Kia Access Security & Privacy Scorecard

Android

78
Overall trust score
Acceptable
74
Security
89
Privacy

Standard usage and device data may be shared with the app developer and integrated services. The breakdown below lists the data types and third parties involved.

Best for

General use with standard privacy expectations

Findings

  • 0 critical
  • 4 high
  • 10 medium
  • 7 low
  • 3 info

3 issues identified across security and privacy analysis.

Top security issues

  • Proprietary Kia Backend API Tokens Hardcoded in Native Binary
  • Exported Activities Without Permission Protection — Connected Car Functions
  • Engineering Debug Screen with SSL Bypass Option Shipped in Production APK

Top privacy issues

  • Driving Behavior Data Shared with LexisNexis Risk Solutions Without Full Disclosure of Downstream Use
  • Firebase Analytics and Crashlytics Auto-Initialize Before User Consent
  • Advertising ID and Attribution Permissions Without Advertising Purpose

Full analysis

<!-- TRUSTEDVERDICTHEADER -->

Did not meet TRUSTED criteria

The app was assessed and did not meet all of the criteria for the TRUSTED mark. The specific items are listed below so the result can be weighed before installing.

Trust Pillars

  • Secure by Design: Not met. Did not meet one criterion in this area.
  • Data Respect: Not met. Did not meet one criterion in this area.
  • Honest Experience: Not met. Did not meet one criterion in this area.
  • User Control: Strong. Strong result in this area.
  • Child-Safe: Not applicable. Does not apply to this app.

<!-- /TRUSTEDVERDICTHEADER -->

Security & Privacy Scorecard

Kia Access

What This Means for You

Usage analytics, crash reports, and advertising identifiers are sent to Google Firebase and Google Ad Services, while the optional driving score program shares detailed driving behavior records with LexisNexis Risk Solutions for potential disclosure to unnamed insurance providers. Backend service access codes are stored inside the app in a readable form that can be extracted from any publicly downloaded copy.

Recommendation: Solid

Kia Access offers solid remote vehicle control with meaningful security practices, including advanced connection verification for vehicle commands and device attestation through Google Play Integrity. The most significant concern is that backend service access codes are embedded in the app binary in a readable form, potentially allowing unauthorized access to Kia's vehicle API. The optional driving score program also shares behavior data with insurance data broker LexisNexis Risk Solutions, with limited disclosure of which specific insurance providers may receive that data downstream.

Best For: Kia owners who need remote vehicle access and are comfortable with analytics, advertising, and optional driving behavior data sharing with insurance data brokers.

Key Findings

Data Security - 4 findings (1 high, 2 medium, 1 low)

Network Security - 2 findings (1 medium, 1 low)

Code Safety - 6 findings (1 high, 3 medium, 2 low)

Privacy - 3 findings (1 medium, 2 low)

Privacy Concerns

What Data is Collected

  • Account information (name, email address): shared with Kia servers to support connected vehicle services
  • Location data (precise GPS): shared with Kia servers for the remote locate and navigation send features
  • Driving behavior records (hard braking, highway speed, annual mileage): shared with LexisNexis Risk Solutions when the optional driving score program is enabled
  • Calendar events: accessed on the device; may be used for appointment-based vehicle pre-conditioning scheduling
  • Usage data: shared with Firebase Analytics
  • Crash and device information: shared with Firebase Crashlytics
  • Performance and interaction telemetry: may be shared with Dynatrace depending on its monitoring configuration
  • Advertising identifiers: shared with Google Ad Services

Third-Party Data Sharing

Third parties that may receive data from the app:

  • Firebase (Google) - analytics, crash reporting, and performance monitoring
  • Google Ad Services - advertising
  • LexisNexis Risk Solutions - driving behavior data via the optional driving score program
  • Dynatrace - performance and interaction telemetry
  • HERE Maps - mapping and location services
  • SiriusXM - media streaming integration
  • myQ Connected Garage - smart garage door integration

Understanding the Scores

Security: 74/100
Privacy: 89/100

Security Breakdown

  • Data Security: 78/100. Device backup protection prevents unauthorized extraction of stored data. Backend service access codes are embedded in the app binary in a form that can be read by anyone who downloads the app.
  • Network Security: 91/100. Vehicle commands are transmitted using strongly verified, encrypted connections that prevent network interception.
  • Code Safety: 82/100. The app employs code protection and device attestation. Some internal screen components and development domain registrations remain present in the production build.

Privacy Breakdown

  • Data Collection: 89/100. Data collection aligns with the app's connected vehicle purpose, with account information, location, and usage data tied to remote vehicle control features.
  • Data Sharing: 87/100. Most data sharing is limited to infrastructure partners including analytics, crash reporting, and mapping. The optional driving score program shares driving behavior data with LexisNexis Risk Solutions, with limited visibility into downstream sharing with unnamed insurance providers.
  • User Control: 92/100. Users retain strong control over their data, with explicit consent required before GPS trip recording begins and options to request data deletion.

Positive Security Features

  • Vehicle command traffic is sent over strongly verified, encrypted connections that prevent network interception by third parties
  • Google Play Integrity is used to verify that the app and device have not been tampered with before executing remote vehicle commands
  • Location tracking and GPS trip recording require explicit user consent, with a documented opt-out flow
  • App backup extraction is blocked, preventing account data from being copied via standard device backup tools

Areas for Improvement

GDPR / CCPA Compliance

The app's privacy practices could be strengthened by:

  1. Driving Data Broker Disclosure
    The optional driving score program discloses sharing with LexisNexis Risk Solutions but does not name the specific insurance providers that may receive driving behavior data downstream. Naming those providers and confirming opt-out rights for California users would improve transparency under CPRA requirements for sensitive data categories including location and driving behavior.

  2. Calendar Permission Disclosure
    The app requests read and write access to calendar events. Clarifying in the privacy policy exactly what calendar data is accessed, whether any of it is sent off the device, and how long it is retained would give users a clearer picture of how this data is used.

Security Enhancements

  1. Remove Backend Service Access Codes from the App Binary
    Production and staging backend service access codes are embedded in the app binary in a readable form. Moving these to a server-side configuration system would prevent unauthorized access to Kia's vehicle API if the app is downloaded and analyzed.

  2. Remove Development Artifacts from Production Builds
    A full engineering screen with environment switching, connection security overrides, and mock modes is present in the production app. Removing these components before release would reduce the risk of misuse on modified devices.

  3. Restrict Exported Vehicle-Related Screen Components
    Several screen components related to garage door control, digital store, and SiriusXM subscriptions are accessible to other apps installed on the same device without any permission requirement. Adding permission restrictions to these components would prevent unintended access from co-installed apps.

Technical Context

App Type: Connected vehicle control - sensitive (location, financial, vehicle access)
Classes Analyzed: 2,053
Third-Party Services: 28 identified
Context Tags: location, financial, sensitive_data, ads


About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. The analysis is static code review of Android applications, intended to help people make informed decisions about app security and privacy.

App Details

Developer: Kia America, Inc.
Version: 7.29.0 (versionCode 10700)
Analysis Date: 2026-07-22
Package: com.myuvo.link

Analysis Limitations

  • Static analysis only (code review without running the app)
  • Based on APK version 7.29.0 analyzed on 2026-07-22
  • May not reflect server-side security controls
  • Cannot detect all runtime behaviors

Versions & scan history

ScanDateOverall score
#8 (current) 78/100
#6 81/100
#5 78/100
#4 70/100
#3 77/100
#2 85/100
#1 71/100