Triodos Banking DE Security & Privacy Scorecard

by Triodos Bank · iOS

79
Overall trust score
Acceptable
76
Security
85
Privacy

Banking transactions and account data stay within Triodos Bank and are not shared with advertisers. How users tap and type is analyzed by fraud detection services to protect accounts. App usage patterns are sent to analytics providers including Adobe and AppsFlyer for performance and marketing measurement.

Best for

Ethical banking with standard analytics and fraud monitoring

Findings

  • 0 critical
  • 3 high
  • 3 medium
  • 3 low
  • 6 info

1 issue identified across security and privacy analysis.

Top security issues

  • Real Customer PII Embedded in Production Bundle (CASTokenStub.json) — full name, DOB, and banking IDs of a real person distributed to all app users
  • Debug HTTP Interception Libraries (netfox + OHHTTPStubs) Linked in Production Binary — can intercept all OAuth tokens and banking API traffic on jailbroken devices
  • Extensive Debug and Test Artifacts Shipped in Production Build — mock OAuth harnesses targeting production Fiducia servers, full OIDC endpoint discovery

Top privacy issues

  • Missing App-Level PrivacyInfo.xcprivacy — AppsFlyer tracking domains misdeclared in Info.plist, rendering App Store privacy labels inaccurate
  • External Public IP Lookup via Third-Party Service (api.ipify.org) — banking session timing and IP address logged by a party outside GDPR DPA
  • Development Firebase Configurations Bundled — exposes development Firebase project names, database URLs, and cross-bank platform linkage to all users

Full analysis

What This Means for You

App usage is monitored by analytics and fraud-detection services. Very little user data is shared with third parties, and users retain strong control over their personal information.

Recommendation: Trustworthy

Best For: Triodos customers managing accounts day-to-day

Key Findings

Data Security - 3 findings (1 high, 2 info)

Network Security - 1 finding (1 medium)

Code Safety - 0 findings

Privacy - 2 findings (1 medium, 1 low)

Privacy Concerns

What Data is Collected

The app collects behavioral and device data through analytics and fraud-detection services. AppsFlyer tracks how users interact with the app to support usage analytics. Adobe Experience Platform gathers in-app usage patterns. ThreatMetrix and Dynatrace observe device signals and behavioral patterns to detect fraud and protect accounts from unauthorized access.

Third-Party Data Sharing

User data is shared with a limited set of third parties. AppsFlyer receives in-app behavioral data for analytics purposes. Adobe Experience Platform collects usage information. ThreatMetrix and BehavioSec receive device and behavioral signals to support fraud prevention. OneTrust manages consent choices. Gini handles document capture data when users use document scanning features. Sharing is bounded to these operational and security purposes, with no evidence of broader advertising or data-broker sharing.

Understanding the Scores

Category Score
Security 76/100
Privacy 85/100
Data Security 83/100
Network Security 78/100
Code Safety 70/100
Data Collection 91/100
Data Sharing 93/100
User Control 92/100

Positive Security Features

  • Local data is stored using strong encryption, protecting account information if a device is lost or accessed without authorization.
  • Fraud detection services actively monitor device and behavioral signals to protect accounts from unauthorized access.
  • Consent management is built into the app, giving users meaningful control over which data practices they agree to.
  • Secure on-device storage mechanisms protect sensitive account data from being accessed by other apps on the device.

Areas for Improvement

  • Some data handling practices could be tightened to reduce the risk of account-related information being accessible in unintended ways on a user's device.
  • Network communication settings could be strengthened to ensure all data sent between the app and its servers uses the most robust protections available.
  • A couple of privacy-related practices fall short of best-in-class standards for limiting how much behavioral data is retained and shared.

About This Analysis

App Details

Field Value
App de.triodos.banking.app
Version 8.7.2 (build 872003)
Scan Date 2026-04-09

This scorecard is generated through automated static analysis. Scores reflect the security and privacy posture of this specific app version at the time of scanning.

Versions & scan history

ScanDateOverall score
#1 (current) 79/100