Scotiabank's mobile banking app enables secure account management with budgeting tools, mobile cheque deposit, 2-step verification, and accessibility features. It offers personalized financial insights, rewards redemption, credit monitoring, and advisor access with data encryption for transaction se
Quick Verdict
Best for: Scotiabank customers banking on the go
What It Means For You
Device behavior and session activity is analyzed by fraud-detection services to verify identity. Adobe and Firebase collect usage data, and interactions are monitored to personalize the in-app experience. Integrated third parties include Interac, Western Union, and TransUnion for financial features.
Quick Verdict
Best for: Scotiabank customers banking on the go
What It Means For You
Device behavior and session activity is analyzed by fraud-detection services to verify identity. Adobe and Firebase collect usage data, and interactions are monitored to personalize the in-app experience. Integrated third parties include Interac, Western Union, and TransUnion for financial features.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Network Security
2 totalCode Security
4 totalPrivacy
3 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.scotiabank.banking
Version
2508.0.0 (versionCode: 212)
Analysis Date
Feb 16, 2026
Classes Analyzed
45,939
Feedback helps us improve our analysis
Data Security - 0 findings
Network Security - 2 findings (2 info)
Code Safety - 0 findings
Privacy - 3 findings (1 high, 1 medium, 1 low)
The app collects behavioral signals from the device, including touch patterns, typing rhythm, and session timing, to support fraud detection and identity verification. Usage analytics are gathered by Adobe Experience Cloud and Firebase, covering screens visited, features used, and session duration. Device identifiers and interaction history may also be retained to personalize the in-app experience.
BioCatch and ThreatMetrix receive behavioral and device signals to assess fraud risk during sessions. Adobe Experience Cloud and Firebase receive usage and interaction data for analytics and personalization. Acuant and Top Image Systems receive document images to support identity verification flows. Western Union, Interac, and TransUnion receive financial data to facilitate transfers, payments, and credit-related features. Scene+ and Personetics receive transaction and preference data to support rewards and financial insights. OneTrust is used for consent and privacy preference management.
| Category | Score |
|---|---|
| Security | 82/100 |
| Privacy | 78/100 |
| Data Security | 85/100 |
| Network Security | 98/100 |
| Code Safety | 80/100 |
| Data Collection | 75/100 |
| Data Sharing | 90/100 |
| User Control | 82/100 |
This scorecard is produced through automated analysis of the app's code and configuration. Scores and findings reflect the security and privacy posture of the version examined and may change as the app is updated.
Developer not yet contacted