Triodos Bank UK Security & Privacy Scorecard
by Triodos Bank · iOS
In-app usage and session activity is shared with Piwik PRO analytics, and crash reports including device details are sent to Bugsnag. During account setup, identity documents and a facial scan are processed by a third-party verification service. A personalization service also analyzes transaction history to generate financial insights shown inside the app.
Best for
Triodos customers comfortable with standard analytics
Findings
- 0 critical
- 0 high
- 2 medium
- 3 low
- 7 info
1 issue identified across security and privacy analysis.
Top security issues
- Wildcard Keychain Access Group Enables Cross-App Credential Sharing
- Deep Link Handlers for Sensitive Financial Operations — Inbound Parameter Validation Unconfirmed
- TrustKit Certificate Pinning Enforcement Mode Cannot Be Statically Verified
Top privacy issues
- FourthlineVision KYC SDK Collects Biometric Face Data Linked to Identity — Disclosure Adequacy Unconfirmed
- PiwikPRO Analytics Tracks 100+ Banking Screen Events Without Observable Analytics Consent Gate
- Wildcard Keychain Access Group Enables Cross-App Credential Sharing
Full analysis
What This Means for You
In-app usage and session activity is shared with Piwik PRO analytics, and crash reports including device details are sent to Bugsnag. During account setup, identity documents and a facial scan are processed by a third-party verification service. A personalization service also analyzes transaction history to generate financial insights shown inside the app.
Recommendation: Trustworthy
Best For: Triodos customers comfortable with standard analytics
Key Findings
Data Security - 3 findings (1 medium, 2 info)
Network Security - 2 findings (1 low, 1 info)
Code Safety - 0 findings
Privacy - 3 findings (2 low, 1 info)
Privacy Concerns
What Data is Collected
Session activity and in-app behavior are recorded for analytics. Device information is collected and sent to a crash reporting service if the app encounters an error. During account setup, identity documents and a biometric scan are captured by a third-party verification provider. Transaction history is analyzed by a personalization service to generate financial recommendations shown inside the app.
Third-Party Data Sharing
- Piwik PRO: Receives in-app usage and session data for analytics purposes.
- Bugsnag: Receives crash reports that include device details when the app encounters an error.
- Fourthline: Processes identity documents and facial scan during account verification.
- Personetics: Analyzes transaction history to generate personalized financial insights within the app.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 89/100 |
| Privacy | 88/100 |
| Data Security | 91/100 |
| Network Security | 94/100 |
| Code Safety | 91/100 |
| Data Collection | 86/100 |
| Data Sharing | 95/100 |
| User Control | 88/100 |
Positive Security Features
- The app's consistently strong scores across all security and privacy categories reflect sound, careful implementation throughout.
Areas for Improvement
- The volume of device and behavioral data sent to third-party analytics and crash reporting services could be reduced to limit how much user information leaves the app.
- Clearer in-app disclosure about how identity documents and transaction history are handled by external providers would give users better visibility into their data.
- Minor improvements to network communication configuration could provide an additional layer of protection for data sent between the app and outside services.
About This Analysis
This scorecard is based on a review of the app's packaged code and configuration. Scores reflect the security and privacy posture of the version analyzed and may not reflect changes introduced in later updates.
App Details
- App: com.triodos.bankinguk
- Version: 5.3.0 (Build 743)
- Scan Date: 2026-04-09
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #2 (current) | 88/100 | |
| #1 | 96/100 |