Triodos Bankieren NL Security & Privacy Scorecard
by Triodos Bank · iOS
App usage and crash data is shared with Piwik PRO for analytics and Bugsnag for error reporting. Identity verification is handled by Fourthline, which processes identity documents and biometric data. Personetics receives banking behavior data to power personalized financial insights.
Best for
Triodos customers comfortable with analytics
Findings
- 0 critical
- 0 high
- 5 medium
- 1 low
- 0 info
1 issue identified across security and privacy analysis.
Top security issues
- Wildcard Keychain Access Group Exposes Session Tokens to Any Triodos Companion App
- Personetics eventDelegate.js Assigns Server-Supplied URL Directly to window.location.href Without Validation
- Custom URL Scheme triodosmobilebanking:// Invocable by Any App on Device Without Origin Verification
Top privacy issues
- PiwikPROSDK 1.0.7 Ships Without Required Apple Privacy Manifest
- PersoneticsCoreIos Framework Has Empty Privacy Manifest Despite Active Financial Data Flows to P-Server
- Personetics Bridge Forwards Financial Behavioral Data to P-Server Cloud Without Declared Data Types
Full analysis
Triodos Bankieren NL
Overall Security: 90/100 | Privacy: 91/100
What This Means for You
App usage and crash data is shared with Piwik PRO for analytics and Bugsnag for error reporting. Identity verification is handled by Fourthline, which processes identity documents and biometric data. Personetics receives banking behavior data to power personalized financial insights.
Recommendation: Very Secure
Best For: Triodos customers comfortable with analytics
Key Findings
Data Security - 1 finding (1 medium)
Network Security - 2 findings (2 medium)
Code Safety - 0 findings
Privacy - 1 finding (1 low)
Privacy Concerns
What Data is Collected
The app collects data about app usage and interactions, device information, crash and error reports, identity documents for account verification, biometric data for identity confirmation, and banking activity patterns.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Piwik PRO - receives app usage and interaction data for analytics purposes
- Bugsnag - receives crash and error data to monitor app stability
- Fourthline - receives identity documents and biometric data for identity verification
- Personetics - receives banking behavior data to generate personalized financial insights
Understanding the Scores
| Category | Score |
|---|---|
| Security | 90/100 |
| Privacy | 91/100 |
| Data Security | 94/100 |
| Network Security | 92/100 |
| Code Safety | 95/100 |
| Data Collection | 93/100 |
| Data Sharing | 93/100 |
| User Control | 94/100 |
Positive Security Features
- None specifically identified in this analysis.
Areas for Improvement
- Some data stored on the device could benefit from stronger safeguards to limit exposure in edge cases.
- The app's network communication configuration has minor gaps that, while low risk, could be tightened to meet the highest available security standards.
- A small amount of behavioral data is shared with a financial insights provider; clearer in-app disclosure would give users more visibility into this sharing.
About This Analysis
This scorecard was generated by automated security analysis. Scores reflect the security and privacy posture of the app at the time of the scan.
App Details
| Field | Value |
|---|---|
| App | Triodos Bankieren NL |
| Package | com.triodos.bankingnl |
| Version | 5.3.0 (Build 743) |
| Scan Date | 2026-04-09 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 90/100 | |
| #1 | 97/100 |