iVerify EDR Security & Privacy Scorecard
by iVerify · iOS
Device data stays private, with no advertising networks or data brokers involved. Diagnostic telemetry is sent to Datadog and Firebase to keep the service running, but personal information is not shared with third parties for marketing. Users are in control of their data.
Best for
Enterprise users who prioritize device security
Findings
- 0 critical
- 2 high
- 2 medium
- 0 low
- 12 info
3 issues identified across security and privacy analysis.
Top security issues
- Embedded prompt injection attempt detected
- Sensitive Diagnostic Data Not Excluded from Backups
- No Explicit File Protection for Diagnostic Data
Top privacy issues
- Firebase Analytics and AdMob Explicitly Disabled
- No IDFA Collection (Advertising Identifier)
- DNS-over-HTTPS Network Extension
Full analysis
Version: 65.0 (Build 3)
Scan Date: March 28, 2026
What This Means for You
Device data stays private, with no advertising networks or data brokers involved. Diagnostic telemetry is sent to Datadog and Firebase to keep the service running, but personal information is not shared with third parties for marketing. Users are in control of their data.
Recommendation: Very Secure
Best For: Enterprise users who prioritize device security
Key Findings
Data Security - 5 findings (2 medium, 3 info)
Network Security - 1 finding (1 info)
Code Safety - 0 findings
Privacy - 4 findings (4 info)
Privacy Concerns
What Data is Collected
Operational and diagnostic data is collected to support reliable service delivery. No behavioral profiles are built from user activity and no advertising-related data collection is present. Collection is limited to what is necessary for performance monitoring and keeping the app functioning correctly.
Third-Party Data Sharing
Diagnostic data is shared with Datadog and Firebase for service monitoring and operational reliability. No data is shared with advertising networks, data brokers, or marketing companies. The following third-party services are present in the app:
- Datadog - service monitoring and diagnostics
- Firebase - operational performance reporting
- Lottie, SnapKit, KeychainSwift, FBLPromises, Down, Resolver - functional libraries with no data collection role
Understanding the Scores
| Category | Score |
|---|---|
| Security | 95/100 |
| Privacy | 100/100 |
| Data Security | 96/100 |
| Network Security | 100/100 |
| Code Safety | 100/100 |
| Data Collection | 100/100 |
| Data Sharing | 100/100 |
| User Control | 100/100 |
Positive Security Features
- All network communications are protected and no unencrypted data transmission was detected
- No advertising or tracking networks have access to user information
- Code structure is clean with no dangerous patterns identified
- Data collection is minimal and strictly limited to operational needs
- User data is not shared with any third party for marketing or profiling purposes
Areas for Improvement
- Some data stored on-device could benefit from stronger protection to reduce risk if the device is physically accessed by another person.
- A small number of configuration values are stored in a way that could be hardened further to improve resilience against direct device access.
- Transparency around diagnostic data sent to Datadog and Firebase could be improved to give users clearer visibility into exactly what operational information is reported.
About This Analysis
This scorecard is based on automated static analysis of the app's code and configuration files. Scores reflect practices observed at the time of the scan and may change as the app is updated.
App Details
- Package ID: com.trailofbits.iverify.enterprise
- Version: 65.0 (Build 3)
- Scan Date: March 28, 2026
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 96/100 |