Triodos Bank UK Security & Privacy Scorecard

by Triodos Bank · iOS

88
Overall trust score
Trustworthy
89
Security
88
Privacy

In-app usage and session activity is shared with Piwik PRO analytics, and crash reports including device details are sent to Bugsnag. During account setup, identity documents and a facial scan are processed by a third-party verification service. A personalization service also analyzes transaction history to generate financial insights shown inside the app.

Best for

Triodos customers comfortable with standard analytics

Findings

  • 0 critical
  • 0 high
  • 2 medium
  • 3 low
  • 7 info

1 issue identified across security and privacy analysis.

Top security issues

  • Wildcard Keychain Access Group Enables Cross-App Credential Sharing
  • Deep Link Handlers for Sensitive Financial Operations — Inbound Parameter Validation Unconfirmed
  • TrustKit Certificate Pinning Enforcement Mode Cannot Be Statically Verified

Top privacy issues

  • FourthlineVision KYC SDK Collects Biometric Face Data Linked to Identity — Disclosure Adequacy Unconfirmed
  • PiwikPRO Analytics Tracks 100+ Banking Screen Events Without Observable Analytics Consent Gate
  • Wildcard Keychain Access Group Enables Cross-App Credential Sharing

Full analysis

What This Means for You

In-app usage and session activity is shared with Piwik PRO analytics, and crash reports including device details are sent to Bugsnag. During account setup, identity documents and a facial scan are processed by a third-party verification service. A personalization service also analyzes transaction history to generate financial insights shown inside the app.

Recommendation: Trustworthy

Best For: Triodos customers comfortable with standard analytics

Key Findings

Data Security - 3 findings (1 medium, 2 info)

Network Security - 2 findings (1 low, 1 info)

Code Safety - 0 findings

Privacy - 3 findings (2 low, 1 info)

Privacy Concerns

What Data is Collected

Session activity and in-app behavior are recorded for analytics. Device information is collected and sent to a crash reporting service if the app encounters an error. During account setup, identity documents and a biometric scan are captured by a third-party verification provider. Transaction history is analyzed by a personalization service to generate financial recommendations shown inside the app.

Third-Party Data Sharing

  • Piwik PRO: Receives in-app usage and session data for analytics purposes.
  • Bugsnag: Receives crash reports that include device details when the app encounters an error.
  • Fourthline: Processes identity documents and facial scan during account verification.
  • Personetics: Analyzes transaction history to generate personalized financial insights within the app.

Understanding the Scores

Category Score
Security 89/100
Privacy 88/100
Data Security 91/100
Network Security 94/100
Code Safety 91/100
Data Collection 86/100
Data Sharing 95/100
User Control 88/100

Positive Security Features

  • The app's consistently strong scores across all security and privacy categories reflect sound, careful implementation throughout.

Areas for Improvement

  • The volume of device and behavioral data sent to third-party analytics and crash reporting services could be reduced to limit how much user information leaves the app.
  • Clearer in-app disclosure about how identity documents and transaction history are handled by external providers would give users better visibility into their data.
  • Minor improvements to network communication configuration could provide an additional layer of protection for data sent between the app and outside services.

About This Analysis

This scorecard is based on a review of the app's packaged code and configuration. Scores reflect the security and privacy posture of the version analyzed and may not reflect changes introduced in later updates.

App Details

  • App: com.triodos.bankinguk
  • Version: 5.3.0 (Build 743)
  • Scan Date: 2026-04-09

Versions & scan history

ScanDateOverall score
#2 (current) 88/100
#1 96/100