Triodos Banking DE Security & Privacy Scorecard
by Triodos Bank · iOS
Banking transactions and account data stay within Triodos Bank and are not shared with advertisers. How users tap and type is analyzed by fraud detection services to protect accounts. App usage patterns are sent to analytics providers including Adobe and AppsFlyer for performance and marketing measurement.
Best for
Ethical banking with standard analytics and fraud monitoring
Findings
- 0 critical
- 3 high
- 3 medium
- 3 low
- 6 info
1 issue identified across security and privacy analysis.
Top security issues
- Real Customer PII Embedded in Production Bundle (CASTokenStub.json) — full name, DOB, and banking IDs of a real person distributed to all app users
- Debug HTTP Interception Libraries (netfox + OHHTTPStubs) Linked in Production Binary — can intercept all OAuth tokens and banking API traffic on jailbroken devices
- Extensive Debug and Test Artifacts Shipped in Production Build — mock OAuth harnesses targeting production Fiducia servers, full OIDC endpoint discovery
Top privacy issues
- Missing App-Level PrivacyInfo.xcprivacy — AppsFlyer tracking domains misdeclared in Info.plist, rendering App Store privacy labels inaccurate
- External Public IP Lookup via Third-Party Service (api.ipify.org) — banking session timing and IP address logged by a party outside GDPR DPA
- Development Firebase Configurations Bundled — exposes development Firebase project names, database URLs, and cross-bank platform linkage to all users
Full analysis
What This Means for You
App usage is monitored by analytics and fraud-detection services. Very little user data is shared with third parties, and users retain strong control over their personal information.
Recommendation: Trustworthy
Best For: Triodos customers managing accounts day-to-day
Key Findings
Data Security - 3 findings (1 high, 2 info)
Network Security - 1 finding (1 medium)
Code Safety - 0 findings
Privacy - 2 findings (1 medium, 1 low)
Privacy Concerns
What Data is Collected
The app collects behavioral and device data through analytics and fraud-detection services. AppsFlyer tracks how users interact with the app to support usage analytics. Adobe Experience Platform gathers in-app usage patterns. ThreatMetrix and Dynatrace observe device signals and behavioral patterns to detect fraud and protect accounts from unauthorized access.
Third-Party Data Sharing
User data is shared with a limited set of third parties. AppsFlyer receives in-app behavioral data for analytics purposes. Adobe Experience Platform collects usage information. ThreatMetrix and BehavioSec receive device and behavioral signals to support fraud prevention. OneTrust manages consent choices. Gini handles document capture data when users use document scanning features. Sharing is bounded to these operational and security purposes, with no evidence of broader advertising or data-broker sharing.
Understanding the Scores
| Category | Score |
|---|---|
| Security | 76/100 |
| Privacy | 85/100 |
| Data Security | 83/100 |
| Network Security | 78/100 |
| Code Safety | 70/100 |
| Data Collection | 91/100 |
| Data Sharing | 93/100 |
| User Control | 92/100 |
Positive Security Features
- Local data is stored using strong encryption, protecting account information if a device is lost or accessed without authorization.
- Fraud detection services actively monitor device and behavioral signals to protect accounts from unauthorized access.
- Consent management is built into the app, giving users meaningful control over which data practices they agree to.
- Secure on-device storage mechanisms protect sensitive account data from being accessed by other apps on the device.
Areas for Improvement
- Some data handling practices could be tightened to reduce the risk of account-related information being accessible in unintended ways on a user's device.
- Network communication settings could be strengthened to ensure all data sent between the app and its servers uses the most robust protections available.
- A couple of privacy-related practices fall short of best-in-class standards for limiting how much behavioral data is retained and shared.
About This Analysis
App Details
| Field | Value |
|---|---|
| App | de.triodos.banking.app |
| Version | 8.7.2 (build 872003) |
| Scan Date | 2026-04-09 |
This scorecard is generated through automated static analysis. Scores reflect the security and privacy posture of this specific app version at the time of scanning.
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 79/100 |