Intesa Sanpaolo Mobile Security & Privacy Scorecard

Android

28
Overall trust score
Don't Trust
25
Security
30
Privacy

User activity is shared with analytics, marketing, and behavioral tracking services including Adjust and Salesforce Marketing Cloud. Crash reports and device data are collected by third parties. User data may not be fully protected during transmission and in storage, which is a significant concern for an app that handles sensitive financial information.

Best for

Intesa Sanpaolo customers who need mobile banking

Avoid if

You use the app on shared or work-managed devices

Findings

  • 0 critical
  • 0 high
  • 0 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Complete SSL/TLS Certificate Validation Bypass
  • Google Cloud Service Account Private Key Embedded in Code
  • Hardcoded OAuth Credentials and Encryption Keys

Top privacy issues

  • Session Tokens and Financial Data in Analytics Events
  • Pre-Authentication Third-Party Data Collection
  • Missing Screenshot Protection (FLAG_SECURE)

Full analysis

Intesa Sanpaolo Mobile

com.latuabancaperandroid | Version 4.0.4 (Build 25120101) | Scanned: January 31, 2026

What This Means for You

User activity is shared with analytics, marketing, and behavioral tracking services including Adjust and Salesforce Marketing Cloud. Crash reports and device data are collected by third parties. User data may not be fully protected during transmission and in storage, which is a significant concern for an app that handles sensitive financial information.

Recommendation: Unsafe

Best For: Intesa Sanpaolo customers who need mobile banking
Avoid If: You use the app on shared or work-managed devices

Key Findings

Data Security - 6 findings (2 critical, 1 high, 3 medium)

Network Security - 3 findings (1 critical, 2 high)

Code Safety - 0 findings

Privacy - 5 findings (1 critical, 1 high, 3 medium)

Privacy Concerns

What Data is Collected

Device identifiers, behavioral patterns, crash reports, and technical diagnostics about the device are collected. Multiple third-party services embedded in the app gather data about how users interact with it and the device it runs on.

Third-Party Data Sharing

User data reaches a broad set of external parties: Adjust and Salesforce Marketing Cloud receive data for advertising and marketing purposes, Tealium and Dynatrace receive behavioral and performance data, Firebase Crashlytics receives crash and device reports, and Cleafy, CA Risk Minder, Unblu, Cisco Webex, and Realm provide operational and engagement services that also receive app data.

Understanding the Scores

Category Score
Security 25/100
Privacy 30/100
Data Security 20/100
Network Security 15/100
Code Safety 35/100
Data Collection 40/100
Data Sharing 25/100
User Control 45/100

Positive Security Features

  • The app relies on standard platform-level security without implementing notable additional protective layers.

Areas for Improvement

  • Protection of financial data during transmission and in storage requires significant strengthening for an app handling sensitive banking information.
  • Marketing and advertising data collection should be made optional, so users are not required to share banking activity with third-party services.
  • More user-facing controls are needed so users can manage what the app collects and limit which outside parties receive their information.

About This Analysis

This scorecard is based on static analysis of the app's code and configuration. It reflects observable behaviors and settings at the time of the scan and does not capture all possible runtime behaviors.

App Details

Field Value
App Name Intesa Sanpaolo Mobile
Package ID com.latuabancaperandroid
Version 4.0.4 (Build 25120101)
Scan Date 2026-01-31

Versions & scan history

ScanDateOverall score
#1 (current) 28/100