Scan results

    Yoti - your digital identity

    Android

    unTRUSTED

    This app did not meet two or more trust checks, has a critical issue in one, or carries a red flag.

    The five trust checks

    Truly LocalNot applicable
    CITT SCORE
    81
    out of 100
    unTRUSTED

    What It Means For You

    Yes, on the evidence available. The code sends precise location to Yoti, and credentials to Yoti, Yoti devicepubapi_v1 and 4 other recipients. Another 13 data points are sent out to other third parties. None of the findings recorded rises to the level of putting a user at risk.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (1006)

    Data Security

    39 total
    13 Medium
    26 Low

    Network Security

    432 total
    71 Medium
    361 Low

    Code Security

    231 total
    138 Medium
    93 Low

    Privacy

    249 total
    85 Medium
    164 Low

    Third-Party Risk

    43 total
    2 Medium
    41 Low

    Permission Usage

    12 total
    1 Medium
    11 Low
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Package

    com.yoti.mobile.android.live

    Analysis Date

    Sep 10, 2026

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    What This App Collects

    The code sends precise location to Yoti; credentials to Yoti, Yoti devicepubapi_v1, Yoti (attrpubapi_v1 attribute service), Yoti (backuppubapi_v1) and 2 other recipients; authentication tokens to Yoti, Yoti (devicepubapi_v1), Yoti pushpubapi_v1 and Yoti user-profile API; and government ID to Yoti. Another 11 data points are sent out to other third parties.

    Other findings record data the code reads on the device and data arriving from a server.

    Can This Be Trusted

    Yes, on the evidence available.

    None of the findings recorded rises to the level of putting a user at risk. Some are at medium severity or above. The rest are lower severity, described in full in the detailed findings. They fall mostly under Network Security, Privacy and Code Security.

    Scores

    • Overall: 81/100
    • Security: 80/100. Held down by how the app talks to servers and by how the app is put together.
    • Privacy: 82/100. Held down by the amount collected and by how little of it is recorded as consented to.
    • Data Security: 89/100
    • Network Security: 85/100
    • Code Safety: 83/100
    • Data Collection: 83/100
    • Data Sharing: 93/100
    • User Control: 82/100
    • Permission Usage: 96/100

    How This Was Checked

    Much of the checking planned for this app did not finish.

    Some of it was set aside before it began, and the code in its scope is left out of this page.

    The app package was taken from the store and decompiled to source. Agents map the app from the components it declares and the class that runs at launch, following what those paths reach, and ask of each part which third-party SDKs are called there, what those SDKs receive, and whether a consent step is on the same path as the data. The code is checked against advisories recorded from earlier CITT scans.

    The most serious findings are then re-examined by a second set of reviews that re-read the cited code from the app itself and argue against each one. A finding is kept when each of those attempts fails, and what survives is what the reports describe.

    This page states the findings in plain language. The detailed report contains the technical detail, with credential-shaped values masked.

    About This Analysis

    This assessment was produced by CITT (Can I Trust That), an independent analysis service. Each statement above comes from one recorded claim, given here as a summary of what was found rather than as the evidence for it.

    Right of Reply

    Developer not yet contacted