This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.
The five trust checks
What It Means For You
Yes, on the evidence available. The code sends precise location to Yoti, and credentials to Yoti, Yoti devicepubapi_v1 and 4 other recipients. Another 13 data points are sent out to other third parties. None of the findings recorded rises to the level of putting a user at risk.
What It Means For You
Yes, on the evidence available. The code sends precise location to Yoti, and credentials to Yoti, Yoti devicepubapi_v1 and 4 other recipients. Another 13 data points are sent out to other third parties. None of the findings recorded rises to the level of putting a user at risk.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
39 totalNetwork Security
432 totalCode Security
231 totalPrivacy
249 totalThird-Party Risk
43 totalPermission Usage
12 totalVersion diff is on the Developer plan. See developer plans.
Package
com.yoti.mobile.android.live
Analysis Date
Sep 10, 2026
Feedback helps us improve our analysis
The code sends precise location to Yoti; credentials to Yoti, Yoti devicepubapi_v1, Yoti (attrpubapi_v1 attribute service), Yoti (backuppubapi_v1) and 2 other recipients; authentication tokens to Yoti, Yoti (devicepubapi_v1), Yoti pushpubapi_v1 and Yoti user-profile API; and government ID to Yoti. Another 11 data points are sent out to other third parties.
Other findings record data the code reads on the device and data arriving from a server.
Yes, on the evidence available.
None of the findings recorded rises to the level of putting a user at risk. Some are at medium severity or above. The rest are lower severity, described in full in the detailed findings. They fall mostly under Network Security, Privacy and Code Security.
Much of the checking planned for this app did not finish.
Some of it was set aside before it began, and the code in its scope is left out of this page.
The app package was taken from the store and decompiled to source. Agents map the app from the components it declares and the class that runs at launch, following what those paths reach, and ask of each part which third-party SDKs are called there, what those SDKs receive, and whether a consent step is on the same path as the data. The code is checked against advisories recorded from earlier CITT scans.
The most serious findings are then re-examined by a second set of reviews that re-read the cited code from the app itself and argue against each one. A finding is kept when each of those attempts fails, and what survives is what the reports describe.
This page states the findings in plain language. The detailed report contains the technical detail, with credential-shaped values masked.
This assessment was produced by CITT (Can I Trust That), an independent analysis service. Each statement above comes from one recorded claim, given here as a summary of what was found rather than as the evidence for it.
Developer not yet contacted