa Sanpaolo customers who need mobile banking
Avoid If: You use the app on shared or work-managed devices
Key Findings
Data Security - 6 findings (2 critical, 1 high, 3 medium)
Network Security - 3 findings (1 critical, 2 high)
Code Safety - 0 findings
Privacy - 5 findings (1 critical, 1 high, 3 medium)
Privacy Concerns
What Data is Collected
Device identifiers, behavioral patterns, crash reports, and technical diagnostics about the device are collected. Multiple third-party services embedded in the app gather data about how users interact with it and the device it runs on.
Third-Party Data Sharing
User data reaches a broad set of external parties: Adjust and Salesforce Marketing Cloud receive data for advertising and marketing purposes, Tealium and Dynatrace receive behavioral and performance data, Firebase Crashlytics receives crash and device reports, and Cleafy, CA Risk Minder, Unblu, Cisco Webex, and Realm provide operational and engagement services that also receive app data.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 25/100 |
| Privacy | 30/100 |
| Data Security | 20/100 |
| Network Security | 15/100 |
| Code Safety | 35/100 |
| Data Collection | 40/100 |
| Data Sharing | 25/100 |
| User Control | 45/100 |
Positive Security Features
- The app relies on standard platform-level security without implementing notable additional protective layers.
Areas for Improvement
- Protection of financial data during transmission and in storage requires significant strengthening for an app handling sensitive banking information.
- Marketing and advertising data collection should be made optional, so users are not required to share banking activity with third-party services.
- More user-facing controls are needed so users can manage what the app collects and limit which outside parties receive their information.
About This Analysis
This scorecard is based on static analysis of the app's code and configuration. It reflects observable behaviors and settings at the time of the scan and does not capture all possible runtime behaviors.
App Details
| Field | Value |
|---|---|
| App Name | Intesa Sanpaolo Mobile |
| Package ID | com.latuabancaperandroid |
| Version | 4.0.4 (Build 25120101) |
| Scan Date | 2026-01-31 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 28/100 |