Scan results

    Intesa Sanpaolo Mobile

    Android

    Intesa Sanpaolo Mobile is an everyday banking app that lets you consult accounts and cards, make payments, manage credit/debit/prepaid cards, and exchange money in real time. Accessible to anyone with a mobile phone.

    CITT SCORE
    28
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: Intesa Sanpaolo customers who need mobile banking

    Not For: You use the app on shared or work-managed devices

    What It Means For You

    User activity is shared with analytics, marketing, and behavioral tracking services including Adjust and Salesforce Marketing Cloud. Crash reports and device data are collected by third parties. User data may not be fully protected during transmission and in storage, which is a significant concern for an app that handles sensitive financial information.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (19)

    Data Security

    6 total
    2 Critical
    1 High
    3 Medium

    Network Security

    3 total
    1 Critical
    2 High

    Code Security

    4 total
    1 Critical
    1 High
    1 Medium
    1 Low

    Privacy

    5 total
    1 Critical
    1 High
    3 Medium

    Third-Party Risk

    1 total
    1 Low

    Third-Party Services

    Tealium, Dynatrace, Salesforce Marketing Cloud, Firebase Crashlytics, Cleafy, CA Risk Minder, Unblu, Cisco Webex, Adjust, Realm

    Security Strengths

    • AES-256-GCM encryption with hardware-backed AndroidKeystore
    • Certificate pinning for primary banking APIs
    • SQL injection prevention through ORM usage
    • Code obfuscation and secure build configuration
    • Secure session token storage in volatile memory vault
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    banking
    location
    camera
    ads

    Package

    com.latuabancaperandroid

    Version

    4.0.4 (Build 25120101)

    Analysis Date

    Jan 31, 2026

    Classes Analyzed

    91,686

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Unsafe

    Key Findings

    Data Security - 6 findings (2 critical, 1 high, 3 medium)

    Network Security - 3 findings (1 critical, 2 high)

    Code Safety - 0 findings

    Privacy - 5 findings (1 critical, 1 high, 3 medium)

    Privacy Concerns

    What Data is Collected

    Device identifiers, behavioral patterns, crash reports, and technical diagnostics about the device are collected. Multiple third-party services embedded in the app gather data about how users interact with it and the device it runs on.

    Third-Party Data Sharing

    User data reaches a broad set of external parties: Adjust and Salesforce Marketing Cloud receive data for advertising and marketing purposes, Tealium and Dynatrace receive behavioral and performance data, Firebase Crashlytics receives crash and device reports, and Cleafy, CA Risk Minder, Unblu, Cisco Webex, and Realm provide operational and engagement services that also receive app data.

    Understanding the Scores

    CategoryScore
    Security25/100
    Privacy30/100
    Data Security20/100
    Network Security15/100
    Code Safety35/100
    Data Collection40/100
    Data Sharing25/100
    User Control45/100

    Positive Security Features

    • The app relies on standard platform-level security without implementing notable additional protective layers.

    Areas for Improvement

    • Protection of financial data during transmission and in storage requires significant strengthening for an app handling sensitive banking information.
    • Marketing and advertising data collection should be made optional, so users are not required to share banking activity with third-party services.
    • More user-facing controls are needed so users can manage what the app collects and limit which outside parties receive their information.

    About This Analysis

    This scorecard is based on static analysis of the app's code and configuration. It reflects observable behaviors and settings at the time of the scan and does not capture all possible runtime behaviors.

    App Details

    FieldValue
    App NameIntesa Sanpaolo Mobile
    Package IDcom.latuabancaperandroid
    Version4.0.4 (Build 25120101)
    Scan Date2026-01-31

    Right of Reply

    Developer not yet contacted