Salesforce Security & Privacy Scorecard
Android
Device details and app crash data are automatically shared with Bugsnag's crash reporting service, and push notifications route through Google Firebase. The app leaves some data protections short of expectations, which could leave work communications and business data less protected than expected, making it a higher risk on personal or unmanaged devices.
Best for
Business teams on managed corporate devices
Avoid if
Users storing sensitive work data on personal devices
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Universal File Access Enabled in WebView
- Mixed Content Mode Set to ALWAYS_ALLOW
- Chuck HTTP Inspector Active in Production Build
Top privacy issues
- Device ID Collected Without Explicit Consent
- Unencrypted SharedPreferences Store 94 Feature Flags and Security Policies
- Analytics Opt-Out Does Not Delete Existing Events
Full analysis
Salesforce
Version: 254.000.0 (Build 254000055)
Scan Date: 2026-02-03
What This Means for You
Device details and app crash data are automatically shared with Bugsnag's crash reporting service, and push notifications route through Google Firebase. The app leaves some data protections short of expectations, which could leave work communications and business data less protected than expected, making it a higher risk on personal or unmanaged devices.
Recommendation: Use With Caution
Best For: Business teams on managed corporate devices
Avoid If: Users storing sensitive work data on personal devices
Key Findings
Data Security - 5 findings (1 high, 3 medium, 1 low)
Network Security - 5 findings (1 critical, 1 high, 3 medium)
Code Safety - 0 findings
Privacy - 5 findings (1 high, 3 medium, 1 info)
Privacy Concerns
What Data is Collected
The app collects device information and crash data to support diagnostics. Features including barcode scanning, text recognition, document scanning, and entity extraction process content directly on the device via Google ML Kit.
Third-Party Data Sharing
| Service | Purpose |
|---|---|
| Bugsnag | Crash reporting - receives device details and error logs |
| Firebase Cloud Messaging | Delivers push notifications to the device |
| ML Kit (Barcode, Text Recognition, Document Scanner, Entity Extraction) | On-device feature processing |
| Google Play Services | Core platform services |
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 55/100 |
| Data Security | 60/100 |
| Network Security | 40/100 |
| Code Safety | 30/100 |
| Data Collection | 70/100 |
| Data Sharing | 85/100 |
| User Control | 65/100 |
Positive Security Features
- ML Kit features (barcode scanning, text recognition, document scanning, entity extraction) process data directly on the device rather than transmitting it to external servers.
- Push notifications are routed through Google Firebase, a widely maintained and regularly updated platform.
Areas for Improvement
- Network communication protections need strengthening to better guard business data as it travels between the app and its servers.
- Data storage and handling practices should be tightened to reduce the risk of sensitive work information being exposed on the device.
- Greater transparency and user control over data collection and sharing practices would better protect user privacy.
About This Analysis
This report is based on automated static analysis of the app's published code and configuration.
App Details
- App: Salesforce
- Package: com.salesforce.chatter
- Version: 254.000.0 (Build 254000055)
- Scan Date: 2026-02-03
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 45/100 |